Age | Commit message (Collapse) | Author |
|
Last commit tried to convert CVE_CHECK_IGNORE to CVE_STATUS,
however it was done in wrong way and caused the CVEs
to be reported as open again.
This fixes CVE_STATUS syntax.
Signed-off-by: Peter Marko <peter.marko@siemens.com>
|
|
The preferred variable name is now CVE_STATUS since:
openembedded-core 34f682a24b7075b12ec308154b937ad118d69fe5
"cve-check: add option to add additional patched CVEs"
Fixes:
WARNING: /build/../meta-java/recipes-core/jcraft/jsch_0.1.40.bb:
CVE_CHECK_IGNORE is deprecated in favor of CVE_STATUS
WARNING: /build/../meta-java/recipes-core/xerces-j/xerces-j_2.11.0.bb:
CVE_CHECK_IGNORE is deprecated in favor of CVE_STATUS
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
|
|
The archive URL has changed slightly, add missing /source/.
https://archive.apache.org/dist/xerces/j/source/
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
|
|
Signed-off-by: Jeremy A. Puhlman <jpuhlman@mvista.com>
Signed-off-by: Richard Leitner <richard.leitner@skidata.com>
|
|
Whitelisted below CVE:
CVE-2018-2799:
CVE only applies to some Oracle Java SE and Red Hat
Enterprise Linux versions which is already fixed with
updates and the issue is closed.
Link: https://access.redhat.com/security/cve/CVE-2018-2799
Link: https://bugzilla.redhat.com/show_bug.cgi?id=1567542
Signed-off-by: Saloni Jain <jainsaloni0918@gmail.com>
Signed-off-by: Richard Leitner <richard.leitner@skidata.com>
|
|
Signed-off-by: AJ Bagwell <anthony.bagwell@hivehome.com>
Signed-off-by: Richard Leitner <richard.leitner@skidata.com>
|
|
Replaces them with class-native.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
|
|
The DEPENDS would be handled in native.bbclass, it's not necessary to
set them explicitly in recipes.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
|
|
bitbake rev 67a7b8b02 "build: don't use $B as the default cwd for
functions" (included in current bitbake master) breaks the assumption
that do_unpackpost runs inside the build directory. Now that has to be
set explicitly, which is also okay for older bitbake versions.
Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
Signed-off-by: Otavio Salvador <otavio@ossystems.com.br>
|
|
This reverts commit 04d5d0bf414c05ca59618d77f17ff9898aa1c566.
Detail reason is in the following commit.
Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
|
|
Instead of potential circular depending virtual/javac-native (even this
recipe provides such a useable java-native), rely on well known path
via cacao-native to build up to icedtea7-native in reliable manner.
virtual/javac-native should be used by parts not belonging to the bootstrap
phase.
Signed-off-by: Jens Rehsack <sno@netbsd.org>
Signed-off-by: Maxin B. John <maxin.john@intel.com>
|
|
This makes other javac implementations happy
Signed-off-by: Khem Raj <raj.khem@gmail.com>
|
|
Fixes warnings like
WARNING: bcel-native: No generic license file exists for: AL2.0 in any
provider
and so on
Signed-off-by: Khem Raj <raj.khem@gmail.com>
|
|
|
|
|
|
archive.apache.org
commons-cli, commons-codec, commons-collections, commons-configuration, commons-digester,
commons-discovery, commons-el, commons-fileupload, commons-httpclient, commons-io,
commons-jxpath, commons-lang, commons-logging, commons-net, commons-pool,
avalon-framework-api, logkit, oro, poi and xerces-j have been updated accordingly.
Signed-off-by: Xerxes Rånby <xerxes@zafena.se>
|
|
* taken over mostly stuff from oe classic
* cleaned up recipes
* added license checksums
* bump icedtea6-native to 1.8.11
* use jamvm from git as native
|