Ubuntu STIG / CMMC Linux Preflight
A signed, versioned Linux collector bundle that produces a locally reviewable evidence package without changing the host.
Public release · version 1.0.0
Context
Linux teams need to see which host evidence is available before mapping remediation or assessment work.
Constraint
Host configuration may be sensitive, so collection, inspection, upload, and review must remain separate operator decisions.
Work
TacitSoft published the collector source, installer, dry-run path, bundle specification, SBOM, checksums, detached signature, provenance record, and public key.
Architecture
- Versioned shell collector with a no-remediation execution policy
- Declared bundle schema, manifest, checksums, and sensitivity metadata
- SBOM, release provenance, detached checksum signature, and public key
- Canonical source synchronized with the downloadable release
Verified current state
Version 1.0.0 is publicly downloadable with checksum and signature verification, a dry-run path, and automated source-to-release parity tests.
- Evidence strength
- Signed public release
- Evidence basis
- Canonical versioned source, published archive, SHA-256 manifest, detached signature, SBOM, provenance record, and release-parity tests.
Operating responsibility
TacitSoft publishes and tests the collector release. The operator runs it locally, reviews every generated file, and initiates any later upload separately.
What remains private
No collected host data is included. Generated bundles may contain sensitive configuration and remain local until an operator reviews them.