mirror of
git://git.yoctoproject.org/poky.git
synced 2025-07-19 12:59:02 +02:00
cve-check: Log if CVE_STATUS set but not reported for component
Log if the CVE_STATUS is set for a CVE, but the cve is not reported for a component. This should hopefully help to clean up not needed CVE_STATUS settings. (From OE-Core rev: c1b3c3856c2bdf2d9d6dfbaccfce549396a8630a) Signed-off-by: Simone Weiß <simone.p.weiss@posteo.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit 013d531a84fa08b6ae8a47bdf3ba1fa8f18ba270) Signed-off-by: Steve Sakoman <steve@sakoman.com>
This commit is contained in:
parent
cae6c78254
commit
05a1e88ce3
|
@ -418,6 +418,9 @@ def check_cves(d, patched_cves):
|
|||
cves_status.append([product, False])
|
||||
|
||||
conn.close()
|
||||
diff_ignore = list(set(cve_ignore) - set(cves_ignored))
|
||||
if diff_ignore:
|
||||
oe.qa.handle_error("cve_status_not_in_db", "Found CVE (%s) with CVE_STATUS set that are not found in database for this component" % " ".join(diff_ignore), d)
|
||||
|
||||
if not cves_in_recipe:
|
||||
bb.note("No CVE records for products in recipe %s" % (pn))
|
||||
|
|
Loading…
Reference in New Issue
Block a user