Skip to content

chore(deps): update dependency ansible-lockdown/ubuntu22-cis to v3#2536

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ansible-lockdown-ubuntu22-cis-3.x
Open

chore(deps): update dependency ansible-lockdown/ubuntu22-cis to v3#2536
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ansible-lockdown-ubuntu22-cis-3.x

Conversation

@renovate

@renovate renovate Bot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ansible-lockdown/UBUNTU22-CIS major 2.0.33.0.0

Release Notes

ansible-lockdown/UBUNTU22-CIS (ansible-lockdown/UBUNTU22-CIS)

v3.0.0

Compare Source

Fixed
  • prelim.yml: Fixed mount UUID/LABEL loss — added fstab source parsing so handlers preserve UUID/LABEL entries instead of replacing them with /dev/sdX device names
  • cis_2.1.x.yml: Added ternary masking to 2.1.1 autofs service mask task — prevents failure when autofs package is not installed
  • templates/tmp.mount.j2: Fixed Options: (colon) to Options= (equals) in systemd mount unit — colon syntax is invalid and silently ignored by systemd
  • defaults/main.yml: Added ubtu22cis_tmp_partition_mount_options variable for tmp.mount template
  • vars/is_container.yml: Added missing ubtu22cis_rule_6_2_1_1 to container skip list — auditd package install requires kernel audit subsystem unavailable in containers
  • 18 files: Added lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" to all remaining ansible.builtin.package tasks across the role — prevents apt/dpkg frontend lock failures when unattended-upgrades or other apt processes are running (extends fix for #​330)
Already Fixed (verified in this pass)
  • pwck/getent SIGPIPE rc=141: All pwck and getent tasks already use failed_when: false — no changes needed
  • UFW "all" loop error (#​328): Rule 4.1.4 already has separate when conditions for string "all" vs list of port dicts — no changes needed


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: Renovate Bot <bot@renovateapp.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant