[Buildroot] CVE tracking for selected packages

Thomas Petazzoni thomas.petazzoni at bootlin.com
Wed Feb 19 12:38:31 UTC 2020

On Wed, 19 Feb 2020 10:21:39 +0100
Thomas De Schampheleire <patrickdepinguin at gmail.com> wrote:

> What would be another great improvement, is the possibility to check
> for a given defconfig in a particular Buildroot tree (i.e. not
> necessarily the master) which CVEs are not yet solved.
> Basically something like:
>     make cve-info


> For the implementation, I assume we should either create a make target
> to call pkg-stats with the list of packages required, and perhaps
> restricting to CVE checking only (instead of also version checking),
> or extract the CVE logic to another file that can be reused by both
> pkg-stats as the new thing.

I don't think calling into pkg-stats is really a good idea for that, we
probably want some other "thing", possibly also used by pkg-stats.

Best regards,

Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering

More information about the buildroot mailing list