Re: [Buildroot] [RFC PATCH 03/14] package/pkg-utils: show-info expose vuln details
Thomas Petazzoni via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <aodoOoem3oIva28M@windsurf> |
Hello,
On Wed, Jun 24, 2026 at 04:06:34PM +0200, Thomas Perale via buildroot wrote:
> For each `_IGNORE_CVES` entries the status and details are exported if
> present.
Perhaps this wording could be a bit nicer?
"This commit expands show-info so that for each CVE listed in the
<pk>_IGNORE_CVES variable, additional information will be provided:
the status and details, according to the information provided by the
following variables:
>
> - `<pkg>_<vuln-id>_STATUS`
> - `<pkg>_<vuln-id>_DETAIL`
>
> For a hypotetical 'CVE-2025-1234' that affects the package 'foo' with
^^^^ h missing somewhere here ?
^^ an ?
> the following declaration:
>
> ```
> FOO_CVE-2025-1234_STATUS = fixed
> FOO_CVE-2025-1234_DETAIL = some details
> ```
>
> Will result in the following show info output.
The sentence doesn't work:
"""
For an hypothetical CVE that affects package foo with the following
declaration will result in the following show info output.
"""
You want to change the last part so that it gives:
"""
For an hypothetical CVE that affects package foo with the following
declaration, the show-info output will look like:
"""
> diff --git a/package/pkg-utils.mk b/package/pkg-utils.mk
> index 17b0aa1760..c6e509e9d1 100644
> --- a/package/pkg-utils.mk
> +++ b/package/pkg-utils.mk
> @@ -154,6 +154,25 @@ define _json-info-pkg
> ) \
> )
> ]
> + $(comma) "cves_status": {
> + $(foreach cve,$(sort $($(1)_IGNORE_CVES)), \
> + $(call _json-info-pkg-cve,$(1),$(cve)) \
> + ) \
> + }
Don't know how we do this for the other show-info stuff, but do we
want to enclose this in an $(if $($(1)_IGNORE_CVES),...) test so that
we don't have an empty "cves_status" property for all packages, and
instead only have one for packages that actually have ignored CVEs?
(Even though admittedly it could still end up being empty, as we might
have ignored CVES but no status/details).
Thanks,
Thomas
--
Thomas Petazzoni, co-owner and CEO, Bootlin
Embedded Linux and Kernel engineering and training
https://bootlin.com
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot