From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Wed, 16 Sep 2026 15:54:00 +0200 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x6q5I-002oFf-0E for lore@lore.pengutronix.de; Wed, 16 Sep 2026 15:54:00 +0200 Received: from [127.0.0.1] (helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1x6q5H-0005A3-GK; Wed, 16 Sep 2026 15:53:59 +0200 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1x6q4z-00059w-3A for ptxdist@pengutronix.de; Wed, 16 Sep 2026 15:53:41 +0200 Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=thorsis.com header.s=dkim header.b=oH+9Fu0t; spf=pass (mx1.white.stw.pengutronix.de: domain of ada@thorsis.com designates 2003:a:e28:26e4::10 as permitted sender) smtp.mailfrom=ada@thorsis.com; dmarc=pass (policy=quarantine) header.from=thorsis.com Received: from mail.thorsis.com (mail.thorsis.com [IPv6:2003:a:e28:26e4::10]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id A8AA7202168 for ; Wed, 16 Sep 2026 15:53:40 +0200 (CEST) Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id 4885614890FD; Wed, 16 Sep 2026 15:53:46 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thorsis.com; s=dkim; t=1789566827; h=from:subject:date:message-id:to:cc:mime-version:content-type: in-reply-to:references; bh=sq1bjMuC3d15DNV2BihTT8oPB/xKPulVTP+6YgMHvKQ=; b=oH+9Fu0tOJH+nfk+OSgkdXprLtC+Uu6+g5Kxp4mP9/4V+fqO85qyYKFiuQp3taWJ9hYvg8 SjGrZPCB67KwSXX9I2vLm9xd0LgOopRTcRaQHmlImA96S6VmwHnQa3RR1nwluvycO1QH3f D/lcYnW6+PfInoZLlaKwJBuk6xs3a60XSwuybigBbL7fD5OZoxYnPtZs8mnjeEMejNLbgJ 9BtQAZTUsRJfeVVK6Lj//rtqecqs0ToaCnDmrURhbR48WnE/ruVsJE8WjnIKnUXg/SiDkG FCSoZa91s5tLIxhwvrY638OCi2xSVo7pYMMah73q/9S2Vd5bG1c9FRZB5uYDWA== Date: Wed, 16 Sep 2026 15:53:38 +0200 To: Alexander Dahl via ptxdist Message-ID: <20260916-shortage-evoke-e3f406644b3f@thorsis.com> Mail-Followup-To: Alexander Dahl via ptxdist References: <20260914121307.134745-1-ada@thorsis.com> <20260914121307.134745-3-ada@thorsis.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260914121307.134745-3-ada@thorsis.com> User-Agent: Mutt/2.2.13 (2024-03-09) X-Last-TLS-Session-Version: TLSv1.3 X-Rspamd-Server: mx1 X-Stat-Signature: cn115gspi6fqasid6tdfqnygp77ta64s X-Rspamd-Queue-Id: A8AA7202168 X-Spamd-Result: default: False [-4.00 / 15.00]; BAYES_HAM(-3.00)[99.99%]; DMARC_POLICY_ALLOW(-0.50)[thorsis.com,quarantine]; R_DKIM_ALLOW(-0.20)[thorsis.com:s=dkim]; R_SPF_ALLOW(-0.20)[+mx]; MIME_GOOD(-0.10)[text/plain]; RCVD_TLS_ALL(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; RCVD_COUNT_ONE(0.00)[1]; ASN(0.00)[asn:3320, ipnet:2003::/19, country:DE]; MID_RHS_MATCH_FROM(0.00)[]; NEURAL_HAM(-0.00)[-1.000]; MIME_TRACE(0.00)[0:+]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_TWO(0.00)[2]; TO_MATCH_ENVRCPT_SOME(0.00)[]; RECEIVED_HELO_LOCALHOST(0.00)[]; TO_DN_ALL(0.00)[]; DKIM_TRACE(0.00)[thorsis.com:+] X-Rspamd-Action: no action Subject: Re: [ptxdist] [PATCH 02/21] boost: Add matching CPE identfiers X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Alexander Dahl via ptxdist Reply-To: ptxdist@pengutronix.de Cc: Alexander Dahl Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Hello, Am Mon, Sep 14, 2026 at 02:12:48PM +0200 schrieb Alexander Dahl via ptxdist: > Link: https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:boost:boost > Signed-off-by: Alexander Dahl > --- > rules/boost.make | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/rules/boost.make b/rules/boost.make > index a3b453efb..fbf6b477c 100644 > --- a/rules/boost.make > +++ b/rules/boost.make > @@ -24,6 +24,8 @@ BOOST_SOURCE := $(SRCDIR)/$(BOOST).$(BOOST_SUFFIX) > BOOST_DIR := $(BUILDDIR)/$(BOOST) > BOOST_LICENSE := BSL-1.0 > BOOST_LICENSE_FILES := file://LICENSE_1_0.txt;md5=e4224ccaecb14d942c71d31bef20d78c > +BOOST_CVE_PRODUCT := boost:boost > +BOOST_CVE_VERSION := $(subst _,.,$(BOOST_VERSION)) Maybe it's better to set BOOST_VERSION to the variant with dots like 1.89.0 and use `subst` for $(BOOST)? This way file and folder names stay the same as before like 1_89_0 and the variant in the usual format with dots ends up in for example SBOM files? An alternative section would look like this: BOOST_VERSION := 1.89.0 BOOST_MD5 := e7414f68f1cb3fd834fc155c7a009aa6 BOOST := boost_$(subst .,_,$(BOOST_VERSION)) BOOST_SUFFIX := tar.bz2 BOOST_URL := $(call ptx/mirror, SF, boost/$(BOOST_VERSION)/$(BOOST).$(BOOST_SUFFIX)) BOOST_SOURCE := $(SRCDIR)/$(BOOST).$(BOOST_SUFFIX) BOOST_DIR := $(BUILDDIR)/$(BOOST) BOOST_LICENSE := BSL-1.0 BOOST_LICENSE_FILES := file://LICENSE_1_0.txt;md5=e4224ccaecb14d942c71d31bef20d78c BOOST_CVE_PRODUCT := boost:boost Note, we can add the subfolder in BOOST_URL now, one less redirect. Not sure if I thought about all implications though. ^^ Greets Alex