Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
68 changes: 66 additions & 2 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# See https://pre-commit.com for more information

Check warning on line 1 in .pre-commit-config.yaml

View workflow job for this annotation

GitHub Actions / flag-out-of-scope-changes

This modified file is outside every Sites/*/Fixlets directory and the top-level Signatures/ directory, so it was not automatically validated and needs manual review.
# See https://pre-commit.com/hooks.html for more hooks
#
# Install once per clone with `pre-commit install`, then these run
Expand Down Expand Up @@ -57,18 +57,82 @@

- id: bes-conventions-check
# autofix by default, but only report errors; many missing descriptions on historical content
args: ["--auto-fix=yes", "--errors-only", "--disable=E204"]
args: ["--auto-fix=yes", "--errors-only" ]
# "--disable=E202,E204,E206,E207,E209,E212,E215,E217,E220,W210,W216"
#
# [E200] ActionScript has no MIMEType (temporary)
# [E202] x-fixlet-modification-time (temporary)
# [E204] ignore missing descriptions on historical content (temporary)
# [E206] action-ui-metadata malformed (permanent, missing icon is flagged)
# [E206] ignore missing 'description' on historical content (temporary)
# [E207] ActionScript entity-escapes a character (< > &) that requires <![CDATA[ ... ]]> (temporary)
# [E209] CVENames value invalid (temporary)
# [E212] relevance is 'true' (temporary)
# [E215] auto-fixed: stripped whitespace before the ActionScript close
# [E217] SuccessCriteria Option="CustomRelevance" has an empty relevance body (temporary)
# [E220] duplicate Analysis <Property> Name
# [W210] auto-fixed: stripped trailing whitespace
# [W216] auto-fixed: cleared SourceSeverity "Unspecified" to empty

- id: bes-actionscript-lint-schclass
args: ["--auto-fix=yes"]
# "--disable=E300,E301,E302,W301,W302,W303"
#
# [E300] line does not start with a known ActionScript command
# [E301] {...} substitution has no closing } before the end of the line
# [E302] createfile until marker (temporary)
# [W301] warning: unbalanced quotes (temporary)
# [W302] warning: command verb not lowercase (temporary)
# [W303] warning: override option not lowercase (temporary)

- id: bes-actionscript-validate-prefetch
# ignore missing sha256 on downloads for historical reasons
args: ["--auto-fix=yes", "--disable=E401", "--auto-fix-network=no"]
args: ["--auto-fix=yes", "--auto-fix-network=no"]
# "--disable=E400,E401,E403,W403,W406",
# [E400] invalid prefetch: ERROR: prefetch is invalid, could not be parsed; (temporary)
# [E401] ignore missing sha256 on downloads for historical reasons (temporary)
# [E403] invalid prefetch: stray tokens (temporary)
# [W403] warning: `add nohash prefetch item` (temporary)
# [W406] warning: prefetch names the file differently than the downloaded file (temporary)

- id: bes-actionscript-validate-script
args: []
# "--disable=E501,E506,E508,E509,E512,E514,E517,E518,E520,E521,E524,E525,W502,W505,W506,W507,W508"
# [E500] `if` is never closed by `endif` (temporary)
# [E501] `endif` with no open `if` (temporary)
# [E506] second `else` for the same `if` (temporary)
# [E508] unbalanced { at column 28 -- the relevance substitution has no closing } (temporary)
# [E509] unbalanced } at (temporary)
# [E512] duplicate download name (temporary)
# [E514] `if` condition is not a relevance expression (temporary)
# [E517] parameter is referenced without assignment (temporary)
# [E518] `continue if` condition is not a relevance expression
# [E520] `setting` line does not match the documented format (temporary)
# [E521] "regset" key is not a quoted, bracketed (temporary)
# [E524] auto-fixed: joined `else if` into `elseif`
# [W502] warning: `action parameter query` after action starts
# [W504] warning: `dos` is deprecated; (temporary)
# [W505] warning: cmd.exe is passed a command line but no `/c`
# [W506] warning: `copy` onto existing files (temporary)
# [W506] warning: `move` onto existing files (temporary)
# [W507] warning: reference a file that was not downloaded (temporary)
# [W508] warning: `parameter ` is never assigned, queried, or named (temporary)
# [E525] auto-fixed: quoted the folder create path (temporary)

- id: bes-relevance-lint
args: []
# "--disable=E600,E601,E603,E604,E605,W600,W601,W602,W604,E608"
# [E600] (parse-error)
# [E601] unlexable text (error-token))
# [E603] (type-error)
# E604: ignore complexity check (permanent)
# [E605] (evaluation-cost) (temporary)
# [W600] unknown inspector (temporary)
# W601: ignore non-unique-risk (temporary)
# [W602] warning: (plural-preferred)
# W604: (version-truncating-compare) (temporary)
# E608: singular/plural relevance result (site-type-mismatch) (permanent)


# A local fork https://github.com/mxab/pre-commit-trivy.git
# to support scanning the filesystem for known vulnerabilities or misplaced secrets
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,8 @@
</Description>
<ActionScript MIMEType="application/x-Fixlet-Windows-Shell">action parameter query &quot;Username&quot; with description &quot;Please enter your network username:&quot; with default &quot;&quot;
action parameter query &quot;Password&quot; with description &quot;Please enter your network password:&quot; with default &quot;&quot;
Delete __createfile
Delete JoinDomain.sh
delete __createfile
delete JoinDomain.sh
createfile until endscript
#!/bin/sh
computerid=`/usr/sbin/scutil --get LocalHostName`
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
<Source>Apple</Source>
<SourceID>APPLE-SA-2015-03-09-3</SourceID>
<SourceReleaseDate>2015-03-09</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2015-1065, CVE-2015-1066, CVE-2015-1061, CVE-2014-4496, CVE-2015-1067</CVENames>
<MIMEField>
<Name>x-fixlet-domain_attributes</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
<Source>Apple</Source>
<SourceID>APPLE-SA-2015-03-09-3</SourceID>
<SourceReleaseDate>2015-03-09</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2015-1065, CVE-2015-1066, CVE-2015-1061, CVE-2014-4496, CVE-2015-1067</CVENames>
<MIMEField>
<Name>x-fixlet-domain_attributes</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
<Source>Apple</Source>
<SourceID>N/A</SourceID>
<SourceReleaseDate>2015-03-19</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2015-1065, CVE-2015-1061</CVENames>
<MIMEField>
<Name>x-fixlet-domain_attributes</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@
<Source>Apple</Source>
<SourceID>N/A</SourceID>
<SourceReleaseDate>2015-03-19</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2015-1065, CVE-2015-1061</CVENames>
<MIMEField>
<Name>x-fixlet-domain_attributes</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -168,6 +168,7 @@ log.close()
print 'Granted Admin Right to ' + userName
EOF
folder create "/Library/PSU"
delete "/Library/PSU/grantAdmin.py"
move __createfile "/Library/PSU/grantAdmin.py"

