- 264 license table entries with exact download URLs (224/264 resolved) - Complete sources/ directory with all BitBake recipes - Build configuration: tqma6ul-multi-mba6ulx, spaetzle (musl) - Full traceability for Softwarefreigabeantrag - GCC 13.4.0, Linux 6.6.102, U-Boot 2023.04, musl 1.2.4 - License distribution: GPL-2.0 (24), MIT (23), GPL-2.0+ (18), BSD-3 (16)
29 lines
1.7 KiB
Plaintext
29 lines
1.7 KiB
Plaintext
# Possible options for CVE statuses
|
|
|
|
# used by this class internally when fix is detected (NVD DB version check or CVE patch file)
|
|
CVE_CHECK_STATUSMAP[patched] = "Patched"
|
|
# use when this class does not detect backported patch (e.g. vendor kernel repo with cherry-picked CVE patch)
|
|
CVE_CHECK_STATUSMAP[backported-patch] = "Patched"
|
|
# use when NVD DB does not mention patched versions of stable/LTS branches which have upstream CVE backports
|
|
CVE_CHECK_STATUSMAP[cpe-stable-backport] = "Patched"
|
|
# use when NVD DB does not mention correct version or does not mention any verion at all
|
|
CVE_CHECK_STATUSMAP[fixed-version] = "Patched"
|
|
|
|
# used internally by this class if CVE vulnerability is detected which is not marked as fixed or ignored
|
|
CVE_CHECK_STATUSMAP[unpatched] = "Unpatched"
|
|
# use when CVE is confirmed by upstream but fix is still not available
|
|
CVE_CHECK_STATUSMAP[vulnerable-investigating] = "Unpatched"
|
|
|
|
# used for migration from old concept, do not use for new vulnerabilities
|
|
CVE_CHECK_STATUSMAP[ignored] = "Ignored"
|
|
# use when NVD DB wrongly indicates vulnerability which is actually for a different component
|
|
CVE_CHECK_STATUSMAP[cpe-incorrect] = "Ignored"
|
|
# use when upstream does not accept the report as a vulnerability (e.g. works as designed)
|
|
CVE_CHECK_STATUSMAP[disputed] = "Ignored"
|
|
# use when vulnerability depends on build or runtime configuration which is not used
|
|
CVE_CHECK_STATUSMAP[not-applicable-config] = "Ignored"
|
|
# use when vulnerability affects other platform (e.g. Windows or Debian)
|
|
CVE_CHECK_STATUSMAP[not-applicable-platform] = "Ignored"
|
|
# use when upstream acknowledged the vulnerability but does not plan to fix it
|
|
CVE_CHECK_STATUSMAP[upstream-wontfix] = "Ignored"
|