mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-05-07 05:10:20 +00:00
nodejs: ignore fixed CVEs
All these CVEs are fixed in v22.22.2[1], except for CVE-2026-21712, which does not affect v22 series, because it was introduced in a later version[2]. All these CVEs are tracked without version info by NVD at the time of creating this patch. [1]: https://github.com/nodejs/node/blob/v22.x/doc/changelogs/CHANGELOG_V22.md [2]: https://nodejs.org/en/blog/vulnerability/march-2026-security-releases Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
This commit is contained in:
@@ -214,3 +214,10 @@ python __anonymous () {
|
||||
}
|
||||
|
||||
BBCLASSEXTEND = "native"
|
||||
|
||||
CVE_STATUS[CVE-2026-21712] = "cpe-incorrect: only v24 and v25 are affected"
|
||||
CVE_STATUS[CVE-2026-21713] = "fixed-version: fixed since v22.22.2"
|
||||
CVE_STATUS[CVE-2026-21714] = "fixed-version: fixed since v22.22.2"
|
||||
CVE_STATUS[CVE-2026-21715] = "fixed-version: fixed since v22.22.2"
|
||||
CVE_STATUS[CVE-2026-21716] = "fixed-version: fixed since v22.22.2"
|
||||
CVE_STATUS[CVE-2026-21717] = "fixed-version: fixed since v22.22.2"
|
||||
|
||||
Reference in New Issue
Block a user