Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Thomas Petazzoni via buildroot <buildroot@buildroot.org>
To: Thomas Perale <thomas.perale@mind.be>
Cc: Thomas Perale via buildroot <buildroot@buildroot.org>,
	Christian Stewart <christian@aperture.us>,
	Thomas Perale <thomas.perale@essensium.com>
Subject: Re: [Buildroot] [PATCH 0/7] Add PURL support
Date: Fri, 18 Apr 2025 12:39:59 +0200	[thread overview]
Message-ID: <20250418123959.3307e037@windsurf> (raw)
In-Reply-To: <221f0412-b320-4ade-8936-9ae8d941ebf7@mind.be>

Hello,

On Wed, 16 Apr 2025 22:49:15 +0200
Thomas Perale <thomas.perale@mind.be> wrote:

> Just to say that with the PURL added to the Django package I got 
> notified for the CVE.

But with what tool? Right now our "reference" tool to track CVEs in
Buildroot is support/scripts/pkg-stats, which renders:

  http://autobuild.buildroot.net/stats/master.html

And which uses the CVE database from
https://github.com/fkie-cad/nvd-json-data-feeds/.

So I'm still not sure to understand your "DependencyTrack uses NVD
annotation unfortunately". Could you clarify?

Right now, packages have a CPE ID, which we use to match
against https://github.com/fkie-cad/nvd-json-data-feeds/ as part
of the pkg-stats tool. If we want to add more identifiers in packages,
it has to be clear with which CVE database this works, and how this is
going to interact with pkg-stats (and if it doesn't interact, why).

Best regards,

Thomas
-- 
Thomas Petazzoni, co-owner and CEO, Bootlin
Embedded Linux and Kernel engineering and training
https://bootlin.com
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2025-04-18 10:40 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-15 19:55 [Buildroot] [PATCH 0/7] Add PURL support Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 1/7] package/pkg-generic.mk: add PURL package variable Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 2/7] package/pkg-download: add 'owner' macro Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 2/7] package/pkg-download: add repository macro Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 3/7] package/pkg-golang: support PURL generation Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 4/7] package/pkg-cargo: " Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 5/7] package/pkg-perl: " Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 6/7] package/pkg-python: " Thomas Perale via buildroot
2025-04-15 19:55 ` [Buildroot] [PATCH 7/7] package/pkg-utils: add PURL to show-info output Thomas Perale via buildroot
2025-04-16 19:07 ` [Buildroot] [PATCH 0/7] Add PURL support Peter Korsgaard
2025-04-16 19:19   ` Arnout Vandecappelle via buildroot
     [not found]     ` <4b029329-2258-428d-80c9-315dbd6335be@essensium.com>
2025-04-16 19:58       ` Thomas Petazzoni via buildroot
2025-04-16 20:06         ` Thomas Perale via buildroot
2025-04-16 20:40           ` Thomas Petazzoni via buildroot
2025-04-16 20:49             ` Thomas Perale via buildroot
2025-04-18 10:39               ` Thomas Petazzoni via buildroot [this message]
2025-04-21 20:19                 ` Thomas Perale via buildroot
2025-04-22 12:53                   ` Thomas Petazzoni via buildroot
2025-04-22 14:00                     ` Peter Korsgaard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250418123959.3307e037@windsurf \
    --to=buildroot@buildroot.org \
    --cc=christian@aperture.us \
    --cc=thomas.perale@essensium.com \
    --cc=thomas.perale@mind.be \
    --cc=thomas.petazzoni@bootlin.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox