* [PATCH v3 0/4] generate-cve-exclusions: Add a new bbclass
@ 2026-01-06 20:46 ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 1/4] generate-cve-exclusions: Add --output-json option ValentinBoudevin
` (3 more replies)
0 siblings, 4 replies; 6+ messages in thread
From: ValentinBoudevin @ 2026-01-06 20:46 UTC (permalink / raw)
To: openembedded-core; +Cc: ValentinBoudevin
Use the script generate-cve-exclusions.py in a class to generate kernel CVE
exclusion from cvelistV5 and integrates it into linux-yocto.
Changes since v2:
- Patch 4/4: Inherit the new bbclass in linux-yocto.inc instead of
individual recipes.
Changes since v1:
- Patch 2/4: Removed the mandatory execution of the
generate-cve-exclusions class on every build. It now needs to be
manually run using:
bitbake -c generate-cve-exclusions <kernel-recipe>
ValentinBoudevin (4):
generate-cve-exclusions: Add --output-json option
generate-cve-exclusions: Add a .bbclass
generate-cve-exclusions: Move python script
linux: Add inherit on generate-cve-exclusions
meta/classes/generate-cve-exclusions.bbclass | 67 +++++++++++++++++++
meta/recipes-kernel/linux/linux-yocto.inc | 3 +
.../contrib}/generate-cve-exclusions.py | 64 ++++++++++++++----
3 files changed, 120 insertions(+), 14 deletions(-)
create mode 100644 meta/classes/generate-cve-exclusions.bbclass
rename {meta/recipes-kernel/linux => scripts/contrib}/generate-cve-exclusions.py (71%)
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v3 1/4] generate-cve-exclusions: Add --output-json option
2026-01-06 20:46 [PATCH v3 0/4] generate-cve-exclusions: Add a new bbclass ValentinBoudevin
@ 2026-01-06 20:46 ` ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 2/4] generate-cve-exclusions: Add a .bbclass ValentinBoudevin
` (2 subsequent siblings)
3 siblings, 0 replies; 6+ messages in thread
From: ValentinBoudevin @ 2026-01-06 20:46 UTC (permalink / raw)
To: openembedded-core; +Cc: ValentinBoudevin
This option "--output-json" can be used to return a json file instead of
the standard .inc file provided.
The JSON file can easily be manipulated contrary to the .inc file.
Example output structure of the JSON file:
```json
{
"cve_status": {
"CVE-2019-25160": {
"active": false,
"message": "fixed-version: Fixed from version 5.0"
},
"CVE-2019-25162": {
"active": false,
"message": "fixed-version: Fixed from version 6.0"
},
...
```
Also, this commit doesn't affect or modify any existing behaviour of the
script.
Signed-off-by: Valentin Boudevin <valentin.boudevin@gmail.com>
---
.../linux/generate-cve-exclusions.py | 64 +++++++++++++++----
1 file changed, 50 insertions(+), 14 deletions(-)
diff --git a/meta/recipes-kernel/linux/generate-cve-exclusions.py b/meta/recipes-kernel/linux/generate-cve-exclusions.py
index dfc16663a5..5a0a947e06 100755
--- a/meta/recipes-kernel/linux/generate-cve-exclusions.py
+++ b/meta/recipes-kernel/linux/generate-cve-exclusions.py
@@ -91,6 +91,7 @@ def main(argp=None):
parser = argparse.ArgumentParser()
parser.add_argument("datadir", type=pathlib.Path, help="Path to a clone of https://github.com/CVEProject/cvelistV5 or https://git.kernel.org/pub/scm/linux/security/vulns.git")
parser.add_argument("version", type=Version, help="Kernel version number to generate data for, such as 6.1.38")
+ parser.add_argument("--output-json", action="store_true", help="Return CVE_STATUS mapping as JSON")
args = parser.parse_args(argp)
datadir = args.datadir.resolve()
@@ -99,7 +100,10 @@ def main(argp=None):
data_version = subprocess.check_output(("git", "describe", "--tags", "HEAD"), cwd=datadir, text=True)
- print(f"""
+ cve_status = {}
+
+ if not args.output_json:
+ print(f"""
# Auto-generated CVE metadata, DO NOT EDIT BY HAND.
# Generated at {datetime.datetime.now(datetime.timezone.utc)} for kernel version {version}
# From {datadir.name} {data_version}
@@ -131,26 +135,58 @@ do_cve_check[prefuncs] += "check_kernel_cve_status_version"
continue
first_affected, fixed, backport_ver = get_fixed_versions(cve_info, base_version)
if not fixed:
- print(f"# {cve} has no known resolution")
+ cve_status[cve] = {
+ "active": True,
+ "message": "no known resolution"
+ }
+ if not args.output_json:
+ print(f"# {cve} has no known resolution")
elif first_affected and version < first_affected:
- print(f'CVE_STATUS[{cve}] = "fixed-version: only affects {first_affected} onwards"')
+ cve_status[cve] = {
+ "active": False,
+ "message": f"fixed-version: only affects {first_affected} onwards"
+ }
+ if not args.output_json:
+ print(f'CVE_STATUS[{cve}] = "fixed-version: only affects {first_affected} onwards"')
elif fixed <= version:
- print(
- f'CVE_STATUS[{cve}] = "fixed-version: Fixed from version {fixed}"'
- )
+ cve_status[cve] = {
+ "active": False,
+ "message": f"fixed-version: Fixed from version {fixed}"
+ }
+ if not args.output_json:
+ print(f'CVE_STATUS[{cve}] = "fixed-version: Fixed from version {fixed}"')
else:
if backport_ver:
if backport_ver <= version:
- print(
- f'CVE_STATUS[{cve}] = "cpe-stable-backport: Backported in {backport_ver}"'
- )
+ cve_status[cve] = {
+ "active": False,
+ "message": f"cpe-stable-backport: Backported in {backport_ver}"
+ }
+ if not args.output_json:
+ print(f'CVE_STATUS[{cve}] = "cpe-stable-backport: Backported in {backport_ver}"')
else:
- print(f"# {cve} may need backporting (fixed from {backport_ver})")
+ cve_status[cve] = {
+ "active": True,
+ "message": f"May need backporting (fixed from {backport_ver})"
+ }
+ if not args.output_json:
+ print(f"# {cve} may need backporting (fixed from {backport_ver})")
else:
- print(f"# {cve} needs backporting (fixed from {fixed})")
-
- print()
-
+ cve_status[cve] = {
+ "active": True,
+ "message": f"#Needs backporting (fixed from {fixed})"
+ }
+ if not args.output_json:
+ print(f"# {cve} needs backporting (fixed from {fixed})")
+
+ if not args.output_json:
+ print()
+
+ # Emit structured output if --ret-struct was requested
+ if args.output_json:
+ print(json.dumps({
+ "cve_status": cve_status,
+ }, indent=2))
if __name__ == "__main__":
main()
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v3 2/4] generate-cve-exclusions: Add a .bbclass
2026-01-06 20:46 [PATCH v3 0/4] generate-cve-exclusions: Add a new bbclass ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 1/4] generate-cve-exclusions: Add --output-json option ValentinBoudevin
@ 2026-01-06 20:46 ` ValentinBoudevin
2026-01-08 8:28 ` [OE-core] " Daniel Turull
2026-01-06 20:46 ` [PATCH v3 3/4] generate-cve-exclusions: Move python script ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 4/4] linux: Add inherit on generate-cve-exclusions ValentinBoudevin
3 siblings, 1 reply; 6+ messages in thread
From: ValentinBoudevin @ 2026-01-06 20:46 UTC (permalink / raw)
To: openembedded-core; +Cc: ValentinBoudevin
Add a .bbclass to generate-cve-exclusions to use this script at every
run.
Two steps for testing:
1) Inherit this class in the kernel recipe with "inherit
generate-cve-exclusions.bbclass"
2) Use the following command to generate a cvelistV5 entry with a JSON
file in in ${WORKDIR}/cvelistV5/ :
"bitbake linux-yocto -c generate-cve-exclusions"
The JSON file can then be parsed in the following run by cve-check.
