Support validated custom audit profile files through the shared engine (#416)

* Support validated operator-owned advanced audit profile files

* Reject lenient custom profile JSON and protect report output aliases

* Link custom audit profile changelog to PR 416

* Make custom JSON rejection fixtures portable across PowerShell versions
This commit is contained in:
田中ザック Isaac Mathis authored and GitHub committed 2026-09-20 18:09:52 +09:00
1 parent 4431533535
commit 83b2ddd526
14 files changed
+715 -9

No files matched your search

@@ -0,0 +1,29 @@
name: Custom audit profile regressions
on:
push:
branches: ['**']
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
custom-profiles:
strategy:
fail-fast: false
matrix:
os: [windows-2022, windows-2025]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Strict input and mocked configuration on Windows PowerShell 5.1
shell: powershell
run: ./tests/CustomAuditProfiles.Tests.ps1
- name: Native read-only custom audit on Windows PowerShell 5.1
shell: powershell
run: ./tests/CustomAuditProfiles.Windows.Tests.ps1
- name: Strict input and mocked configuration on PowerShell 7
shell: pwsh
run: ./tests/CustomAuditProfiles.Tests.ps1
- name: Native read-only custom audit on PowerShell 7
shell: pwsh
run: ./tests/CustomAuditProfiles.Windows.Tests.ps1