From: Adrian Bunk <bunk@stusta.de>
To: akuster808 <akuster808@gmail.com>
Cc: Patches and discussions about the oe-core layer
<openembedded-core@lists.openembedded.org>
Subject: Re: [RFC][PATCH 1/2] nss: Move to meta-oe
Date: Thu, 27 Feb 2020 15:27:29 +0200 [thread overview]
Message-ID: <20200227132729.GA6240@localhost> (raw)
In-Reply-To: <e43b3057-37d5-7a35-b988-7307cc7fd67f@gmail.com>
On Mon, Feb 24, 2020 at 08:32:24AM -0800, akuster808 wrote:
>...
> On 2/23/20 9:17 PM, Adrian Bunk wrote:
> > On Sun, Feb 23, 2020 at 04:25:18PM -0800, Khem Raj wrote:
> >> On Sun, Feb 23, 2020 at 11:34 AM Adrian Bunk <bunk@stusta.de> wrote:
> >>> rpm was the last user in OE-core.
> >> we should also assess external dependencies especially on libraries,
> >> there might be layers which do not depend on meta-oe but use nss
> >> or enable nss packageconfigs in core components like curl.
> >> ...
> > Is providing a crypto library in OE-core without providing security
> > support better than not shipping it?
> >
> > nss in warrior seems to lack fixes for at least 5 CVEs.
>
> I don't see how that is relevant to the RFC?
>...
It is a crypto library with a history of unfixed CVEs in supported
stable Yocto releases.
> - armin
cu
Adrian
next prev parent reply other threads:[~2020-02-27 13:27 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-02-23 19:34 [RFC][PATCH 1/2] nss: Move to meta-oe Adrian Bunk
2020-02-23 19:34 ` [RFC][PATCH 2/2] nspr: " Adrian Bunk
2020-02-24 0:25 ` [RFC][PATCH 1/2] nss: " Khem Raj
2020-02-24 5:17 ` Adrian Bunk
2020-02-24 16:32 ` akuster808
2020-02-27 13:27 ` Adrian Bunk [this message]
2020-02-27 14:03 ` Alexander Kanavin
2020-03-04 9:05 ` Adrian Bunk
2020-03-04 9:36 ` Alexander Kanavin
2020-03-04 11:32 ` Adrian Bunk
2020-03-04 12:13 ` Alexander Kanavin
2020-03-04 14:01 ` Does YP provide security support for stable and LTS branches? Adrian Bunk
2020-03-04 16:00 ` Alexander Kanavin
2020-03-04 17:24 ` Adrian Bunk
2020-03-04 20:26 ` [Openembedded-architecture] " akuster808
2020-03-06 10:04 ` Adrian Bunk
2020-03-06 10:36 ` Richard Purdie
2020-03-08 21:46 ` Adrian Bunk
2020-03-08 22:08 ` Alexander Kanavin
2020-03-09 0:23 ` Adrian Bunk
2020-03-09 7:29 ` Ayoub Zaki
2020-03-09 9:53 ` Alexander Kanavin
2020-03-09 12:45 ` Richard Purdie
2020-03-10 16:11 ` Ross Burton
2020-03-10 19:45 ` Ayoub Zaki
2020-03-11 14:53 ` Ross Burton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200227132729.GA6240@localhost \
--to=bunk@stusta.de \
--cc=akuster808@gmail.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox