diff --git a/tasks/prelim.yml b/tasks/prelim.yml index c560eed..52fc10f 100644 --- a/tasks/prelim.yml +++ b/tasks/prelim.yml @@ -25,6 +25,10 @@ changed_when: false check_mode: false +- name: "PRELIM | Gather package facts" + package_facts: + manager: auto + - name: "PRELIM | Run apt cache update" apt: update_cache: true diff --git a/tasks/section6.yml b/tasks/section6.yml index 44f904d..5ddffb9 100644 --- a/tasks/section6.yml +++ b/tasks/section6.yml @@ -250,18 +250,6 @@ - patch - rule_6.2.5 -- name: "SCORED | 6.2.6 | PATCH | Ensure root PATH Integrity" - command: /bin/true - changed_when: false - when: - - debian9cis_rule_6_2_6 - tags: - - level1 - - scored - - patch - - rule_6.2.6 - - notimplemented - - name: "SCORED | 6.2.6 | PATCH | Ensure root PATH Integrity" shell: | set -o pipefail @@ -280,6 +268,7 @@ changed_when: false check_mode: false when: + - "'sudo' in ansible_facts.packages" - debian9cis_rule_6_2_6 tags: - level1 @@ -294,6 +283,8 @@ line: '\1"{{ fixsudo.stdout_lines[0] }}"' backrefs: true when: + - "'sudo' in ansible_facts.packages" + - debian9cis_rule_6_2_6 - fixsudo.stdout_lines[0] tags: - level1