]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
cve-check: Fix false negative version issue
authorGeoffrey GIRY <geoffrey.giry@smile.fr>
Tue, 28 Mar 2023 10:23:49 +0000 (12:23 +0200)
committerSteve Sakoman <steve@sakoman.com>
Thu, 30 Mar 2023 18:29:50 +0000 (08:29 -1000)
commitf331c80df6c447d3073ebe3f00102c78ced242f3
tree82e662669123b2cf1801da02b82f6b79883749c2
parent699ed495ee65991bf4ab286070d72109e72b1f81
cve-check: Fix false negative version issue

NVD DB store version and update in the same value, separated by '_'.
The proposed patch check if the version from NVD DB contains a "_",
ie 9.2.0_p1 is convert to 9.2.0p1 before version comparison.

[YOCTO #14127]

Reviewed-by: Yoann CONGAL <yoann.congal@smile.fr>
Signed-off-by: Geoffrey GIRY <geoffrey.giry@smile.fr>
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
(cherry picked from commit 7d00f6ec578084a0a0e5caf36241d53036d996c4)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/classes/cve-check.bbclass
meta/lib/oe/cve_check.py
meta/lib/oeqa/selftest/cases/cve_check.py