[OE-core] [PATCH 1/1] binutils: fix PV to respect upstream tag and also cve database

Burton, Ross ross.burton at intel.com
Thu Mar 28 14:38:40 UTC 2019


On Thu, 28 Mar 2019 at 14:25, Tom Rini <trini at konsulko.com> wrote:
> Bumping PE is what this is for too, to not break package feeds after
> we've done something wrong in PV.  So lets bump PE and not break feeds.
> Especially since this is so that CVE check starts to see and correctly
> complain about issues that will result in "lets move this from master to
> ..." and so break feeds.

Bumping PE is a nuclear-armed hammer when setting CVE_VERSION="2.32"
is sufficient and will go away when we upgrade to 2.32.1 onwards.

Ross


More information about the Openembedded-core mailing list