mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-10 00:04:06 -09:00
package/mbedtls: fix CPE
A new (and hopefully definitive) CPE is to be used for mbedtls:
cpe:2.3:a:trustedfirmware:mbed_tls:
CVEs for projects under the TrustedFirmware umbrella are now seemingly
handled under the CPE vendor "trustedfirmware"[1].
NVD correctly reports[2] the new CPE deprecates the "old" one Buildroot
was using.
[1] https://review.trustedfirmware.org/c/TF-A/trusted-firmware-a/+/49486/comment/2fd93ed7_df27998e/ before last comment from Sandrine
[2] https://nvd.nist.gov/products/cpe/detail/453A781D-74D5-4FB5-9BB6-8C1F7F281A7A
Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d2ceab1c15)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
This commit is contained in:
committed by
Titouan Christophe
parent
7948f1794f
commit
2dfa94ec02
@@ -15,7 +15,7 @@ MBEDTLS_CONF_OPTS = \
|
||||
MBEDTLS_INSTALL_STAGING = YES
|
||||
MBEDTLS_LICENSE = Apache-2.0 or GPL-2.0+
|
||||
MBEDTLS_LICENSE_FILES = LICENSE
|
||||
MBEDTLS_CPE_ID_VENDOR = arm
|
||||
MBEDTLS_CPE_ID_VENDOR = trustedfirmware
|
||||
MBEDTLS_CPE_ID_PRODUCT = mbed_tls
|
||||
|
||||
# This is mandatory for hiawatha
|
||||
|
||||
Reference in New Issue
Block a user