On 19 June 2017 at 14:20, Philip Balister <phi...@balister.org> wrote:

> So the issue is leaking credentials, not build system paths? I mention
> this because we do leak build system paths into images in other places.
>

Yes, SRC_URI can contain username/passwords, and even if you filter those
out explicitly you can expose internal hostnames and so on.

Ross
-- 
_______________________________________________
Openembedded-core mailing list
Openembedded-core@lists.openembedded.org
http://lists.openembedded.org/mailman/listinfo/openembedded-core

Reply via email to