Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rpcbind: Add PKG_CPE_ID for proper CVE tracking #8525

Merged
merged 1 commit into from
Mar 31, 2019

Conversation

ja-pa
Copy link
Contributor

@ja-pa ja-pa commented Mar 28, 2019

Maintainer: @Andy2244
Compile tested: N/A
Run tested: N/A

Description:
This PR adds PKG_CPE_ID for CVE tracking.

Signed-off-by: Jan Pavlinec [email protected]

@ja-pa
Copy link
Contributor Author

ja-pa commented Mar 29, 2019

@Andy2244 There are projects like https://github.com/kkreitmair/cve-indicator which will benefit from better CPE ID coverage.

@Andy2244
Copy link
Contributor

Sure, i noticed those CVE tracking commits, yet there seems to-be no documentation at all on how this actually works and what components naming rules maintainers should be aware of.
As example PKG_CPE_ID is not listed as valid option anywhere on https://openwrt.org/docs/.

So is it the commit message, the .patch file name?
If maintainers are expected to use the system, i think there should be at least a minimal documentation on it, with examples.

@neheb
Copy link
Contributor

neheb commented Mar 31, 2019

Merging. The issue of PKG_CPE_ID is referenced.

@neheb neheb merged commit eb72553 into openwrt:master Mar 31, 2019
@ja-pa ja-pa deleted the rpcbind-cpe-id branch May 5, 2019 07:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants