All checks were successful
🛡️ Retrieve DNSSEC status of coresecret.dev. / 🛡️ Retrieve DNSSEC status of coresecret.dev. (push) Successful in 34s
🛡️ Shell Script Linting / 🛡️ Shell Script Linting (push) Successful in 1m19s
🔐 Generating a Private Live ISO FLV 0. / 🔐 Generating a Private Live ISO FLV 0. (push) Successful in 48m28s
🔐 Generating a Private Live ISO FLV 1. / 🔐 Generating a Private Live ISO FLV 1. (push) Successful in 47m5s
💙 Generating a PUBLIC Live ISO. / 💙 Generating a PUBLIC Live ISO. (push) Successful in 47m5s
Signed-off-by: Marc S. Weidner <msw@coresecret.dev>
2.3 KiB
2.3 KiB
Table of Contents
1. CISS.debian.live.builder
Centurion Intelligence Consulting Agency Information Security Standard
Debian Live Build Generator for hardened live environment and CISS Debian Installer
Master Version: 8.03
Build: V8.03.768.2025.06.09
2. Changelog
V8.03.768.2025.06.09
V8.03.644.2025.06.07
- Updated workflows ISO Generators Runners.
- Installing
bookworm-backportsVersions of:btrfs-progscurldebootstrapiproute2ncatnmapsshsystemdsystemd-sysvwhois
- Changed default:
/etc/login.defsLOGIN_TIMEOUT 60to:LOGIN_TIMEOUT 180 - LIVE ISO generated by workflow tested against:
- Netcup Root Server
- Proxmox
- LIVE ISO generated by script tested against:
- Netcup Root Server
V8.03.512.2025.06.06
-
Updated workflows:
git stash pushgit fetch origin mastergit merge --no-edit origin/mastergit stash pop
-
Changed workflows ISO Generators routines
🛠️ Build GnuPG from the sources, as the Bookworm GPG does not understand key format 5.- added
wget --https-onlyflag - added verification step
- added
V8.03.400.2025.06.05
- The workflow ISO Generators image was changed to
debian:bookworm. - Added a LIVE ISO workflow routine to build GnuPG from sources, since Bookworm GPG does not recognize key format 5.
- Changed verbosity of:
- Added basic linter checks for:
*.sh,*.zsh,*.chroot,- all files with Shebang
#! for:- Windows CRLF line endings
- unauthorized control characters (C0 control characters except \t, \n)
- non-ASCII (ambiguous UTF) characters
- linter_char_scripts.yaml
no tracking | no logging | no advertising | no profiling | no bullshit