]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
cve-check: don't warn if a patch is remote
authorRoss Burton <ross.burton@arm.com>
Fri, 3 Nov 2023 13:28:11 +0000 (13:28 +0000)
committerSteve Sakoman <steve@sakoman.com>
Mon, 13 Nov 2023 15:34:11 +0000 (05:34 -1000)
commit32a19dfbaac38cd4864281a1131ac65e1216318f
tree78d342351408dfd6ac176e337f71a08f530ce100
parente3574760ee59c1ca7d2698f09ddd37ee568f04f3
cve-check: don't warn if a patch is remote

We don't make do_cve_check depend on do_unpack because that would be a
waste of time 99% of the time.  The compromise here is that we can't
scan remote patches for issues, but this isn't a problem so downgrade
the warning to a note.

Also move the check for CVEs in the filename before the local file check
so that even with remote patches, we still check for CVE references in
the name.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 0251cad677579f5b4dcc25fa2f8552c6040ac2cf)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/lib/oe/cve_check.py