This class contains several methods:
*do_clone_cvelistV5: Clone the cvelistV5 repo in
${WORKDIR}/cvelistV5/git
(e.g. bitbake-builds/poky-master/build/tmp/work/qemux86_64-poky-linux/
linux-yocto/6.18.1+git/cvelistV5/git)
*do_generate_cve_exclusions: Use the script generate-cve-exclusions.py.
It uses the new "--output-json" argument to generate a JSON file as an
output stored in ${WORKDIR}/cvelistV5//cve-exclusion_${LINUX_VERSION}.json
*do_cve_check:prepend: Parse the previously generated JSON file to set
the variable CVE_STATUS corretly
Signed-off-by: Valentin Boudevin <valentin.boudevin@gmail.com>
---
meta/classes/generate-cve-exclusions.bbclass | 67 ++++++++++++++++++++
1 file changed, 67 insertions(+)
create mode 100644 meta/classes/generate-cve-exclusions.bbclass
diff --git a/meta/classes/generate-cve-exclusions.bbclass b/meta/classes/generate-cve-exclusions.bbclass
new file mode 100644
index 0000000000..254ea5531d
--- /dev/null
+++ b/meta/classes/generate-cve-exclusions.bbclass
@@ -0,0 +1,67 @@
+CVE_EXCLUSIONS_WORKDIR ?= "${WORKDIR}/cvelistV5"
+CVELISTV5_PATH ?= "${CVE_EXCLUSIONS_WORKDIR}/git"
+
+python do_clone_cvelistV5() {
+ import subprocess
+ import shutil, os
+ rootdir = d.getVar("CVELISTV5_PATH")
+ d.setVar("SRC_URI", "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https")
+ d.setVar("SRCREV", "${AUTOREV}")
+ src_uri = (d.getVar('SRC_URI') or "").split()
+ # Fetch the kernel vulnerabilities sources
+ fetcher = bb.fetch2.Fetch(src_uri, d)
+ fetcher.download()
+ # Unpack into the standard work directory
+ fetcher.unpack(rootdir)
+ # Remove the folder ${PN} set by unpack
+ subdirs = [d for d in os.listdir(rootdir) if os.path.isdir(os.path.join(rootdir, d))]
+ if len(subdirs) == 1:
+ srcdir = os.path.join(rootdir, subdirs[0])
+ for f in os.listdir(srcdir):
+ shutil.move(os.path.join(srcdir, f), rootdir)
+ shutil.rmtree(srcdir)
+ bb.note("Vulnerabilities repo unpacked into: %s" % rootdir)
+}
+do_clone_cvelistV5[network] = "1"
+do_clone_cvelistV5[nostamp] = "1"
+do_clone_cvelistV5[doc] = "Clone CVE information from the CVE Project: https://github.com/CVEProject/cvelistV5.git"
+addtask clone_cvelistV5 before do_generate_cve_exclusions
+
+do_generate_cve_exclusions() {
+ generate_cve_exclusions_script=$(find ${COREBASE} -name "generate-cve-exclusions.py")
+ if [ -z "${generate_cve_exclusions_script}" ]; then
+ bbfatal "generate-cve-exclusions.py not found in ${COREBASE}."
