On Tue, Aug 25, 2026 at 16:05:39 +0200, Peter Krempa via Devel wrote:
> From: Peter Krempa <[email protected]>
> 
> Introduce a job which will run with the scheduled libvirt pipeline runs
> which will check if all CVEs mentioned in the git commit messages, NEWS
> entries and for all libvirt security notices published at
> https://security.libvirt.org have corresponding git tags.
> 
> Since git commit messages do sometimes mention CVE not related to
> libvirt, the '.cve_exceptions' file lists allows to add overrides.
> 
> Since the upstream repository has signed tags, the tagging is done by
> Jirka, so it doesn't make sense to run this check inside the checkout or
> as a regular CI pipeline run, so it's implemented directly in the CI job
> rather than as a standalone tool.
> 
> The job also creates an artifact containing all tagged CVEs in the
> repository. This can later be used e.g. to see which CVEs are missing a
> libvirt security notice.
> 
> Signed-off-by: Peter Krempa <[email protected]>
> ---
>  .cve_exceptions | 46 +++++++++++++++++++++++++++++++++++++++++++++
>  .gitlab-ci.yml  | 50 +++++++++++++++++++++++++++++++++++++++++++++++++
>  2 files changed, 96 insertions(+)
>  create mode 100644 .cve_exceptions

This is how the pipeline result looks when it picks up something that
needs to be tagged:

https://gitlab.com/pipo.sk/testlibvirt/-/jobs/16094064680

> 
> In order for this to pass the following CVEs need to be tagged (the
> order of the commit IDs is as 'git log' shows):

And after this list of commits is tagged successful result:

https://gitlab.com/pipo.sk/testlibvirt/-/jobs/16094536454

Reply via email to