]> code.ossystems Code Review - openembedded-core.git/commit
cve-check: Run it after do_fetch
authorKhem Raj <raj.khem@gmail.com>
Thu, 21 May 2020 15:18:47 +0000 (08:18 -0700)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sun, 24 May 2020 22:55:31 +0000 (23:55 +0100)
commite406fcb6c609a0d2456d7da0d2406d2d9fa52dd2
tree75987a338882b7f12eea0ae3050dbc576da1bee0
parent67294d3e9cb2b3e416b76808dce1701391b88df1
cve-check: Run it after do_fetch

Certain recipes e.g. bash readline ( from meta-gplv2 ) download patches instead of having them in
metadata, this could fail cve_check

ERROR: readline-5.2-r9 do_cve_check: File Not found: qemuarm/build/../downloads/readline52-001

This patch ensures that download is done before running CVE scan, even
though these will be external patches and may not contain CVE tags as it
expects, but it will fix the run failures as seen above

Signed-off-by: Khem Raj <raj.khem@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/classes/cve-check.bbclass