]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
builder: set CVE_PRODUCT
authorPeter Marko <peter.marko@siemens.com>
Thu, 5 Dec 2024 23:41:39 +0000 (00:41 +0100)
committerSteve Sakoman <steve@sakoman.com>
Fri, 6 Dec 2024 17:10:53 +0000 (09:10 -0800)
Builder is a common word and there are many other builder components
which makes us to ignore CVEs for all of them.
There is already 1 ignored and currently 3 new ones.

Instead, set product to yocto to filter them.

(From OE-Core rev: fd4ec5a5318b36af0a9a0a097a5b1f1de44a8edf)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-graphics/builder/builder_0.1.bb

index 7719b783c2626806522767813f4b4b8cfb6703cf..39abaf31ce5c03c2c12db07f665997a9638d83c6 100644 (file)
@@ -29,4 +29,5 @@ do_install () {
        chown  builder.builder ${D}${sysconfdir}/mini_x/session.d/builder_session.sh
 }
 
-CVE_STATUS[CVE-2008-4178] = "cpe-incorrect: This CVE is for an unrelated builder"
+# do not report CVEs for other builder apps
+CVE_PRODUCT = "yoctoproject:builder"