+ fi
+ python3 "${generate_cve_exclusions_script}" \
+ ${CVELISTV5_PATH} \
+ ${LINUX_VERSION} \
+ --output-json > ${CVE_EXCLUSIONS_WORKDIR}/cve-exclusion_${LINUX_VERSION}.json
+}
+do_generate_cve_exclusions[nostamp] = "1"
+do_generate_cve_exclusions[doc] = "Generate CVE exclusions for the kernel build. (e.g., cve-exclusion_6.12.inc)"
+addtask generate_cve_exclusions after do_clone_cvelistV5
+
+python do_cve_check:prepend() {
+ import os
+ import json
+
+ workdir = d.getVar("CVE_EXCLUSIONS_WORKDIR")
+ kernel_version = d.getVar("LINUX_VERSION")
+ json_input_file = os.path.join(workdir, "cve-exclusion_%s.json" % kernel_version)
+
+ if os.path.exists(json_input_file):
+ with open(json_input_file, 'r', encoding='utf-8') as f:
+ cve_data = json.load(f)
+ cve_status_dict = cve_data.get("cve_status", {})
+ count = 0
+ for cve_id, info in cve_status_dict.items():
+ if info.get("active", True):
+ # Skip active CVEs
+ continue
+ d.setVarFlag("CVE_STATUS", cve_id, info.get("message", ""))
+ count += 1
+
+ bb.note("Loaded %d CVE_STATUS entries from JSON output for kernel %s" % (count, kernel_version))
+ else:
+ bb.warn("CVE exclusion JSON not found: %s. Skipping CVE_STATUS updates" % json_input_file)
+}
\ No newline at end of file
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v3 3/4] generate-cve-exclusions: Move python script
2026-01-06 20:46 [PATCH v3 0/4] generate-cve-exclusions: Add a new bbclass ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 1/4] generate-cve-exclusions: Add --output-json option ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 2/4] generate-cve-exclusions: Add a .bbclass ValentinBoudevin
@ 2026-01-06 20:46 ` ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 4/4] linux: Add inherit on generate-cve-exclusions ValentinBoudevin
3 siblings, 0 replies; 6+ messages in thread
From: ValentinBoudevin @ 2026-01-06 20:46 UTC (permalink / raw)
To: openembedded-core; +Cc: ValentinBoudevin
The script should be located with other scripts in scripts/contrib
instead of staying in meta/classes/.
Update the new .bbclass to match this modification
Signed-off-by: Valentin Boudevin <valentin.boudevin@gmail.com>
---
meta/classes/generate-cve-exclusions.bbclass | 2 +-
.../linux => scripts/contrib}/generate-cve-exclusions.py | 0
2 files changed, 1 insertion(+), 1 deletion(-)
rename {meta/recipes-kernel/linux => scripts/contrib}/generate-cve-exclusions.py (100%)
diff --git a/meta/classes/generate-cve-exclusions.bbclass b/meta/classes/generate-cve-exclusions.bbclass
index 254ea5531d..100d2e99b6 100644
--- a/meta/classes/generate-cve-exclusions.bbclass
+++ b/meta/classes/generate-cve-exclusions.bbclass
@@ -28,7 +28,7 @@ do_clone_cvelistV5[doc] = "Clone CVE information from the CVE Project: https://g
addtask clone_cvelistV5 before do_generate_cve_exclusions
do_generate_cve_exclusions() {
- generate_cve_exclusions_script=$(find ${COREBASE} -name "generate-cve-exclusions.py")
+ generate_cve_exclusions_script=${COREBASE}/scripts/contrib/generate-cve-exclusions.py
if [ -z "${generate_cve_exclusions_script}" ]; then
bbfatal "generate-cve-exclusions.py not found in ${COREBASE}."
fi
diff --git a/meta/recipes-kernel/linux/generate-cve-exclusions.py b/scripts/contrib/generate-cve-exclusions.py
similarity index 100%
rename from meta/recipes-kernel/linux/generate-cve-exclusions.py
rename to scripts/contrib/generate-cve-exclusions.py
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v3 4/4] linux: Add inherit on generate-cve-exclusions
2026-01-06 20:46 [PATCH v3 0/4] generate-cve-exclusions: Add a new bbclass ValentinBoudevin
` (2 preceding siblings ...)
2026-01-06 20:46 ` [PATCH v3 3/4] generate-cve-exclusions: Move python script ValentinBoudevin
@ 2026-01-06 20:46 ` ValentinBoudevin
3 siblings, 0 replies; 6+ messages in thread
From: ValentinBoudevin @ 2026-01-06 20:46 UTC (permalink / raw)
To: openembedded-core; +Cc: ValentinBoudevin
Update linux-yocto.inc to inherit the new generate-cve-exclusions class.
