summaryrefslogtreecommitdiffstats
path: root/meta/lib/oe
diff options
context:
space:
mode:
authorJasper Orschulko <jasper@fancydomain.eu>2023-08-21 14:02:30 +0200
committerRichard Purdie <richard.purdie@linuxfoundation.org>2023-08-22 15:13:54 +0100
commit92983dba651cffe5c11973d90aad00c581a79c93 (patch)
tree474ef446e5a7ead52b697bca09c2897b97de9837 /meta/lib/oe
parentbedbda856130e838c7945e136ca48f52d96b423c (diff)
downloadpoky-92983dba651cffe5c11973d90aad00c581a79c93.tar.gz
cve_check: Fix cpe_id generation
Use "*" (wildcard) instead of "a" (application)in cpe_id generation, as the product is not necessarily of type application, e.g. linux_kernel, which is of type "o" (operating system). (From OE-Core rev: cae9528b002c06143bf048b991b9d7e93968cb6b) (From OE-Core rev: e7c1def3c3c3a72249802ef6fb64292277a7a53e) Signed-off-by: Jasper Orschulko <jasper@fancydomain.eu> Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/lib/oe')
-rw-r--r--meta/lib/oe/cve_check.py2
1 files changed, 1 insertions, 1 deletions
diff --git a/meta/lib/oe/cve_check.py b/meta/lib/oe/cve_check.py
index 5bf3caac47..3979d521d1 100644
--- a/meta/lib/oe/cve_check.py
+++ b/meta/lib/oe/cve_check.py
@@ -156,7 +156,7 @@ def get_cpe_ids(cve_product, version):
156 else: 156 else:
157 vendor = "*" 157 vendor = "*"
158 158
159 cpe_id = 'cpe:2.3:a:{}:{}:{}:*:*:*:*:*:*:*'.format(vendor, product, version) 159 cpe_id = 'cpe:2.3:*:{}:{}:{}:*:*:*:*:*:*:*'.format(vendor, product, version)
160 cpe_ids.append(cpe_id) 160 cpe_ids.append(cpe_id)
161 161
162 return cpe_ids 162 return cpe_ids