selinux: Set CVE_PRODUCT

The CVE product name for selinux-* package is (usually) the selinux
(and not our recipe name), so use selinux as the default.

See also:
http://lists.openembedded.org/pipermail/openembedded-core/2017-July/139897.html

"Results from cve-check are not very good at the moment.
One of the reasons for this is that component names used in CVE
database differ from yocto recipe names. This series fixes several
of those name mapping problems by setting the CVE_PRODUCT correctly
in the recipes. To check this mapping with after a build, I'm exporting
LICENSE and CVE_PRODUCT variables to buildhistory for recipes and
packages."

Value added is based on:
https://nvd.nist.gov/vuln/search/results?results_type=overview&search_type=all&cpe_product=cpe%3A%2F%3Akernel%3Aselinux

Signed-off-by: Sanjay Chitroda <schitrod@cisco.com>
Signed-off-by: Joe MacDonald <joe@deserted.net>
This commit is contained in:
schitrod=cisco.com@lists.yoctoproject.org 2023-05-15 06:15:22 -07:00 committed by Joe MacDonald
parent 47858343ed
commit bd3902cb93

View File

@ -17,3 +17,5 @@ do_install() {
LIBDIR="${libdir}" \
SHLIBDIR="${base_libdir}"
}
CVE_PRODUCT ?= "kernel:selinux"