Skip to content

Fix false positives in CVE check#280

Open
atcstew wants to merge 1 commit intolinux4sam:scarthgapfrom
atcstew:cve-version-cryptoauthlib
Open

Fix false positives in CVE check#280
atcstew wants to merge 1 commit intolinux4sam:scarthgapfrom
atcstew:cve-version-cryptoauthlib

Conversation

@atcstew
Copy link

@atcstew atcstew commented Sep 18, 2025

The Yocto Scarthgap CVE checker flags the following as unresolved CVEs:

Provide the legacy CVE_VERSION so that these false positives don't show up.

This prevents false positives from the CVE checker, as NVD still
expects the old style (YYYYMMDD) version numbering.

Signed-off-by: Aidan Stewart <astewart@tektelic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant