From: "Anatol Belski" <anbelski@linux.microsoft.com>
To: Mikko Rapeli <mikko.rapeli@bmw.de>
Cc: openembedded-core@lists.openembedded.org
Subject: Re: [OE-core] [dunfell][PATCH] glib-2.0: Rename patch file for CVE-2020-35457
Date: Wed, 3 Feb 2021 15:54:17 +0100 [thread overview]
Message-ID: <30a17ea8-3af9-026b-64eb-5d25f34bae77@linux.microsoft.com> (raw)
In-Reply-To: <YBp0r/IvR1vFubjt@korppu>
[-- Attachment #1: Type: text/plain, Size: 937 bytes --]
Hi,
On 2/3/2021 11:02 AM, Mikko Rapeli wrote:
> Hi,
>
> On Wed, Feb 03, 2021 at 08:42:57AM +0000, Anatol Belski wrote:
>> The naming convention needs to be help so the CVE is recognized as
>> fixed by the tooling.
> Yocto CVE checker does detect CVE patches also from patch comments so
> this change is not needed for that. This is sufficient:
>
> poky$ git grep CVE-2020-35457
> meta/recipes-core/glib-2.0/glib-2.0/0001-goption-Add-a-precondition-to-avoid-GOptionEntry-lis.patch:CVE: CVE-2020-35457
>
> Is there some other tooling that you are referring to?
I should have read meta/classes/cve-check.bbclass before :) Looks like
it was a wrong impression on my side, that the filename needs to match
there, also when working with older versions. Thanks for the
explanation, indeed there's no action required on this, I didn't refer
to any other tools.
Regards
Anatol
> Cheers,
>
> -Mikko
>
>
>
[-- Attachment #2: Type: text/html, Size: 1726 bytes --]
prev parent reply other threads:[~2021-02-03 14:54 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-02-03 8:42 [dunfell][PATCH] glib-2.0: Rename patch file for CVE-2020-35457 Anatol Belski
2021-02-03 10:02 ` [OE-core] " Mikko Rapeli
2021-02-03 14:38 ` Steve Sakoman
2021-02-03 15:03 ` Anatol Belski
2021-02-03 15:53 ` Mikko Rapeli
2021-02-03 16:31 ` Steve Sakoman
2021-02-03 14:54 ` Anatol Belski [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=30a17ea8-3af9-026b-64eb-5d25f34bae77@linux.microsoft.com \
--to=anbelski@linux.microsoft.com \
--cc=mikko.rapeli@bmw.de \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.