[Buildroot] [git commit branch/next] support/scripts/pkg-stats: verified CPE has a known id but not version

Yann E. MORIN yann.morin.1998 at free.fr
Tue Aug 3 21:10:00 UTC 2021


commit: https://git.buildroot.net/buildroot/commit/?id=9b83bb13826ac3c34e6fb67a5092d94d98ca6a5d
branch: https://git.buildroot.net/buildroot/commit/?id=refs/heads/next

Currently a verified CPE reports the following if versions are not found
 cpe:2.3:a:qemu:qemu:5.2.0:*:*:*:*:*:*:*
 CPE identifier unknown in CPE database (Search)

This patch clarifies the report to state the 'version' is unknown instead
of the 'identifier'.

Cc: Yann E. MORIN <yann.morin.1998 at free.fr>
Signed-off-by: Matthew Weber <matthew.weber at collins.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998 at free.fr>
---
 support/scripts/pkg-stats | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/support/scripts/pkg-stats b/support/scripts/pkg-stats
index 0cd3674c52..42c36f7f94 100755
--- a/support/scripts/pkg-stats
+++ b/support/scripts/pkg-stats
@@ -610,7 +610,7 @@ def check_package_cpes(nvd_path, packages):
         if cpedb.find(p.cpeid):
             p.status['cpe'] = ("ok", "verified CPE identifier")
         else:
-            p.status['cpe'] = ("error", "CPE identifier unknown in CPE database")
+            p.status['cpe'] = ("error", "CPE version unknown in CPE database")
 
 
 def calculate_stats(packages):


More information about the buildroot mailing list