|
7369a3612c
|
Update kernel module blacklist URL
|
2024-08-09 16:02:35 -07:00 |
|
|
80a12f1ecc
|
Enable hardened_malloc for Flatpak
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-29 10:16:04 -07:00 |
|
|
4998051aa3
|
Disable GJS and WebkitGTK JIT
|
2024-07-28 22:43:29 -07:00 |
|
|
d96f5a70da
|
Update modprobe url and bug fixes
|
2024-07-26 04:59:01 -07:00 |
|
|
e04febb0fe
|
Add set -u
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-20 18:23:38 -07:00 |
|
|
d434af04b4
|
Not overwrite USERGROUP_ENAB on anything but Ubuntu
The nonsense with umask is introduced by Canonical's infinite wisdom: https://git.launchpad.net/ubuntu/+source/pam/tree/debian/patches/pam_umask_usergroups_from_login.defs.patch?h=ubuntu/noble
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583958
We don't need to break sensible distributions because of Ubuntu nonsenses
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-09 15:07:40 -07:00 |
|
|
9f429d1b75
|
Remove unnecessary groups
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-05 14:30:48 -07:00 |
|
|
fe4205fe45
|
Suppress curl output
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-03 02:23:28 -07:00 |
|
|
0b25901b86
|
Add set -e
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-02 16:48:15 -07:00 |
|
|
5aa7838940
|
Remove unnecessary commands
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-02 15:50:44 -07:00 |
|
|
e3104f037f
|
POSIX Compliance
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-25 22:24:45 -07:00 |
|
|
3aadb5455f
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-09 20:37:50 -07:00 |
|
|
babba9de39
|
Fix Edge policies permissions
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-09 20:33:40 -07:00 |
|
|
46ea5f81bf
|
Remove real-ucode
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-09 05:34:13 -07:00 |
|
|
517c1ed2dc
|
Fix real-ucode condition
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-07 21:20:30 -07:00 |
|
|
afb3f0e98a
|
Typo fix
|
2024-06-06 21:59:38 -07:00 |
|
|
4514fe279a
|
Add preload file for hmalloc
|
2024-06-06 21:58:28 -07:00 |
|
|
fe7f17fb6b
|
Permission fixes
|
2024-06-05 22:18:53 -07:00 |
|
|
3790c4df70
|
Fix file permission on Fedora
|
2024-06-05 21:42:12 -07:00 |
|
|
905096e36a
|
Wildcard removal of abrt
|
2024-06-05 16:24:37 -07:00 |
|
|
2ff48df2d1
|
Typo fixes
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-04 14:29:50 -07:00 |
|
|
236f650566
|
Use custom config & SecureBlue whenever possible on Fedora
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-04 04:23:30 -07:00 |
|
|
db4a82be7e
|
Better regex for kernel module blacklist
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:46:59 -07:00 |
|
|
8087457cb0
|
Add escape for regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:34:48 -07:00 |
|
|
90bebe1665
|
Better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:19:20 -07:00 |
|
|
4b9ae05218
|
Even better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 02:33:02 -07:00 |
|
|
5bc20644e6
|
Better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 02:27:28 -07:00 |
|
|
f1508a7f01
|
Stop hardcoding compression level
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-30 21:57:03 -07:00 |
|
|
0c892f019b
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 17:48:45 -07:00 |
|
|
441c4e068a
|
Remove abrt
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 15:33:25 -07:00 |
|
|
1aecfcd3a5
|
Add missing -y
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 14:53:50 -07:00 |
|
|
7c8394ea12
|
Better virtualization handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 14:52:09 -07:00 |
|
|
1cca00f237
|
Better umask handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 12:27:45 -07:00 |
|
|
6e80f936bb
|
Fix kargs
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 10:40:07 -07:00 |
|
|
c2c57e5393
|
Update kernel hardening params
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 10:22:47 -07:00 |
|
|
312d968efd
|
Minor reorganization
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-21 23:16:23 -07:00 |
|
|
07d62d45f5
|
Remove more useless packages
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-21 19:26:42 -07:00 |
|
|
7b9a916694
|
Remove unnecessary command
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-20 19:02:18 -07:00 |
|
|
ad4b8ac8df
|
Better systemd-boot detection
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-20 07:07:44 -07:00 |
|
|
40e9c49fcd
|
Check for /usr/lib/systemd/boot/efi
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-19 18:26:54 -07:00 |
|
|
2e1b763290
|
tuned not installed by default
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 15:22:28 -07:00 |
|
|
3d1ece9861
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 02:49:31 -07:00 |
|
|
c5d3b81475
|
Update zram config
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 22:32:28 -07:00 |
|
|
552d18820e
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-04-28 21:21:30 -07:00 |
|
|
59fb5c611b
|
Better handling for Parallels
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-04-28 13:41:30 -07:00 |
|
|
db0046bc8b
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-04-28 13:29:04 -07:00 |
|
|
64660867fe
|
Typo fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-04-28 13:17:59 -07:00 |
|
|
a6a3c40ee5
|
Remove extra space
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-04-28 12:18:44 -07:00 |
|
|
912c884841
|
Move networking setup to the end of the scripts
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-04-28 11:47:36 -07:00 |
|
|
41a1237561
|
Fix chrony.conf location on Fedora
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-04-26 23:28:13 -07:00 |
|