mirror of
https://git.yoctoproject.org/poky
synced 2026-05-30 00:20:08 +00:00
cve_check: convert CVE_CHECK_IGNORE to CVE_STATUS
- Try to add convert and apply statuses for old CVEs - Drop some obsolete ignores, while they are not relevant for current version (From OE-Core rev: 1634ed4048cf56788cd5c2c1bdc979b70afcdcd7) Signed-off-by: Andrej Valek <andrej.valek@siemens.com> Reviewed-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
7e18a90d35
commit
c15e506a46
@@ -26,10 +26,10 @@ SRC_URI[sha256sum] = "e87aae032bf07c26f85ac0ed3250998c37621d95f8bd748b31f15b33c4
|
||||
|
||||
GITHUB_BASE_URI = "https://github.com/westes/flex/releases"
|
||||
|
||||
# Disputed - yes there is stack exhaustion but no bug and it is building the
|
||||
# parser, not running it, effectively similar to a compiler ICE. Upstream no plans to address
|
||||
# https://github.com/westes/flex/issues/414
|
||||
CVE_CHECK_IGNORE += "CVE-2019-6293"
|
||||
CVE_STATUS[CVE-2019-6293] = "upstream-wontfix: \
|
||||
there is stack exhaustion but no bug and it is building the \
|
||||
parser, not running it, effectively similar to a compiler ICE. Upstream no plans to address this."
|
||||
|
||||
inherit autotools gettext texinfo ptest github-releases
|
||||
|
||||
|
||||
Reference in New Issue
Block a user