Signed-off-by: Valentin Boudevin <valentin.boudevin@gmail.com>
---
meta/recipes-kernel/linux/linux-yocto.inc | 3 +++
1 file changed, 3 insertions(+)
diff --git a/meta/recipes-kernel/linux/linux-yocto.inc b/meta/recipes-kernel/linux/linux-yocto.inc
index 4d0a726bb6..f6a1161940 100644
--- a/meta/recipes-kernel/linux/linux-yocto.inc
+++ b/meta/recipes-kernel/linux/linux-yocto.inc
@@ -5,6 +5,9 @@ HOMEPAGE = "https://www.yoctoproject.org/"
LIC_FILES_CHKSUM ?= "file://COPYING;md5=d7810fab7487fb0aad327b76f1be7cd7"
+# Generate Dynamic CVE Exclusions
+inherit generate-cve-exclusions
+
UPSTREAM_CHECK_GITTAGREGEX = "(?P<pver>\d+\.\d+(\.\d+)*)"
RECIPE_NO_UPDATE_REASON = "Recipe is updated through a separate process"
^ permalink raw reply related [flat|nested] 6+ messages in thread
* RE: [OE-core] [PATCH v3 2/4] generate-cve-exclusions: Add a .bbclass
2026-01-06 20:46 ` [PATCH v3 2/4] generate-cve-exclusions: Add a .bbclass ValentinBoudevin
@ 2026-01-08 8:28 ` Daniel Turull
0 siblings, 0 replies; 6+ messages in thread
From: Daniel Turull @ 2026-01-08 8:28 UTC (permalink / raw)
To: valentin.boudevin@gmail.com,
openembedded-core@lists.openembedded.org
> -----Original Message-----
> From: openembedded-core@lists.openembedded.org <openembedded-
> core@lists.openembedded.org> On Behalf Of vboudevin via
> lists.openembedded.org
> Sent: Tuesday, 6 January 2026 21:47
> To: openembedded-core@lists.openembedded.org
> Cc: ValentinBoudevin <valentin.boudevin@gmail.com>
> Subject: [OE-core] [PATCH v3 2/4] generate-cve-exclusions: Add a .bbclass
>
> Add a .bbclass to generate-cve-exclusions to use this script at every run.
>
> Two steps for testing:
> 1) Inherit this class in the kernel recipe with "inherit
> generate-cve-exclusions.bbclass"
> 2) Use the following command to generate a cvelistV5 entry with a JSON
> file in in ${WORKDIR}/cvelistV5/ :
> "bitbake linux-yocto -c generate-cve-exclusions"
>
> The JSON file can then be parsed in the following run by cve-check.
>
> This class contains several methods:
>
> *do_clone_cvelistV5: Clone the cvelistV5 repo in ${WORKDIR}/cvelistV5/git
>
> (e.g. bitbake-builds/poky-master/build/tmp/work/qemux86_64-poky-linux/
> linux-yocto/6.18.1+git/cvelistV5/git)
>
> *do_generate_cve_exclusions: Use the script generate-cve-exclusions.py.
> It uses the new "--output-json" argument to generate a JSON file as an output
> stored in ${WORKDIR}/cvelistV5//cve-exclusion_${LINUX_VERSION}.json
>
> *do_cve_check:prepend: Parse the previously generated JSON file to set the
> variable CVE_STATUS corretly
>
> Signed-off-by: Valentin Boudevin <valentin.boudevin@gmail.com>
> ---
> meta/classes/generate-cve-exclusions.bbclass | 67 ++++++++++++++++++++
> 1 file changed, 67 insertions(+)
> create mode 100644 meta/classes/generate-cve-exclusions.bbclass
>
> diff --git a/meta/classes/generate-cve-exclusions.bbclass
> b/meta/classes/generate-cve-exclusions.bbclass
> new file mode 100644
> index 0000000000..254ea5531d
> --- /dev/null
> +++ b/meta/classes/generate-cve-exclusions.bbclass
> @@ -0,0 +1,67 @@
> +CVE_EXCLUSIONS_WORKDIR ?= "${WORKDIR}/cvelistV5"
> +CVELISTV5_PATH ?= "${CVE_EXCLUSIONS_WORKDIR}/git"
> +
> +python do_clone_cvelistV5() {
> + import subprocess
> + import shutil, os
> + rootdir = d.getVar("CVELISTV5_PATH")
> + d.setVar("SRC_URI",
> "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https")
> + d.setVar("SRCREV", "${AUTOREV}")
Same comment as the other email regarding AUTOREV and reproducible and offline builds using mirrors.
