浏览代码

package/python-pip: ignore CVE-2018-20225

See https://security-tracker.debian.org/tracker/CVE-2018-20225 for the
rationale of ignoring this CVE. Things basically work as intended.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 57229c22f17fa892c18dff1e424dedc7e3d05358)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Thomas Petazzoni 1 年之前
父节点
当前提交
45440a7e62
共有 1 个文件被更改,包括 3 次插入0 次删除
  1. 3 0
      package/python-pip/python-pip.mk

+ 3 - 0
package/python-pip/python-pip.mk

@@ -12,6 +12,9 @@ PYTHON_PIP_LICENSE = MIT
 PYTHON_PIP_LICENSE_FILES = LICENSE.txt
 PYTHON_PIP_CPE_ID_VENDOR = pypa
 PYTHON_PIP_CPE_ID_PRODUCT = pip
+# Disputed CVE: things work as designed, and only affects the
+# --extra-index-url option. This CVE will never be fixed.
+PYTHON_PIP_IGNORE_CVES += CVE-2018-20225
 
 $(eval $(python-package))
 $(eval $(host-python-package))