[Buildroot] [git commit] package/mbedtls: fix CPE
Julien Olivain via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
commit: https://gitlab.com/buildroot.org/buildroot/-/commit/d2ceab1c154aeab278f50f4f1451afdacda630f4 branch: https://gitlab.com/buildroot.org/buildroot/-/tree/master A new (and hopefully definitive) CPE is to be used for mbedtls: cpe:2.3:a:trustedfirmware:mbed_tls: CVEs for projects under the TrustedFirmware umbrella are now seemingly handled under the CPE vendor "trustedfirmware"[1]. NVD correctly reports[2] the new CPE deprecates the "old" one Buildroot was using. [1] https://review.trustedfirmware.org/c/TF-A/trusted-firmware-a/+/49486/comment/2fd93ed7_df27998e/ before last comment from Sandrine [2] https://nvd.nist.gov/products/cpe/detail/453A781D-74D5-4FB5-9BB6-8C1F7F281A7A Signed-off-by: Quentin Schulz <[email protected]> Signed-off-by: Julien Olivain <[email protected]> --- package/mbedtls/mbedtls.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/mbedtls/mbedtls.mk b/package/mbedtls/mbedtls.mk index e8bb0a71b9..9def876808 100644 --- a/package/mbedtls/mbedtls.mk +++ b/package/mbedtls/mbedtls.mk @@ -15,7 +15,7 @@ MBEDTLS_CONF_OPTS = \ MBEDTLS_INSTALL_STAGING = YES MBEDTLS_LICENSE = Apache-2.0 or GPL-2.0+ MBEDTLS_LICENSE_FILES = LICENSE -MBEDTLS_CPE_ID_VENDOR = arm +MBEDTLS_CPE_ID_VENDOR = trustedfirmware MBEDTLS_CPE_ID_PRODUCT = mbed_tls # This is mandatory for hiawatha _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot