Re: [OE-core][kirkstone][PATCH] libpciaccess: Remove duplicated license entry

2024-05-05 Thread Bhabu Bindu via lists.openembedded.org
Hello Steve, The license is already corrected in master branch during libpciaccess upgrade. Link given below, I guess it doesn't need a patch for master as issue is resolved. Link: https://git.yoctoproject.org/poky/commit/meta/recipes-graphics/xorg-lib?id=00013601aad7826df6524b15356ce935234af3e

[OE-core][kirkstone][PATCH 1/1] ncurses: Fix CVE-2023-45918

2024-05-05 Thread Soumya via lists.openembedded.org
From: Soumya Sambu ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c. References: https://nvd.nist.gov/vuln/detail/CVE-2023-45918 Signed-off-by: Soumya Sambu --- .../ncurses/files/CVE-2023-45918.patch| 180 ++ .../ncurses/ncurses_6.

[OE-core][PATCH 1/1] ncurses: Fix CVE-2023-45918

2024-05-05 Thread Soumya via lists.openembedded.org
From: Soumya Sambu ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c. References: https://nvd.nist.gov/vuln/detail/CVE-2023-45918 Signed-off-by: Soumya Sambu --- .../ncurses/files/CVE-2023-45918.patch| 180 ++ meta/recipes-core/ncur

[oe-core][kirkstone][PATCH V2 1/1] gstreamer1.0-plugins-bad: fix CVE-2023-44446

2024-05-05 Thread Polampalli, Archana via lists.openembedded.org
From: Archana Polampalli Signed-off-by: Archana Polampalli --- .../CVE-2023-6.patch | 329 ++ .../gstreamer1.0-plugins-bad_1.20.7.bb| 1 + 2 files changed, 330 insertions(+) create mode 100644 meta/recipes-multimedia/gstreamer/gstreamer1.0-pl

[OE-core][kirkstone][PATCH] libpciaccess: Remove duplicated license entry

2024-05-05 Thread dnyandev
From: Bhabu Bindu Remove duplicated MIT license entry for libpciaccess Duplication was done as part of below commit: Link: https://git.yoctoproject.org/poky/commit/meta/recipes-graphics/xorg-lib/libpciaccess_0.16.bb?h=kirkstone&id=b0130fcf91daee0d905af755302fabe608da141c Signed-off-by: Bhabu

[OE-core] [PATCH] python3-manifest: prune python3-core

2024-05-05 Thread Guðni Már Gilbert
Remove file entries which no longer exist in the source. I spotted this when I added a custom QA error locally which raised a warning when a file in FILES list of a package isn't found in the source. Signed-off-by: Guðni Már Gilbert --- .../python/python3/python3-manifest.json | 23 ---

[OE-core][kirkstone][PATCH] libpciaccess: Remove duplicated license entry

2024-05-05 Thread dnyandev
From: Bhabu Bindu Remove duplicated MIT license entry for libpciaccess Duplication was done as part of below commit: Link: https://git.yoctoproject.org/poky/commit/meta/recipes-graphics/xorg-lib/libpciaccess_0.16.bb?h=kirkstone&id=b0130fcf91daee0d905af755302fabe608da141c Signed-off-by: Bhabu

[OE-core] [PATCH] devtool: ide-sdk: correct help typo

2024-05-05 Thread Antonin Godard via lists.openembedded.org
Signed-off-by: Antonin Godard --- scripts/lib/devtool/ide_sdk.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/lib/devtool/ide_sdk.py b/scripts/lib/devtool/ide_sdk.py index 7807b322b3..65873b088d 100755 --- a/scripts/lib/devtool/ide_sdk.py +++ b/scripts/lib/devtool/i

Re: [OE-core][PATCH] glibc: correct license

2024-05-05 Thread Khem Raj
On Sun, May 5, 2024 at 1:43 PM Marko, Peter wrote: > > From: Khem Raj > Sent: Sunday, May 5, 2024 21:22 > To: Marko, Peter (ADV D EU SK BFS1) > Cc: openembedded-core@lists.openembedded.org > Subject: Re: [OE-core][PATCH] glibc: correct license > > > On Sun, May 5, 2024 at 2:18 AM Peter Marko via

Re: [OE-core][PATCH] glibc: correct license

2024-05-05 Thread Peter Marko via lists.openembedded.org
From: Khem Raj Sent: Sunday, May 5, 2024 21:22 To: Marko, Peter (ADV D EU SK BFS1) Cc: openembedded-core@lists.openembedded.org Subject: Re: [OE-core][PATCH] glibc: correct license > On Sun, May 5, 2024 at 2:18 AM Peter Marko via http://lists.openembedded.org > mailto:siemens@lists.openemb

Re: [OE-core][PATCH] glibc: correct license

2024-05-05 Thread Khem Raj
On Sun, May 5, 2024 at 2:18 AM Peter Marko via lists.openembedded.org wrote: > From: Peter Marko > > The license per https://www.gnu.org/software/libc/ is LGPL-2.1-or-later. > > https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=273a835fe7c685cc54266bb8b502787bad5e9bae > converted last LGPL-

[OE-core] OE-core CVE metrics for nanbield on Sun 05 May 2024 04:00:01 AM HST

2024-05-05 Thread Steve Sakoman
Branch: nanbield New this week: 20 CVEs CVE-2023-52455 (CVSS3: 7.8 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52455 * CVE-2023-52456 (CVSS3: 5.5 MEDIUM): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52456 * CVE-2023-52457 (CVSS3: 7.8 HIG

[OE-core] OE-core CVE metrics for kirkstone on Sun 05 May 2024 03:00:01 AM HST

2024-05-05 Thread Steve Sakoman
Branch: kirkstone New this week: 0 CVEs Removed this week: 0 CVEs Full list: Found 33 unpatched CVEs CVE-2021-35937 (CVSS3: 6.4 MEDIUM): rpm:rpm-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-35937 * CVE-2021-35938 (CVSS3: 6.7 MEDIUM): rpm:rpm-native https://web.nvd.nist.gov

[OE-core] OE-core CVE metrics for dunfell on Sun 05 May 2024 02:00:01 AM HST

2024-05-05 Thread Steve Sakoman
Branch: dunfell New this week: 0 CVEs Removed this week: 0 CVEs Full list: Found 105 unpatched CVEs CVE-2020-15705 (CVSS3: 6.4 MEDIUM): grub:grub-efi:grub-efi-native https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15705 * CVE-2020-25742 (CVSS3: 3.2 LOW): qemu:qemu-native:qemu-system-

[OE-core] [PATCH] python3-pyopenssl: drop python3-six from RDEPENDS

2024-05-05 Thread Guðni Már Gilbert
Python 2.7 support was dropped in version 22.0.0 python3-six was dropped as a dependency in 22.0.0 Signed-off-by: Guðni Már Gilbert --- meta/recipes-devtools/python/python3-pyopenssl_24.1.0.bb | 1 - 1 file changed, 1 deletion(-) diff --git a/meta/recipes-devtools/python/python3-pyopenssl_24.1.

[OE-core] [PATCH] python3-bcrypt: drop python3-six from RDEPENDS

2024-05-05 Thread Guðni Már Gilbert
Python 2.7 support was dropped in version 3.2.0 and python3-six dependency was subsequently dropped in version 3.2.1 Signed-off-by: Guðni Már Gilbert --- meta/recipes-devtools/python/python3-bcrypt_4.1.2.bb | 1 - 1 file changed, 1 deletion(-) diff --git a/meta/recipes-devtools/python/python3-b

Re: [OE-core] [PATCH] python3-manifest: prune python3-core

2024-05-05 Thread Guðni Már Gilbert
Hi again Tim, update from me regarding the scripts. TLDR: The manifest is out of date, and the python scripts are working as they should. I've convinced myself the python scripts used to generate the manifest *are correct*. However, for anyone reading this, I can confirm the manifest is ou

[OE-core] OE-core CVE metrics for master on Sun 05 May 2024 01:00:01 AM HST

2024-05-05 Thread Steve Sakoman
Branch: master New this week: 2 CVEs CVE-2024-26900 (CVSS3: 5.5 MEDIUM): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-26900 * CVE-2024-26913 (CVSS3: 7.8 HIGH): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-26913 * Removed this week: 7 CVEs CVE-20

[OE-core][PATCH] glibc: correct license

2024-05-05 Thread Peter Marko via lists.openembedded.org
From: Peter Marko The license per https://www.gnu.org/software/libc/ is LGPL-2.1-or-later. https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=273a835fe7c685cc54266bb8b502787bad5e9bae converted last LGPL-2.1-only references. License-Update: correction Signed-off-by: Peter Marko --- meta/re