Bugzilla – Bug 1150557
AUDIT-1: tmpwatch: review of cron job file(s): /etc/cron.daily/tmpwatch
Last modified: 2019-11-15 14:02:33 UTC
+++ This bug was initially created as a clone of Bug #1150175 As discussed in the proactive security team we want to restrict the installation of cron job files in the future. To achieve this we first need to cover the currently existing packages that do this. tmpwatch installs a cron file in /etc/cron.daily/tmpwatch. It should be reviewed and whitelisted if all is well.
the functionality of tmpwatch and more is provided by systemd-tmpfiles nowadays, you could also consider filling a drop request instead.
(In reply to crrodriguez@opensuse.org from comment #1) > the functionality of tmpwatch and more is provided by systemd-tmpfiles > nowadays, you could also consider filling a drop request instead. Thanks for the hint. We will consider it. A review makes sense anyways since the package is still shipped with older products. It will take some time until we manage to review all affected packages.
The file-handling had me do a double-take, but it's safe after all. So this is fine.