| Rule | CIS | Reason |
|---|
| aide_build_database | 6.3.1 | building the AIDE database of a GitHub runner (a large, short-lived toolchain image) did not finish in 15 minutes (spike run 37055526938); file integrity monitoring belongs on long-lived servers |
| nftables_rules_permanent | 4.3 | CIS 4.1.1 asks for a single firewall utility and this lab uses ufw (4.2); the profile also checks the nftables variant (4.3), whose rules cannot pass while ufw manages the firewall |
| package_aide_installed | 6.3.1 | building the AIDE database of a GitHub runner (a large, short-lived toolchain image) did not finish in 15 minutes (spike run 37055526938); file integrity monitoring belongs on long-lived servers |
| package_ufw_removed | 4.3 | CIS 4.1.1 asks for a single firewall utility and this lab uses ufw (4.2); the profile also checks the nftables variant (4.3), whose rules cannot pass while ufw manages the firewall |
| partition_for_tmp | 1.1.2.1.1 | a booted CI runner cannot be repartitioned; /tmp stays on the root filesystem |
| service_nftables_enabled | 4.3 | CIS 4.1.1 asks for a single firewall utility and this lab uses ufw (4.2); the profile also checks the nftables variant (4.3), whose rules cannot pass while ufw manages the firewall |
| set_nftables_loopback_traffic | 4.3 | CIS 4.1.1 asks for a single firewall utility and this lab uses ufw (4.2); the profile also checks the nftables variant (4.3), whose rules cannot pass while ufw manages the firewall |
| set_nftables_table | 4.3 | CIS 4.1.1 asks for a single firewall utility and this lab uses ufw (4.2); the profile also checks the nftables variant (4.3), whose rules cannot pass while ufw manages the firewall |