From 641beb3217ce1686772c80ac9e2cf815d72f1624 Mon Sep 17 00:00:00 2001 From: Sam Voss Date: Wed, 29 Sep 2021 22:52:49 -0500 Subject: [PATCH] package/ripgrep: ignore CVE-2021-3013 as Windows only CVE-2021-3013 does not impact any buildroot versions of ripgrep as it is a Windows-only exploit targeting ripgrep versions earlier than 13. It can be safely ignored on our LTS branches. https://nvd.nist.gov/vuln/detail/CVE-2021-3013 Signed-off-by: Sam Voss Signed-off-by: Yann E. MORIN --- package/ripgrep/ripgrep.mk | 3 +++ 1 file changed, 3 insertions(+) diff --git a/package/ripgrep/ripgrep.mk b/package/ripgrep/ripgrep.mk index 2d9dd3ee2f..7c2b79a4a7 100644 --- a/package/ripgrep/ripgrep.mk +++ b/package/ripgrep/ripgrep.mk @@ -10,6 +10,9 @@ RIPGREP_LICENSE = MIT RIPGREP_LICENSE_FILES = LICENSE-MIT RIPGREP_CPE_ID_VENDOR = ripgrep_project +# CVE only impacts ripgrep on Windows +RIPGREP_IGNORE_CVES += CVE-2021-3013 + RIPGREP_DEPENDENCIES = host-rustc RIPGREP_CARGO_ENV = CARGO_HOME=$(HOST_DIR)/share/cargo \ __CARGO_TEST_CHANNEL_OVERRIDE_DO_NOT_USE_THIS="nightly" \