summaryrefslogtreecommitdiffstats
path: root/meta/recipes-devtools/flex
diff options
context:
space:
mode:
authorRoss Burton <ross.burton@intel.com>2019-07-17 11:45:36 +0100
committerRichard Purdie <richard.purdie@linuxfoundation.org>2019-07-18 12:16:19 +0100
commita78725c81f78559a4223fd6822c5b886772cca4c (patch)
tree748c603e9d491c7f410eb9a12e500be2400aa1f1 /meta/recipes-devtools/flex
parentda620cc68b4d99c8be3f539ded71fedd9ada01ed (diff)
downloadpoky-a78725c81f78559a4223fd6822c5b886772cca4c.tar.gz
cve-check: allow comparison of Vendor as well as Product
Some product names are too vague to be searched without also matching the vendor, for example Flex could be the parser compiler we ship, or Adobe Flex, or Apache Flex, or IBM Flex. If entries in CVE_PRODUCT contain a colon then split it as vendor:product to improve the search. Also don't use .format() to construct SQL as that can lead to security issues. Instead, use ? placeholders and lets sqlite3 handle the escaping. (From OE-Core rev: e6bf90009877d00243417898700d2320fd87b39c) Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-devtools/flex')
0 files changed, 0 insertions, 0 deletions