public inbox for openembedded-core@lists.openembedded.org
 help / color / mirror / Atom feed
From: richard.purdie@linuxfoundation.org
To: akash.hadke@kpit.com, Marta Rybczynska <rybczynska@gmail.com>
Cc: OE-core <openembedded-core@lists.openembedded.org>,
	Ranjitsinh Rathod <Ranjitsinh.Rathod@kpit.com>,
	Akash Hadke <hadkeakash4@gmail.com>
Subject: Re: [OE-core] [poky][master][PATCH 1/3] cve_check.py: Add new method get_ignored_cves
Date: Tue, 17 May 2022 15:19:20 +0100	[thread overview]
Message-ID: <722011c32a289bb9945a491e1f9b9e290e62c3ea.camel@linuxfoundation.org> (raw)
In-Reply-To: <PN3PR01MB67120A503C169C733A3C0A888ECE9@PN3PR01MB6712.INDPRD01.PROD.OUTLOOK.COM>

On Tue, 2022-05-17 at 11:42 +0000, akash hadke via lists.openembedded.org wrote:
> Actually, I wanted to add the ignored and patched CVEs in
> buildhistory and for that purpose, I am exporting variables
> CVE_IGNORED and CVE_PATCHED with those values. I don't want to use
> cve-check.bbclass as it checks for the CVEs from the NVD database,
> and I only want to get ignored and patched CVEs from the recipe.

I'd really prefer to have one cve handling class where we can configure
it to get the data different people need rather than multiple
difference cve classes which are going to confuse people. Could we have
a way to disable NVD data from the cve-check class?

Cheers,

Richard


  parent reply	other threads:[~2022-05-17 14:19 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-05-11 14:36 [poky][master][PATCH 1/3] cve_check.py: Add new method get_ignored_cves Akash Hadke
2022-05-11 14:36 ` [poky][master][PATCH 2/3] cve-export.bbclass: Add a new class to get patched and ignored CVEs from the build Akash Hadke
2022-05-11 14:36 ` [poky][master][PATCH 3/3] cve_export.py: Add new selftest for cve-export.bbclass Akash Hadke
2022-05-17  9:12 ` [OE-core] [poky][master][PATCH 1/3] cve_check.py: Add new method get_ignored_cves Marta Rybczynska
2022-05-17 11:42   ` Akash Hadke
2022-05-17 13:33     ` Marta Rybczynska
2022-05-17 13:51       ` akash hadke
2022-05-17 14:19     ` richard.purdie [this message]
2022-05-18  9:46       ` akash hadke
2022-05-18 10:33         ` [OE-core] " richard.purdie
2022-05-18 11:58           ` Marta Rybczynska

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=722011c32a289bb9945a491e1f9b9e290e62c3ea.camel@linuxfoundation.org \
    --to=richard.purdie@linuxfoundation.org \
    --cc=Ranjitsinh.Rathod@kpit.com \
    --cc=akash.hadke@kpit.com \
    --cc=hadkeakash4@gmail.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=rybczynska@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox