mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-30 22:11:59 -09:00
support/scripts/cve.py: don't call download_nvd
This patch move the 'download_nvd' call to the 'pkg-stats' script
instead of automatically calling 'read_nvd_dir'.
Since the cve.py file can be used as a library it's up to the caller to
decide whether or not to update the NVD database.
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 867017e736)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
@@ -144,7 +144,9 @@ class CVE:
|
|||||||
self.nvd_cve = nvd_cve
|
self.nvd_cve = nvd_cve
|
||||||
|
|
||||||
@staticmethod
|
@staticmethod
|
||||||
def download_nvd(nvd_git_dir):
|
def download_nvd(nvd_dir):
|
||||||
|
nvd_git_dir = os.path.join(nvd_dir, "git")
|
||||||
|
|
||||||
if os.path.exists(nvd_git_dir):
|
if os.path.exists(nvd_git_dir):
|
||||||
subprocess.check_call(
|
subprocess.check_call(
|
||||||
["git", "pull"],
|
["git", "pull"],
|
||||||
@@ -177,7 +179,7 @@ class CVE:
|
|||||||
nvd_dir, a fresh copy will be downloaded, and kept in .json.gz
|
nvd_dir, a fresh copy will be downloaded, and kept in .json.gz
|
||||||
"""
|
"""
|
||||||
nvd_git_dir = os.path.join(nvd_dir, "git")
|
nvd_git_dir = os.path.join(nvd_dir, "git")
|
||||||
CVE.download_nvd(nvd_git_dir)
|
|
||||||
for year in range(NVD_START_YEAR, datetime.datetime.now().year + 1):
|
for year in range(NVD_START_YEAR, datetime.datetime.now().year + 1):
|
||||||
for dirpath, _, filenames in os.walk(os.path.join(nvd_git_dir, f"CVE-{year}")):
|
for dirpath, _, filenames in os.walk(os.path.join(nvd_git_dir, f"CVE-{year}")):
|
||||||
for filename in filenames:
|
for filename in filenames:
|
||||||
|
|||||||
@@ -676,6 +676,8 @@ def check_package_cves(nvd_path, packages):
|
|||||||
cpe_product_pkgs[pkg.name].append(pkg)
|
cpe_product_pkgs[pkg.name].append(pkg)
|
||||||
|
|
||||||
print(f"Updating NVD database in '{nvd_path}'")
|
print(f"Updating NVD database in '{nvd_path}'")
|
||||||
|
cvecheck.CVE.download_nvd(nvd_path)
|
||||||
|
|
||||||
for cve in cvecheck.CVE.read_nvd_dir(nvd_path):
|
for cve in cvecheck.CVE.read_nvd_dir(nvd_path):
|
||||||
check_package_cve_affects(cve, cpe_product_pkgs)
|
check_package_cve_affects(cve, cpe_product_pkgs)
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user