wait /usr/bin/python "/Library/PSU/grantAdmin.py"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@
<Source>Apple</Source>
<SourceID>APPLE-SA-2015-01-27-3</SourceID>
<SourceReleaseDate>2015-01-27</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2014-6277, CVE-2014-7186, CVE-2014-7187, CVE-2014-8836, CVE-2014-8837, CVE-2014-4460, CVE-2014-4481, CVE-2014-4498, CVE-2014-4499, CVE-2014-1595, CVE-2014-8817, CVE-2014-4484, CVE-2014-4483, CVE-2014-4485, CVE-2014-8819, CVE-2014-8820, CVE-2014-8821, CVE-2014-4486, CVE-2014-4487, CVE-2014-4488, CVE-2014-4489, CVE-2014-8822, CVE-2014-8830, CVE-2014-8838, CVE-2014-8835, CVE-2014-4495, CVE-2014-8824, CVE-2014-4491, CVE-2014-4461, CVE-2014-8826, CVE-2014-4492, CVE-2014-8827, CVE-2014-8517, CVE-2014-3566, CVE-2014-3567, CVE-2014-3568, CVE-2014-8832, CVE-2014-4389, CVE-2014-8823, CVE-2014-8825, CVE-2014-4371, CVE-2014-4419, CVE-2014-4420, CVE-2014-4421, CVE-2014-8839, CVE-2014-8833, CVE-2014-8834</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@
<Source>Apple</Source>
<SourceID>APPLE-SA-2015-01-27-4</SourceID>
<SourceReleaseDate>2015-01-27</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2014-6277, CVE-2014-7186, CVE-2014-7187, CVE-2014-8836, CVE-2014-8837, CVE-2014-4460, CVE-2014-4481, CVE-2014-4498, CVE-2014-4499, CVE-2014-1595, CVE-2014-8817, CVE-2014-4484, CVE-2014-4483, CVE-2014-4485, CVE-2014-8819, CVE-2014-8820, CVE-2014-8821, CVE-2014-4486, CVE-2014-4487, CVE-2014-4488, CVE-2014-4489, CVE-2014-8822, CVE-2014-8830, CVE-2014-8838, CVE-2014-8835, CVE-2014-4495, CVE-2014-8824, CVE-2014-4491, CVE-2014-4461, CVE-2014-8826, CVE-2014-4492, CVE-2014-8827, CVE-2014-8517, CVE-2014-3566, CVE-2014-3567, CVE-2014-3568, CVE-2014-8832, CVE-2014-4389, CVE-2014-8823, CVE-2014-8825, CVE-2014-4371, CVE-2014-4419, CVE-2014-4420, CVE-2014-4421, CVE-2014-8839, CVE-2014-8833, CVE-2014-8834</CVENames>
<MIMEField>
<Name>x-fixlet-domain_attributes</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@
<Source>Apple</Source>
<SourceID>APPLE-SA-2015-01-27-4</SourceID>
<SourceReleaseDate>2015-01-27</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2014-6277, CVE-2014-7186, CVE-2014-7187, CVE-2014-8836, CVE-2014-8837, CVE-2014-4460, CVE-2014-4481, CVE-2014-4498, CVE-2014-4499, CVE-2014-1595, CVE-2014-8817, CVE-2014-4484, CVE-2014-4483, CVE-2014-4485, CVE-2014-8819, CVE-2014-8820, CVE-2014-8821, CVE-2014-4486, CVE-2014-4487, CVE-2014-4488, CVE-2014-4489, CVE-2014-8822, CVE-2014-8830, CVE-2014-8838, CVE-2014-8835, CVE-2014-4495, CVE-2014-8824, CVE-2014-4491, CVE-2014-4461, CVE-2014-8826, CVE-2014-4492, CVE-2014-8827, CVE-2014-8517, CVE-2014-3566, CVE-2014-3567, CVE-2014-3568, CVE-2014-8832, CVE-2014-4389, CVE-2014-8823, CVE-2014-8825, CVE-2014-4371, CVE-2014-4419, CVE-2014-4420, CVE-2014-4421, CVE-2014-8839, CVE-2014-8833, CVE-2014-8834</CVENames>
<MIMEField>
<Name>x-fixlet-domain_attributes</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@
<Source>Apple</Source>
<SourceID>APPLE-SA-2015-01-27-3</SourceID>
<SourceReleaseDate>2015-01-27</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>CVE-2014-6277, CVE-2014-7186, CVE-2014-7187, CVE-2014-8836, CVE-2014-8837, CVE-2014-4460, CVE-2014-4481, CVE-2014-4498, CVE-2014-4499, CVE-2014-1595, CVE-2014-8817, CVE-2014-4484, CVE-2014-4483, CVE-2014-4485, CVE-2014-8819, CVE-2014-8820, CVE-2014-8821, CVE-2014-4486, CVE-2014-4487, CVE-2014-4488, CVE-2014-4489, CVE-2014-8822, CVE-2014-8830, CVE-2014-8838, CVE-2014-8835, CVE-2014-4495, CVE-2014-8824, CVE-2014-4491, CVE-2014-4461, CVE-2014-8826, CVE-2014-4492, CVE-2014-8827, CVE-2014-8517, CVE-2014-3566, CVE-2014-3567, CVE-2014-3568, CVE-2014-8832, CVE-2014-4389, CVE-2014-8823, CVE-2014-8825, CVE-2014-4371, CVE-2014-4419, CVE-2014-4420, CVE-2014-4421, CVE-2014-8839, CVE-2014-8833, CVE-2014-8834</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@
// NOTE: the relevance depends on this target_folder location and should also be changed so they match
parameter "target_folder" = "/tmp/system_profiler/"

