mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-01-01 13:58:06 +00:00
apache2: add vendor to product name used for CVE checking
This recipe sets the product name used for CVE checking to "http_server". However, the cve-check logic matches that name to all products in the CVE database regardless of vendor. Currently, it is matching to products from vendors other than apache. As a result, CVE checking incorrectly reports CVEs for those vendors' products for this package. Signed-off-by: Jeffrey Pautler <jeffrey.pautler@ni.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
This commit is contained in:
parent
33240e1783
commit
51f70eaaa5
|
|
@ -36,7 +36,7 @@ inherit autotools update-rc.d pkgconfig systemd update-alternatives
|
|||
|
||||
DEPENDS = "openssl expat pcre apr apr-util apache2-native "
|
||||
|
||||
CVE_PRODUCT = "http_server"
|
||||
CVE_PRODUCT = "apache:http_server"
|
||||
|
||||
SSTATE_SCAN_FILES += "apxs config_vars.mk config.nice"
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user