Skip to content

Conversation

@bmastbergen
Copy link
Collaborator

@bmastbergen bmastbergen commented Nov 10, 2025

Allow commits to reference CVEs using 'cve-bf CVE-YYYY-NNNN' or 'cve-pre CVE-YYYY-NNNN' in addition to the standard 'cve CVE-YYYY-NNNN' format when validating against JIRA VULN tickets. Otherwise we will output a warning for these commits even though they are correctly referencing the CVE from the ticket.

Here is an example of the warnings we get today for 'cve-pre' or 'cve-bf' references:
ctrliq/kernel-src-tree#670 (comment)

Allow commits to reference CVEs using 'cve-bf CVE-YYYY-NNNN' or
'cve-pre CVE-YYYY-NNNN' in addition to the standard 'cve CVE-YYYY-NNNN'
format when validating against JIRA VULN tickets.  Otherwise we will
output a warning for these commits even though they are correctly
referencing the CVE from the ticket.
Copy link
Contributor

@thefossguy-ciq thefossguy-ciq left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚤

@bmastbergen bmastbergen merged commit bcb91b2 into mainline Nov 10, 2025
@bmastbergen bmastbergen deleted the cve-pre-and-cve-bf-are-ok branch November 10, 2025 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants