[libvirt] [security-notice PATCH 9/9] notices: re-generate all branch/tag info

Ján Tomko jtomko at redhat.com
Fri Jun 14 11:09:44 UTC 2019


On Mon, May 13, 2019 at 12:52:06PM +0100, Daniel P. Berrangé wrote:
>Use the new script logic to regenerate all branch tag info for flaws
>
>A few manual edits are still needed, as the script still doesn't cope
>with two situations:
>
>  - The vulnerable commit from master was backported to an older
>    branch. We don't search older branches looking for cherry-picks
>    yet
>  - There are multiple vulnerable commits, and they were introduce
>    across multiple releases. This means some older branches only
>    contain a subset of the vulnerable commits. We don't check
>    which vulnerable commits are applicable to branches, instead
>    assuming all vulnerable commits arrived at the same time.
>
>Signed-off-by: Daniel P. Berrangé <berrange at redhat.com>
>---
> notices/2008/0001.xml |   6 --

[...]

> notices/2019/0002.xml |   2 +-
> 47 files changed, 1224 insertions(+), 189 deletions(-)
>

Reviewed-by: Ján Tomko <jtomko at redhat.com>

Jano
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/libvir-list/attachments/20190614/2b505ddf/attachment-0001.sig>


More information about the libvir-list mailing list