[yocto] [meta-security][PATCH] *.patch: fix CVE and Signed-off-by tag

2023-07-02 Thread Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org
From: Sanjay Chitroda * as reported by openembedded-core/scripts/contrib/patchreview.py -v . Missing Signed-off-by tag (./recipes-scanners/clamav/files/oe_cmake_fixup.patch) Missing CVE tag (./recipes-security/ecryptfs-utils/files/ecryptfs-utils-CVE-2016-6224.patch) Signed-off-by: Sanjay

Re: [yocto] [meta-selinux][PATCH] selinux: Set CVE_PRODUCT

2023-05-30 Thread Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org
Hi all, Any update/comment ? Thanks, Sanjay -Original Message- From: Sanjay Chitroda Sent: Monday, May 15, 2023 6:45 PM To: yocto@lists.yoctoproject.org Cc: Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) Subject: [meta-selinux][PATCH] selinux: Set

Re: [yocto] [meta-selinux][PATCH] selinux: Set CVE_PRODUCT

2023-05-26 Thread Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org
Hi all, Any update/comment ? Thanks, Sanjay -Original Message- From: Sanjay Chitroda Sent: Friday, May 12, 2023 7:12 PM To: yocto@lists.yoctoproject.org Cc: Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) Subject: [meta-selinux][PATCH] selinux: Set

[yocto] [meta-selinux][PATCH] selinux: Set CVE_PRODUCT

2023-05-15 Thread Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org
The CVE product name for selinux-* package is (usually) the selinux (and not our recipe name), so use selinux as the default. See also: http://lists.openembedded.org/pipermail/openembedded-core/2017-July/139897.html "Results from cve-check are not very good at the moment. One of the reasons for

[yocto] [dunfell][PATCH] pypi.bbclass: Set CVE_PRODUCT to PYPI_PACKAGE

2023-05-15 Thread Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org
From: Alex Kiernan The CVE product name for PyPI packages is (usually) the same as the PyPI package name (and not our recipe name), so use that as the default. Signed-off-by: Alex Kiernan Signed-off-by: Alex Kiernan Signed-off-by: Richard Purdie (cherry picked from commit