Re: [gentoo-dev] extending metadata.xml to support CPE information

2013-05-09 Thread Sven Vermeulen
On Wed, May 08, 2013 at 09:06:00PM -0400, Mike Frysinger wrote: On Wednesday 08 May 2013 21:01:19 Mike Frysinger wrote: On Tuesday 07 May 2013 23:59:18 Mike Frysinger wrote: we've already got a database for maintaining this sort of thing on a per- package basis: metadata.xml. so let's

Re: [gentoo-dev] extending metadata.xml to support CPE information

2013-05-08 Thread Sergey Popov
08.05.2013 07:59, Mike Frysinger пишет: the guys who maintain the security CVE project [1] [2] (designed to be the authority when it comes to indexing security related vulnerabilities in projects) have a CPE specification [3] to make tracking CVEs back to a canonical source in a machine

Re: [gentoo-dev] extending metadata.xml to support CPE information

2013-05-08 Thread Sven Vermeulen
On Tue, May 07, 2013 at 11:59:18PM -0400, Mike Frysinger wrote: the guys who maintain the security CVE project [1] [2] (designed to be the authority when it comes to indexing security related vulnerabilities in projects) have a CPE specification [3] to make tracking CVEs back to a canonical

Re: [gentoo-dev] extending metadata.xml to support CPE information

2013-05-08 Thread Mike Frysinger
On Tuesday 07 May 2013 23:59:18 Mike Frysinger wrote: we've already got a database for maintaining this sort of thing on a per- package basis: metadata.xml. so let's extend the DTD to cover this. the existing remote-id field looks like a pretty good fit, so the proposal is simple: add a new

Re: [gentoo-dev] extending metadata.xml to support CPE information

2013-05-08 Thread Mike Frysinger
On Wednesday 08 May 2013 21:01:19 Mike Frysinger wrote: On Tuesday 07 May 2013 23:59:18 Mike Frysinger wrote: we've already got a database for maintaining this sort of thing on a per- package basis: metadata.xml. so let's extend the DTD to cover this. the existing remote-id field looks

[gentoo-dev] extending metadata.xml to support CPE information

2013-05-07 Thread Mike Frysinger
the guys who maintain the security CVE project [1] [2] (designed to be the authority when it comes to indexing security related vulnerabilities in projects) have a CPE specification [3] to make tracking CVEs back to a canonical source in a machine parseable format. the ChromiumOS project wants

Re: [gentoo-dev] extending metadata.xml to support CPE information

2013-05-07 Thread Rick Zero_Chaos Farina
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 05/07/2013 11:59 PM, Mike Frysinger wrote: the guys who maintain the security CVE project [1] [2] (designed to be the authority when it comes to indexing security related vulnerabilities in projects) have a CPE specification [3] to make