mirror of
https://github.com/motioneye-project/motioneyeos.git
synced 2025-07-25 20:26:34 +00:00
docs/manual: describe the new <pkg>_IGNORE_CVES variable
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> Signed-off-by: Titouan Christophe <titouan.christophe@railnova.eu> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
This commit is contained in:
parent
4a157be9ef
commit
ea796fc542
@ -488,6 +488,20 @@ not and can not work as people would expect it should:
|
|||||||
locations, `/lib/firmware`, `/usr/lib/firmware`, `/lib/modules`,
|
locations, `/lib/firmware`, `/usr/lib/firmware`, `/lib/modules`,
|
||||||
`/usr/lib/modules`, and `/usr/share`, which are automatically excluded.
|
`/usr/lib/modules`, and `/usr/share`, which are automatically excluded.
|
||||||
|
|
||||||
|
* +LIBFOO_IGNORE_CVES+ is a space-separated list of CVEs that tells
|
||||||
|
Buildroot CVE tracking tools which CVEs should be ignored for this
|
||||||
|
package. This is typically used when the CVE is fixed by a patch in
|
||||||
|
the package, or when the CVE for some reason does not affect the
|
||||||
|
Buildroot package. A Makefile comment must always precede the
|
||||||
|
addition of a CVE to this variable. Example:
|
||||||
|
|
||||||
|
----------------------
|
||||||
|
# 0001-fix-cve-2020-12345.patch
|
||||||
|
LIBFOO_IGNORE_CVES += CVE-2020-12345
|
||||||
|
# only when built with libbaz, which Buildroot doesn't support
|
||||||
|
LIBFOO_IGNORE_CVES += CVE-2020-54321
|
||||||
|
----------------------
|
||||||
|
|
||||||
The recommended way to define these variables is to use the following
|
The recommended way to define these variables is to use the following
|
||||||
syntax:
|
syntax:
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user