> + src_uri = (d.getVar('SRC_URI') or "").split()
> + # Fetch the kernel vulnerabilities sources
> + fetcher = bb.fetch2.Fetch(src_uri, d)
> + fetcher.download()
> + # Unpack into the standard work directory
> + fetcher.unpack(rootdir)
> + # Remove the folder ${PN} set by unpack
> + subdirs = [d for d in os.listdir(rootdir) if os.path.isdir(os.path.join(rootdir, d))]
> + if len(subdirs) == 1:
> + srcdir = os.path.join(rootdir, subdirs[0])
> + for f in os.listdir(srcdir):
> + shutil.move(os.path.join(srcdir, f), rootdir)
> + shutil.rmtree(srcdir)
> + bb.note("Vulnerabilities repo unpacked into: %s" % rootdir) }
> +do_clone_cvelistV5[network] = "1"
> +do_clone_cvelistV5[nostamp] = "1"
> +do_clone_cvelistV5[doc] = "Clone CVE information from the CVE Project:
> https://github.co/
> m%2FCVEProject%2FcvelistV5.git&data=05%7C02%7Cdaniel.turull%40ericsson.c
> om%7C3b56ca9a146149d141dd08de4d64bd6f%7C92e84cebfbfd47abbe52080c6
> b87953f%7C0%7C0%7C639033292229191613%7CUnknown%7CTWFpbGZsb3d8
> eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiT
> WFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=rvOYYuld78txVFfm1jnu7fo
> EP12SNCfxSdN6MHHv4nk%3D&reserved=0"
> +addtask clone_cvelistV5 before do_generate_cve_exclusions
> +
> +do_generate_cve_exclusions() {
> + generate_cve_exclusions_script=$(find ${COREBASE} -name "generate-cve-
> exclusions.py")
> + if [ -z "${generate_cve_exclusions_script}" ]; then
> + bbfatal "generate-cve-exclusions.py not found in ${COREBASE}."
> + fi
> + python3 "${generate_cve_exclusions_script}" \
> + ${CVELISTV5_PATH} \
> + ${LINUX_VERSION} \
> + --output-json >
> +${CVE_EXCLUSIONS_WORKDIR}/cve-exclusion_${LINUX_VERSION}.json
> +}
> +do_generate_cve_exclusions[nostamp] = "1"
> +do_generate_cve_exclusions[doc] = "Generate CVE exclusions for the kernel
> build. (e.g., cve-exclusion_6.12.inc)"
> +addtask generate_cve_exclusions after do_clone_cvelistV5
> +
> +python do_cve_check:prepend() {
> + import os
> + import json
> +
> + workdir = d.getVar("CVE_EXCLUSIONS_WORKDIR")
> + kernel_version = d.getVar("LINUX_VERSION")
> + json_input_file = os.path.join(workdir, "cve-exclusion_%s.json" %
> + kernel_version)
> +
> + if os.path.exists(json_input_file):
> + with open(json_input_file, 'r', encoding='utf-8') as f:
> + cve_data = json.load(f)
> + cve_status_dict = cve_data.get("cve_status", {})
> + count = 0
> + for cve_id, info in cve_status_dict.items():
> + if info.get("active", True):
> + # Skip active CVEs
> + continue
> + d.setVarFlag("CVE_STATUS", cve_id, info.get("message", ""))
> + count += 1
> +
> + bb.note("Loaded %d CVE_STATUS entries from JSON output for kernel %s"
> % (count, kernel_version))
> + else:
> + bb.warn("CVE exclusion JSON not found: %s. Skipping CVE_STATUS
> +updates" % json_input_file) }
> \ No newline at end of file
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-01-08 8:28 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-01-06 20:46 [PATCH v3 0/4] generate-cve-exclusions: Add a new bbclass ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 1/4] generate-cve-exclusions: Add --output-json option ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 2/4] generate-cve-exclusions: Add a .bbclass ValentinBoudevin
2026-01-08 8:28 ` [OE-core] " Daniel Turull
2026-01-06 20:46 ` [PATCH v3 3/4] generate-cve-exclusions: Move python script ValentinBoudevin
2026-01-06 20:46 ` [PATCH v3 4/4] linux: Add inherit on generate-cve-exclusions ValentinBoudevin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox