| Message ID | 20241124122711.18001-1-peter.marko@siemens.com |
|---|---|
| State | Accepted, archived |
| Commit | fd4ec5a5318b36af0a9a0a097a5b1f1de44a8edf |
| Headers | show |
| Series | builder: set CVE_PRODUCT | expand |
On 24 Nov 2024, at 12:27, Peter Marko via lists.openembedded.org <peter.marko=siemens.com@lists.openembedded.org> wrote: > -CVE_STATUS[CVE-2008-4178] = "cpe-incorrect: This CVE is for an unrelated builder" > +# do not report CVEs for other builder apps > +CVE_PRODUCT = "yocto:builder" Please don’t make up vendor names. There are already yocto_project and yoctoproject vendors so let's not add another variation. Personally, I lean towards yoctoproject. Ross
Hi Ross, I have realized this and sent v2 with yoctoproject only 10 minutes after sending this patch. I guess I have forgotten to chain it with --in-reply-to=, sorry for that. Peter > -----Original Message----- > From: Ross Burton <Ross.Burton@arm.com> > Sent: Monday, November 25, 2024 12:30 > To: Marko, Peter (FT D EU SK BFS1) <Peter.Marko@siemens.com> > Cc: openembedded-core@lists.openembedded.org > Subject: Re: [OE-core][PATCH] builder: set CVE_PRODUCT > > On 24 Nov 2024, at 12:27, Peter Marko via lists.openembedded.org > <peter.marko=siemens.com@lists.openembedded.org> wrote: > > -CVE_STATUS[CVE-2008-4178] = "cpe-incorrect: This CVE is for an unrelated > builder" > > +# do not report CVEs for other builder apps > > +CVE_PRODUCT = "yocto:builder" > > Please don’t make up vendor names. There are already yocto_project and > yoctoproject vendors so let's not add another variation. Personally, I lean > towards yoctoproject. > > Ross
On 25 Nov 2024, at 12:09, Marko, Peter <Peter.Marko@siemens.com> wrote: > > Hi Ross, > > I have realized this and sent v2 with yoctoproject only 10 minutes after sending this patch. > I guess I have forgotten to chain it with --in-reply-to=, sorry for that. So you did, sorry about that. Drive-by review over a coffee on a Monday might not be a good idea :) Ross
diff --git a/meta/recipes-graphics/builder/builder_0.1.bb b/meta/recipes-graphics/builder/builder_0.1.bb index 7719b783c2..c0c271d564 100644 --- a/meta/recipes-graphics/builder/builder_0.1.bb +++ b/meta/recipes-graphics/builder/builder_0.1.bb @@ -29,4 +29,5 @@ do_install () { chown builder.builder ${D}${sysconfdir}/mini_x/session.d/builder_session.sh } -CVE_STATUS[CVE-2008-4178] = "cpe-incorrect: This CVE is for an unrelated builder" +# do not report CVEs for other builder apps +CVE_PRODUCT = "yocto:builder"