[openwrt/openwrt] trusted-firmware-a.mk: use correct CPE ID

LEDE Commits lede-commits at lists.infradead.org
Wed Dec 21 15:48:31 PST 2022


hauke pushed a commit to openwrt/openwrt.git, branch openwrt-22.03:
https://git.openwrt.org/377d8058879524d07231a11da0e5ccfeed0424e2

commit 377d8058879524d07231a11da0e5ccfeed0424e2
Author: Stijn Tintel <stijn at linux-ipv6.be>
AuthorDate: Tue Dec 20 20:04:53 2022 +0200

    trusted-firmware-a.mk: use correct CPE ID
    
    There are 2 different CPE IDs on the NVD website:
    cpe:/a:arm:trusted_firmware-a
    cpe:/o:arm:arm_trusted_firmware
    
    The ID as currently used in trusted-firmware-a.mk does not exist. The
    CPE ID using the arm_trusted_firmware product name only lists a few
    records for versions 2.2 and 2.3 on the NVD site. The CPE ID using the
    trusted_firmware-a product name lists many more records, and actually
    has a CVE linked to it. Therefore, use the CPE ID using the
    trusted_firmware-a product name.
    
    Fixes: 104d60fe94ce ("trusted-firmware-a.mk: add PKG_CPE_ID")
    Signed-off-by: Stijn Tintel <stijn at linux-ipv6.be>
    (cherry picked from commit c8c6508c22c59a09b7acce63bed28947788a46d4)
---
 include/trusted-firmware-a.mk | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/trusted-firmware-a.mk b/include/trusted-firmware-a.mk
index d95250452b..14c03b99c8 100644
--- a/include/trusted-firmware-a.mk
+++ b/include/trusted-firmware-a.mk
@@ -1,5 +1,5 @@
 PKG_NAME ?= trusted-firmware-a
-PKG_CPE_ID ?= cpe:/a:arm:arm_trusted_firmware
+PKG_CPE_ID ?= cpe:/a:arm:trusted_firmware-a
 
 ifndef PKG_SOURCE_PROTO
 PKG_SOURCE = trusted-firmware-a-$(PKG_VERSION).tar.gz




More information about the lede-commits mailing list