cip-dev.lists.cip-project.org archive mirror
 help / color / mirror / Atom feed
* [cip-dev] [ANNOUNCE] Linux kernel CVE tracker
@ 2018-12-19 16:08 Ben Hutchings
  0 siblings, 0 replies; only message in thread
From: Ben Hutchings @ 2018-12-19 16:08 UTC (permalink / raw)
  To: cip-dev

As part of my work for the Civil Infrastructure Platform, I've been
tracking security issues in the kernel and trying to ensure that the
fixes are applied to stable branches as necessary.

The "kernel-sec" repository at
<https://gitlab.com/cip-project/cip-kernel/cip-kernel-sec> contains
information about known issues and scripts to aid in maintaining and
viewing that information.  Issues are identified by CVE ID and their
status is recorded for mainline and all live stable branches.

I import most of the information from distribution security trackers,
and from upstream commit references in stable branch commit messages. 
Manual editing is needed mostly to correct errors in these sources, or
where the commits fixing an issue in a stable branch don't correspond
exactly to the commits fixing it in mainline.

I recently added a local web application that allows browsing the
status of all branches and issues, complete with links to references
and related commits.  There is also a simple reporting script that
lists open issues for each branch.

If you're interested in security support for stable branches, please
take a look at this.

I would welcome merge requests to add to the issue data or to improve
the scripts.

Ben.

-- 
Ben Hutchings, Software Developer                ?        Codethink Ltd
https://www.codethink.co.uk/                 Dale House, 35 Dale Street
                                     Manchester, M1 2HF, United Kingdom

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2018-12-19 16:08 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-12-19 16:08 [cip-dev] [ANNOUNCE] Linux kernel CVE tracker Ben Hutchings

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).