apache2: add vendor to product name used for CVE checking

This recipe sets the product name used for CVE checking to
"http_server". However, the cve-check logic matches that name to all
products in the CVE database regardless of vendor. Currently, it is
matching to products from vendors other than apache. As a result,
CVE checking incorrectly reports CVEs for those vendors' products for
this package.

Signed-off-by: Jeffrey Pautler <jeffrey.pautler@ni.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 51f70eaaa5)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
This commit is contained in:
Jeffrey Pautler
2023-11-10 10:14:04 -06:00
committed by Armin Kuster
parent f27be5ba3f
commit 60cb911925
@@ -36,7 +36,7 @@ inherit autotools update-rc.d pkgconfig systemd update-alternatives
DEPENDS = "openssl expat pcre apr apr-util apache2-native " DEPENDS = "openssl expat pcre apr apr-util apache2-native "
CVE_PRODUCT = "http_server" CVE_PRODUCT = "apache:http_server"
SSTATE_SCAN_FILES += "apxs config_vars.mk config.nice" SSTATE_SCAN_FILES += "apxs config_vars.mk config.nice"