diff --git a/.ansible-lint b/.ansible-lint index f21e1f4..c3dfee3 100644 --- a/.ansible-lint +++ b/.ansible-lint @@ -4,6 +4,10 @@ skip_list: - 'schema' - 'no-changed-when' - 'fqcn-builtins' + - 'experimental' + - 'name[casing]' + - 'name[template]' + - 'jinja[spacing]' - '204' - '305' - '303' diff --git a/meta/main.yml b/meta/main.yml index aac8be8..b4a804e 100644 --- a/meta/main.yml +++ b/meta/main.yml @@ -5,6 +5,7 @@ galaxy_info: company: "MindPoint Group" license: MIT role_name: rhel9_cis + namespace: mindpointgroup min_ansible_version: 2.10.0 platforms: - name: EL diff --git a/tasks/section_1/cis_1.4.x.yml b/tasks/section_1/cis_1.4.x.yml index 8ba419e..cdad67f 100644 --- a/tasks/section_1/cis_1.4.x.yml +++ b/tasks/section_1/cis_1.4.x.yml @@ -3,7 +3,7 @@ - name: "1.4.1 | PATCH | Ensure bootloader password is set" copy: dest: /boot/grub2/user.cfg - content: "GRUB2_PASSWORD={{ rhel9cis_bootloader_password_hash }}" + content: "GRUB2_PASSWORD={{ rhel9cis_bootloader_password_hash }}" # noqa template-instead-of-copy owner: root group: root mode: 0600 diff --git a/tasks/section_5/cis_5.6.x.yml b/tasks/section_5/cis_5.6.x.yml index 4064d74..f1052c3 100644 --- a/tasks/section_5/cis_5.6.x.yml +++ b/tasks/section_5/cis_5.6.x.yml @@ -93,8 +93,8 @@ regexp: "{{ item.regexp }}" replace: "{{ item.replace }}" loop: - - { regexp: '(UMASK\s+)0[012][0-6]', replace: '\1 027' } - - { regexp: '(USERGROUPS_ENAB\s+)yes', replace: '\1 no' } + - { regexp: '(UMASK\s+)0[012][0-6]', replace: '\1 027' } + - { regexp: '(USERGROUPS_ENAB\s+)yes', replace: '\1 no' } - name: "5.6.5 | PATCH | Ensure default user umask is 027 or more restrictive | Set umask for /etc/bashrc" replace: diff --git a/tasks/section_6/cis_6.1.x.yml b/tasks/section_6/cis_6.1.x.yml index 099eb0e..29d98b3 100644 --- a/tasks/section_6/cis_6.1.x.yml +++ b/tasks/section_6/cis_6.1.x.yml @@ -14,7 +14,7 @@ block: - name: "6.1.1 | AUDIT | Audit system file permissions | Add file discrepancy list to system" copy: - dest: "{{ rhel9cis_rpm_audit_file }}" + dest: "{{ rhel9cis_rpm_audit_file }}" # noqa template-instead-of-copy content: "{{ rhel9cis_6_1_1_packages_rpm.stdout }}" owner: root group: root