]> code.ossystems Code Review - openembedded-core.git/commitdiff
classes: don't scan for CVEs in images or packagegroups
authorRoss Burton <ross.burton@intel.com>
Fri, 9 Feb 2018 12:44:36 +0000 (12:44 +0000)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 16 Feb 2018 18:05:26 +0000 (18:05 +0000)
There's no point even looking in the database for these, so unset CVE_PRODUCT.

Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/classes/image.bbclass
meta/classes/packagegroup.bbclass

index 7abb9182120d9f57bd71997641e710633c347f0d..23ed53deb4bee235880b8b44c4191ecea45f2c8f 100644 (file)
@@ -674,3 +674,5 @@ reproducible_final_image_task () {
     fi
 }
 IMAGE_PREPROCESS_COMMAND_append = " reproducible_final_image_task; "
+
+CVE_PRODUCT = ""
index eea2e5b9fcfcc41a783782aeb8de5fcacec46bc9..d540d4214eb8786cde90f8185415e25d0aaded39 100644 (file)
@@ -56,3 +56,4 @@ python () {
         bb.fatal("Please ensure that your setting of VIRTUAL-RUNTIME_init_manager (%s) matches the entries enabled in DISTRO_FEATURES" % initman)
 }
 
+CVE_PRODUCT = ""