summaryrefslogtreecommitdiffstats
path: root/documentation/dev-manual
diff options
context:
space:
mode:
authorMichael Opdenacker <michael.opdenacker@bootlin.com>2022-06-06 17:58:29 +0200
committerRichard Purdie <richard.purdie@linuxfoundation.org>2022-06-21 20:57:16 +0100
commitc91b04679f8bee04b3e41697c6d823fb4a68dec8 (patch)
tree8e7ee2e6feaf19e057855a7c42705eae0019021e /documentation/dev-manual
parent8b01f7811f9a46085d8b65f67d618b36e1fb9be9 (diff)
downloadpoky-c91b04679f8bee04b3e41697c6d823fb4a68dec8.tar.gz
dev-manual: mention the new CVE patch metrics page
(From yocto-docs rev: 42bfcb2d3a13e71264e5f29b07615c2da9866273) Signed-off-by: Michael Opdenacker <michael.opdenacker@bootlin.com> Reviewed-by: Quentin Schulz <foss+yocto@0leil.net> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'documentation/dev-manual')
-rw-r--r--documentation/dev-manual/common-tasks.rst11
1 files changed, 9 insertions, 2 deletions
diff --git a/documentation/dev-manual/common-tasks.rst b/documentation/dev-manual/common-tasks.rst
index ca6d594386..d7f0b263e7 100644
--- a/documentation/dev-manual/common-tasks.rst
+++ b/documentation/dev-manual/common-tasks.rst
@@ -11507,8 +11507,15 @@ known security vulnerabilities, as tracked by the public
11507`Common Vulnerabilities and Exposures (CVE) <https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures>`__ 11507`Common Vulnerabilities and Exposures (CVE) <https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures>`__
11508database. 11508database.
11509 11509
11510To know which packages are vulnerable to known security vulnerabilities, 11510The Yocto Project maintains a `list of known vulnerabilities
11511add the following setting to your configuration:: 11511<https://autobuilder.yocto.io/pub/non-release/patchmetrics/>`__
11512for packages in Poky and OE-Core, tracking the evolution of the number of
11513unpatched CVEs and the status of patches. Such information is available for
11514the current development version and for each supported release.
11515
11516To know which packages are vulnerable to known security vulnerabilities
11517in the specific image you are building, add the following setting to your
11518configuration::
11512 11519
11513 INHERIT += "cve-check" 11520 INHERIT += "cve-check"
11514 11521