]> code.ossystems Code Review - openembedded-core.git/commit
cve-check: Allow multiple entries in CVE_PRODUCT
authorGrygorii Tertychnyi <gtertych@cisco.com>
Mon, 29 Oct 2018 15:13:10 +0000 (17:13 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 16 Nov 2018 16:32:29 +0000 (16:32 +0000)
commit667d5e77e1ce0f0e531ed87f6fc30e1d65b16759
tree8c97fcc32c77838f7b001ab2baa545dcfe1d0e4d
parentf01153e1782425756a40929ffb3fa72993b7a3b1
cve-check: Allow multiple entries in CVE_PRODUCT

There are both "curl" and "libcurl" CPEs in NVD.
All "curl" CVEs are currently missing in the reports.

Hence, switch "CVE_PRODUCT" to a space separated list.
It is useful for recipes generating several packages,
that have different product names in NVD.

(From OE-Core rev: 404f75e026393ddc55da87f6f04fb1201cff4e11)

Signed-off-by: Grygorii Tertychnyi <gtertych@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/classes/cve-check.bbclass