-
Notifications
You must be signed in to change notification settings - Fork 585
Add Documentation: CVE Quickstart Guide #11294
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: 3.0
Are you sure you want to change the base?
Conversation
2. Apply the patch: | ||
```bash | ||
patch -p1 --fuzz=0 < CVE-xxxx-yyyy.patch | ||
``` |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we add "Tips for working with patches that don't apply cleanly"?
- Monitor for additional verification or testing needs. | ||
|
||
--- | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Any specific section needed for Dispute?
https://dev.azure.com/mariner-org/mariner/_wiki/wikis/mariner.wiki/1688/Resolve-and-Dispute-Process
# **Document: Fixing CVE Patches for Azure Linux** | ||
|
||
This document provides a step-by-step guide to fixing CVE patches for Azure Linux. It includes identifying the CVE, locating and preparing the package, applying the patch, and submitting it for integration into Azure Linux. | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Shall I add the CVE Guide in ADO: https://dev.azure.com/mariner-org/mariner/_wiki/wikis/mariner.wiki/233/CVEs?
4. Commit and push changes: | ||
```bash | ||
git add -u | ||
git commit -m "Fix CVE-xxxx-yyyy" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
leave a signed commit message
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-static
subpackages, etc.) have had theirRelease
tag incremented../cgmanifest.json
,./toolkit/scripts/toolchain/cgmanifest.json
,.github/workflows/cgmanifest.json
)./LICENSES-AND-NOTICES/SPECS/data/licenses.json
,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON
)*.signatures.json
filessudo make go-tidy-all
andsudo make go-test-coverage
passSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology