package/ripgrep: ignore CVE-2021-3013 as Windows only

CVE-2021-3013 does not impact any buildroot versions of ripgrep as it is
a Windows-only exploit targeting ripgrep versions earlier than 13. It
can be safely ignored on our LTS branches.

    https://nvd.nist.gov/vuln/detail/CVE-2021-3013

Signed-off-by: Sam Voss <sam.voss@gmail.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
(cherry picked from commit 641beb3217)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
This commit is contained in:
Sam Voss 2021-09-29 22:52:49 -05:00 committed by Peter Korsgaard
parent b22acc487f
commit 03952dfb73

View File

@ -10,6 +10,9 @@ RIPGREP_LICENSE = MIT
RIPGREP_LICENSE_FILES = LICENSE-MIT
RIPGREP_CPE_ID_VENDOR = ripgrep_project
# CVE only impacts ripgrep on Windows
RIPGREP_IGNORE_CVES += CVE-2021-3013
RIPGREP_DEPENDENCIES = host-rustc
RIPGREP_CARGO_ENV = CARGO_HOME=$(HOST_DIR)/share/cargo