Since v1.3.4, `sbom-cve-check` includes a new `--offline-mode` flag that
raises an error if a git command requiring network access is executed.
Note that `--offline-mode` does not automatically enable
`--disable-auto-updates`, so both flags must be specified explicitly.

For example, with the `--offline-mode` flag, if the CVE database is not
already deployed, `sbom-cve-check` will not attempt to clone the git
database, it will generate an explicit error instead.

Signed-off-by: Benjamin Robin (Schneider Electric) <[email protected]>
---
 meta/classes/sbom-cve-check-common.bbclass | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/classes/sbom-cve-check-common.bbclass 
b/meta/classes/sbom-cve-check-common.bbclass
index 1bd1af22b6cb..7918cb25f2a7 100644
--- a/meta/classes/sbom-cve-check-common.bbclass
+++ b/meta/classes/sbom-cve-check-common.bbclass
@@ -102,6 +102,7 @@ def run_sbom_cve_check(d, sbom_path, export_base_name, 
export_link_name=None):
         "--sbom-path",
         sbom_path,
         "--disable-auto-updates",
+        "--offline-mode",
         "--export-process-native",
         scan_scope,
     ]

-- 
2.55.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245251): 
https://lists.openembedded.org/g/openembedded-core/message/245251
Mute This Topic: https://lists.openembedded.org/mt/121127236/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to