1
Fork 0
mirror of https://https.git.savannah.gnu.org/git/guix.git/ synced 2025-07-16 03:50:45 +02:00

gnu: git: Use lint-hidden-cpe-vendors.

* gnu/packages/version-control.scm (git-minimal, git)[properties]: Use
lint-hidden-cpe-vendors in place of lint-hidden-cve.

Signed-off-by: Zheng Junjie <z572@z572.online>
This commit is contained in:
Nicolas Graves 2025-03-07 14:40:06 +01:00 committed by Zheng Junjie
parent eecd00e744
commit 06c5c2d41e
No known key found for this signature in database
GPG key ID: 3B5AA993E1A2DFF0

View file

@ -591,20 +591,7 @@ Python 3.3 and later, rather than on Python 2.")
(description
"Git is a free distributed version control system designed to handle
everything from small to very large projects with speed and efficiency.")
;; XXX: Ignore this CVE to work around a name clash with the unrelated
;; "cpe:2.3:a:jenkins:git" package. The proper fix is for (guix cve) to
;; account for "vendor names".
(properties '((lint-hidden-cve . ("CVE-2018-1000182"
"CVE-2018-1000110"
"CVE-2019-1003010"
"CVE-2020-2136"
"CVE-2021-21684"
"CVE-2022-30947"
"CVE-2022-30948"
"CVE-2022-30949"
"CVE-2022-36882"
"CVE-2022-36883"
"CVE-2022-36884"))
(properties '((lint-hidden-cpe-vendors . ("jenkins"))
(upstream-name . "git")))
(license license:gpl2)
(home-page "https://git-scm.com/")))