All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH 1/1] package/go: add GO_CPE_ID_VENDOR
@ 2021-01-11 20:36 Fabrice Fontaine
  2021-01-11 20:51 ` Thomas Petazzoni
  0 siblings, 1 reply; 2+ messages in thread
From: Fabrice Fontaine @ 2021-01-11 20:36 UTC (permalink / raw)
  To: buildroot

golang is the correct CPE ID vendor for the go package, see:
https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Agolang%3Ago

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
---
 package/go/go.mk | 1 +
 1 file changed, 1 insertion(+)

diff --git a/package/go/go.mk b/package/go/go.mk
index e9f8be7783..e65b24364f 100644
--- a/package/go/go.mk
+++ b/package/go/go.mk
@@ -10,6 +10,7 @@ GO_SOURCE = go$(GO_VERSION).src.tar.gz
 
 GO_LICENSE = BSD-3-Clause
 GO_LICENSE_FILES = LICENSE
+GO_CPE_ID_VENDOR = golang
 
 HOST_GO_DEPENDENCIES = host-go-bootstrap
 HOST_GO_GOPATH = $(HOST_DIR)/usr/share/go-path
-- 
2.29.2

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* [Buildroot] [PATCH 1/1] package/go: add GO_CPE_ID_VENDOR
  2021-01-11 20:36 [Buildroot] [PATCH 1/1] package/go: add GO_CPE_ID_VENDOR Fabrice Fontaine
@ 2021-01-11 20:51 ` Thomas Petazzoni
  0 siblings, 0 replies; 2+ messages in thread
From: Thomas Petazzoni @ 2021-01-11 20:51 UTC (permalink / raw)
  To: buildroot

On Mon, 11 Jan 2021 21:36:24 +0100
Fabrice Fontaine <fontaine.fabrice@gmail.com> wrote:

> golang is the correct CPE ID vendor for the go package, see:
> https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Agolang%3Ago
> 
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
> ---
>  package/go/go.mk | 1 +
>  1 file changed, 1 insertion(+)

Applied to master, thanks. Notice that the CPE dictionary only has up
to 1.15.5, while we have 1.15.6 in Buildroot. So this would be a good
case of using the "missing-cpe" target that
https://patchwork.ozlabs.org/project/buildroot/list/?series=223181 is
introducing, and then see how it goes in submitting the resulting XML
to NIST.

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2021-01-11 20:51 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-01-11 20:36 [Buildroot] [PATCH 1/1] package/go: add GO_CPE_ID_VENDOR Fabrice Fontaine
2021-01-11 20:51 ` Thomas Petazzoni

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.