mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-09 16:01:54 -09:00
56ea5a02268631f2ea679c067e9b0ec94e0e512e
The NVD database contains some CPEs that are wrongly not associated with any version number. They are for example sometimes associated with very old CVEs. Those CPEs are annoying, because they pollute our pkg-stat CVE results with CVE entries which actually don't affect us. The proper way to solve it is, and should remain, to fix the NVD database by reporting these issues. Having to deal with a lot of CVEs/CPEs, the NVD database is however slow to be updated. To reduce the noise in our pkg-stats results in the meantime, one possibility is to add <PKG_IGNORE_CVES> entries for those CVEs. This however comes with the downside that even once the NVD database gets fixed, those ignored entries risk remaining in Buildroot forever because they are undetected. This commit tries to address this downside by checking for and reporting CVEs that are ignored in Buildroot, but where the NVD reports our package version as unaffected. Those CVEs will appear in the 'CVEs Ignored' column as '(stale)', and the cell will be colored the same way warnings are. This should allow us to detect and remove those entries. It can be tested for example by adding the following variable to the apache package (for a CVE that was recently fixed in the NVD database): APACHE_IGNORE_CVES = CVE-1999-0236 Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
…
…
…
Buildroot is a simple, efficient and easy-to-use tool to generate embedded Linux systems through cross-compilation. The documentation can be found in docs/manual. You can generate a text document with 'make manual-text' and read output/docs/manual/manual.text. Online documentation can be found at http://buildroot.org/docs.html To build and use the buildroot stuff, do the following: 1) run 'make menuconfig' 2) select the target architecture and the packages you wish to compile 3) run 'make' 4) wait while it compiles 5) find the kernel, bootloader, root filesystem, etc. in output/images You do not need to be root to build or run buildroot. Have fun! Buildroot comes with a basic configuration for a number of boards. Run 'make list-defconfigs' to view the list of provided configurations. Please feed suggestions, bug reports, insults, and bribes back to the buildroot mailing list: buildroot@buildroot.org You can also find us on #buildroot on OFTC IRC. If you would like to contribute patches, please read https://buildroot.org/manual.html#submitting-patches
Description
Languages
Makefile
62.5%
Python
19%
C
8.5%
Shell
6.1%
PHP
1.4%
Other
2.1%