Hi Devansh,
On 8/24/26 1:01 PM, Devansh Patel via lists.openembedded.org wrote:
From: Devansh Patel <[email protected]>
The current inherited "u-boot-tools" identity has no vulnerability records even
though this recipe builds host utilities from the U-Boot source tree, so
source-aligned CVEs are missed.
Use "u-boot:u-boot" for the CNA affected-data identity and
"denx:u-boot" for the NVD dictionary CPE and configuration identity.
How about using a file that is included by both u-boot-tools and u-boot
so that we don't have to not forget to update both?
u-boot-common.inc is included by both u-boot-tools.bb and u-boot.bb so
that seems like an ideal candidate (if so, then we probably could remove
CVE_PRODUCT from u-boot.inc?)
We only have denx:u-boot today in u-boot.inc, how did you come to the
conclusion we also needed u-boot:u-boot?
Cheers,
Quentin
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244092):
https://lists.openembedded.org/g/openembedded-core/message/244092
Mute This Topic: https://lists.openembedded.org/mt/120901049/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-