diff mbox series

ovmf: set CVE_PRODUCT and CVE_VERSION

Message ID 20240306043249.2673982-1-Qi.Chen@windriver.com
State New
Headers show
Series ovmf: set CVE_PRODUCT and CVE_VERSION | expand

Commit Message

ChenQi March 6, 2024, 4:32 a.m. UTC
From: Chen Qi <Qi.Chen@windriver.com>

Set CVE_PRODUCT and CVE_VERSION for ovmf. NVD uses 'edk2' and the
version should be the date only. Here's an example:
https://nvd.nist.gov/vuln/detail/CVE-2023-45232

Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
---
 meta/recipes-core/ovmf/ovmf_git.bb | 3 +++
 1 file changed, 3 insertions(+)

Comments

Alexander Kanavin March 6, 2024, 6:39 a.m. UTC | #1
On Wed, 6 Mar 2024 at 05:33, Chen Qi via lists.openembedded.org
<Qi.Chen=windriver.com@lists.openembedded.org> wrote:
> +CVE_VERSION = "202308"

This will almost certainly become mismatched with PV on version
updates, so please set from PV with a helper function.

Alex
diff mbox series

Patch

diff --git a/meta/recipes-core/ovmf/ovmf_git.bb b/meta/recipes-core/ovmf/ovmf_git.bb
index 3dc031d3b6..6931536229 100644
--- a/meta/recipes-core/ovmf/ovmf_git.bb
+++ b/meta/recipes-core/ovmf/ovmf_git.bb
@@ -30,6 +30,9 @@  PV = "edk2-stable202308"
 SRCREV = "819cfc6b42a68790a23509e4fcc58ceb70e1965e"
 UPSTREAM_CHECK_GITTAGREGEX = "(?P<pver>edk2-stable.*)"
 
+CVE_PRODUCT = "edk2"
+CVE_VERSION = "202308"
+
 inherit deploy
 
 PARALLEL_MAKE = ""