[Buildroot] CVE tracking for selected packages

Thomas Petazzoni thomas.petazzoni at bootlin.com
Wed Feb 19 12:38:31 UTC 2020


On Wed, 19 Feb 2020 10:21:39 +0100
Thomas De Schampheleire <patrickdepinguin at gmail.com> wrote:

> What would be another great improvement, is the possibility to check
> for a given defconfig in a particular Buildroot tree (i.e. not
> necessarily the master) which CVEs are not yet solved.
> 
> Basically something like:
> 
>     make cve-info

Absolutely.

> For the implementation, I assume we should either create a make target
> to call pkg-stats with the list of packages required, and perhaps
> restricting to CVE checking only (instead of also version checking),
> or extract the CVE logic to another file that can be reused by both
> pkg-stats as the new thing.

I don't think calling into pkg-stats is really a good idea for that, we
probably want some other "thing", possibly also used by pkg-stats.

Best regards,

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


More information about the buildroot mailing list