folder create { parameter "target_folder" }
folder create "{ parameter "target_folder" }"

wait sh -c "system_profiler -listDataTypes > {parameter "target_folder"}_spOut_listDataTypes.txt"

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (x64 of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 57020416 * 2) and exists (key of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of ( x32 registry)) whose (value "DisplayName" of it as string is "Google Chrome" and value "DisplayVersion" of it as string as version < "53.0.2785.101" as version)]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-01-01</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (not x64 of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 48979968 * 2) and exists (key of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of ( x32 registry)) whose (value "DisplayName" of it as string is "Google Chrome" and value "DisplayVersion" of it as string as version < "53.0.2785.101" as version)]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-01-01</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (x64 of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 56819712 * 2) and exists (key of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of ( x32 registry)) whose (value "DisplayName" of it as string is "Google Chrome" and value "DisplayVersion" of it as string as version < "53.0.2785.113" as version)]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-01-01</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (not x64 of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 48893952 * 2) and exists (key of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of ( x32 registry)) whose (value "DisplayName" of it as string is "Google Chrome" and value "DisplayVersion" of it as string as version < "53.0.2785.113" as version)]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-01-01</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (x64 of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 56815616 * 2) and exists (key of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of ( x32 registry)) whose (value "DisplayName" of it as string is "Google Chrome" and value "DisplayVersion" of it as string as version < "53.0.2785.116" as version)]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-01-01</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (not x64 of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 48902144 * 2) and exists (key of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of ( x32 registry)) whose (value "DisplayName" of it as string is "Google Chrome" and value "DisplayVersion" of it as string as version < "53.0.2785.116" as version)]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-01-01</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>x-fixlet-modification-time</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 48922624 * 2) and (x64 of operating system) and (exists value "DisplayVersion" whose (it as string as version < "53.0.2785.143") of keys whose (value "DisplayName" of it as string is "Google Chrome") of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of (x32 registries; x64 registries))]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-10-04</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>cpe-id-v2.3</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 48922624 * 2) and (not x64 of operating system) and (exists value "DisplayVersion" whose (it as string as version < "53.0.2785.143") of keys whose (value "DisplayName" of it as string is "Google Chrome") of keys "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall" of (x32 registries))]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-10-06</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>cpe-id-v2.3</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 46182400 * 2) and (x64 of operating system) and (exists key whose ((set of ("Google %c5%a9%b7%d2";"Google Chrome") contains value "name" of it as string) and value "pv" of it as string as version < "54.0.2840.59") of keys "Software\Google\Update\Clients" of (current user keys (logged on users) of registry;keys "HKEY_LOCAL_MACHINE" of x32 registry))]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-10-17</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>cpe-id-v2.3</Name>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
<Relevance><![CDATA[(windows of operating system) and (version of operating system >= "6.1") and (if exists property "in proxy agent context" then ( not in proxy agent context ) else true) and (free space of drive of client > 46182400 * 2) and (not x64 of operating system) and (exists key whose ((set of ("Google %c5%a9%b7%d2";"Google Chrome") contains value "name" of it as string) and value "pv" of it as string as version < "54.0.2840.59") of keys "Software\Google\Update\Clients" of (current user keys (logged on users) of registry;keys "HKEY_LOCAL_MACHINE" of x32 registry))]]></Relevance>
<Source>C3 Patch</Source>
<SourceReleaseDate>2016-10-17</SourceReleaseDate>
<SourceSeverity>Unspecified</SourceSeverity>
<SourceSeverity></SourceSeverity>
<CVENames>Unspecified</CVENames>
<MIMEField>
<Name>cpe-id-v2.3</Name>
Expand Down
Loading
Loading