From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A9D64C433FE for ; Mon, 7 Feb 2022 23:18:20 +0000 (UTC) Subject: Package revision To: openembedded-core@lists.openembedded.org From: "jbouchard" X-Originating-Location: =?utf-8?b?UXXDqWJlYywgUXVlYmVjLCBDQSAoMjQuMjAwLjEz?= =?utf-8?b?Ni4xMjUp?= X-Originating-Platform: Mac Chrome 97 User-Agent: GROUPS.IO Web Poster MIME-Version: 1.0 Date: Mon, 07 Feb 2022 15:18:20 -0800 Message-ID: Content-Type: multipart/alternative; boundary="hJtt27bQDWgcdfJUxf7v" List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Feb 2022 23:18:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/161469 --hJtt27bQDWgcdfJUxf7v Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi, I was wondering why the package revision are not increasing when a patch is= apply to other project source, like this commit https://git.openembedded.o= rg/openembedded-core/commit/?h=3Dhonister&id=3D2d3c5b078feb34cb729902292d28= 05c9288ebc4c. Most distribution tend to increase the package revision when = such changes occur. This help to track vulnerability and bugs. I know CVE_C= HECK can deal with CVE, but it is hard to track with external software. Thanks --hJtt27bQDWgcdfJUxf7v Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi,

I was wondering why the package revision are not increasing = when a patch is apply to other project source, like this commit https://git.openembedded.org/openembedded-core/commit/?h=3Dhoniste= r&id=3D2d3c5b078feb34cb729902292d2805c9288ebc4c. Most distribution = tend to increase the package revision when such changes occur. This help to= track vulnerability and bugs. I know CVE_CHECK can deal with CVE, but it i= s hard to track with external software.

Thanks --hJtt27bQDWgcdfJUxf7v--