mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2025-12-14 22:35:25 +01:00
emlog: ignore unrelated CVEs
This product is not present in the NVD database but another one with exactly the same name is in fact present. For that reason cve-check is outputting CVEs that are unrelated so they can be ignored. Signed-off-by: Davide Gardenal <davide.gardenal@huawei.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
This commit is contained in:
parent
19061fea15
commit
eaf1ea2e1f
|
|
@ -24,3 +24,14 @@ do_install() {
|
|||
}
|
||||
|
||||
RRECOMMENDS:${PN} += "kernel-module-emlog"
|
||||
|
||||
# The NVD database doesn't have a CPE for this product,
|
||||
# the name of this product is exactly the same as github.com/emlog/emlog
|
||||
# but it's not related in any way. The following CVEs are from that project
|
||||
# so they can be safely ignored
|
||||
CVE_CHECK_IGNORE += "\
|
||||
CVE-2019-16868 \
|
||||
CVE-2019-17073 \
|
||||
CVE-2021-44584 \
|
||||
CVE-2022-1526 \
|
||||
"
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user