<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/pepe2k/scripts, branch v23.05.4</title>
<subtitle>Staging tree of Piotr Dymacz</subtitle>
<id>https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v23.05.4</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v23.05.4'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/'/>
<updated>2024-07-08T19:13:26Z</updated>
<entry>
<title>scripts: Add GNU ftp mirror redirector for GNU and Savannah</title>
<updated>2024-07-08T19:13:26Z</updated>
<author>
<name>Sahil Dhiman</name>
</author>
<published>2024-05-25T09:57:12Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=4df592f7a34166a57dab2ab7570ce3fe2ebd3118'/>
<id>urn:sha1:4df592f7a34166a57dab2ab7570ce3fe2ebd3118</id>
<content type='text'>
Add GNU's redirector which automatically redirect user to nearby online
mirror.

Signed-off-by: Sahil Dhiman &lt;sahil@hopbox.in&gt;
Link: https://github.com/openwrt/openwrt/pull/15557
Signed-off-by: Robert Marko &lt;robimarko@gmail.com&gt;
(cherry picked from commit 6510eb3b5d612ea7a70c4a8d9b83639e3b46e221)
Link: https://github.com/openwrt/openwrt/pull/15898
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>scripts/ext-toolchain: add missing libc library specs</title>
<updated>2024-07-08T19:13:25Z</updated>
<author>
<name>Christian Marangi</name>
</author>
<published>2024-06-17T11:19:52Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=f8690ca0db5e3c2ece966d8323c1a40bf62ec6d8'/>
<id>urn:sha1:f8690ca0db5e3c2ece966d8323c1a40bf62ec6d8</id>
<content type='text'>
Add missing libc library spec that weren't added to the ext-toolchain
script when the library were introduced in the packages libs toolchain
Makefile.

Signed-off-by: Christian Marangi &lt;ansuelsmth@gmail.com&gt;
(cherry picked from commit 8cad52a267bffe384a119f3e5ae1892e8580a981)
Link: https://github.com/openwrt/openwrt/pull/15898
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>build: add explicit timezone in CycloneDX SBOM</title>
<updated>2024-06-20T12:58:17Z</updated>
<author>
<name>Roman Azarenko</name>
</author>
<published>2024-06-04T16:00:03Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=cc0527b36281e7347f4da1b1169e11e7215c8c60'/>
<id>urn:sha1:cc0527b36281e7347f4da1b1169e11e7215c8c60</id>
<content type='text'>
The sender domain has a DMARC Reject/Quarantine policy which disallows
sending mailing list messages using the original "From" header.

To mitigate this problem, the original message has been wrapped
automatically by the mailing list software.
Per the CycloneDX 1.4 spec, the `metadata.timestamp` field contains
the date/time when the BOM was created [1].

Before the change, the value generated by the package-metadata.pl
script would look like this:

	2024-06-03T15:51:10

CycloneDX 1.4 relies on the JSON Schema specification version draft-07,
which defines the `date-time` format [2] as derived from RFC 3339,
section 5.6 [3]. In this format, the `time-offset` component is required,
however in the original version of package-metadata.pl it is omitted.

This is causing problems with OWASP Dependency-Track version 4.11.0 or
newer, where it now validates submitted SBOMs against the JSON schema
by default [4]. SBOMs with incorrect timestamp values are rejected with
the following error:

	{
	    "detail": "Schema validation failed",
	    "errors": [
	        "$.metadata.timestamp: 2024-06-03T15:51:10 is an invalid date-time"
	    ],
	    "status": 400,
	    "title": "The uploaded BOM is invalid"
	}

Add explicit `Z` (UTC) timezone offset in the `timestamp` field
to satisfy the CycloneDX schema.

[1]: https://github.com/CycloneDX/specification/blob/1.4/schema/bom-1.4.schema.json#L116-L121
[2]: https://json-schema.org/draft-07/draft-handrews-json-schema-validation-01#rfc.section.7.3.1
[3]: https://datatracker.ietf.org/doc/html/rfc3339#section-5.6
[4]: https://github.com/DependencyTrack/dependency-track/pull/3522

Signed-off-by: Roman Azarenko &lt;roman.azarenko@iopsys.eu&gt;
(cherry picked from commit 2ded629864de779df8ddd0224a875edf17f9fea5)
Link: https://github.com/openwrt/openwrt/pull/15693
Signed-off-by: Christian Marangi &lt;ansuelsmth@gmail.com&gt;
</content>
</entry>
<entry>
<title>build: fix kernel component in CycloneDX SBOM</title>
<updated>2024-04-17T04:34:36Z</updated>
<author>
<name>Cedric DOURLENT</name>
</author>
<published>2024-03-01T15:42:34Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=340e3dc4537522f44f3b8247d90b132e8e293948'/>
<id>urn:sha1:340e3dc4537522f44f3b8247d90b132e8e293948</id>
<content type='text'>
As stated in the cycloneDX documentation, the field "type" is mandatory for all components.

More details here (https://cyclonedx.org/docs/1.5/json/#components_items_type)

Signed-off-by: Cedric DOURLENT &lt;cedric.dourlent@softathome.com&gt;
(cherry picked from commit 84331215e57090a9cdae4af75af2539c39cd7de7)
</content>
</entry>
<entry>
<title>build: add explicit --no-show-signature for git</title>
<updated>2024-02-20T19:58:41Z</updated>
<author>
<name>Oto Šťáva</name>
</author>
<published>2024-02-16T15:28:10Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=60768064ce5d8801a82a00fe914e6068fbae86e8'/>
<id>urn:sha1:60768064ce5d8801a82a00fe914e6068fbae86e8</id>
<content type='text'>
When `log.showSignature` is set, it causes the `SOURCE_DATE_EPOCH` to
include a textual signature description on OpenPGP-signed commits,
because Git prints the description into stdout. This then causes some
scripts to fail because they cannot parse the date from the variable.

Adding an explicit `--no-show-signature` prevents the signatures from
being displayed even when one has Git configured to show them by
default, fixing the scripts.

Signed-off-by: Oto Šťáva &lt;oto.stava@gmail.com&gt;
(cherry picked from commit 1e93208bd2c605704b19fe8b04025c20c17e808d)
</content>
</entry>
<entry>
<title>scripts: sercomm-pid.py: use uppercase hwid in pid</title>
<updated>2023-11-27T01:02:35Z</updated>
<author>
<name>Mikhail Zhilkin</name>
</author>
<published>2023-11-12T07:46:11Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=dae399196b5b0b84f0250a69e6de42abdebd71d7'/>
<id>urn:sha1:dae399196b5b0b84f0250a69e6de42abdebd71d7</id>
<content type='text'>
Sercomm uses uppercase for hexadecimal representation of the device
hardware IDs in factory image PID. This commit brings the sercomm-pid.py
script into compliance with the original Sercomm algorithm.

Example
-------
+--------+-------------+-----------+-------------+
| Device | PID (before | PID       | PID (after  |
| HWID   | the commit) | (Sercomm) | the commit) |
+--------+-------------+-----------+-------------+
| CPJ    | 43 50 4a    | 43 50 4A  | 43 50 4A    |
+--------+-------------+-----------+-------------+

Signed-off-by: Mikhail Zhilkin &lt;csharper2005@gmail.com&gt;
(cherry picked from commit 28d32244e122051ec88551e831fb9cf34da7cd76)
</content>
</entry>
<entry>
<title>scripts/dump-target-info.pl: add new function to DUMP devices</title>
<updated>2023-11-15T10:00:19Z</updated>
<author>
<name>Christian Marangi</name>
</author>
<published>2023-11-12T18:14:46Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=c7b6cfac40ce1b5e8fb0d9e5ce2c56e089abfadb'/>
<id>urn:sha1:c7b6cfac40ce1b5e8fb0d9e5ce2c56e089abfadb</id>
<content type='text'>
Add new function to dump-targer-info.pl to DUMP devices provided a
matching target/subtarget.

Example:

./scripts/dump-targer-info.pl devices ipq806x/generic

will produce the sorted list of devices defined in the following format:

device_id device_name

Devices may have alternative names, the script will dump each
alternative name in the same line of device_id.

Following the pattern:

device_id "PRIMARY DEVICE NAME" "ALT0 DEVICE NAME" "ALT1 DEVICE NAME" ...

Example:

tplink_ad7200 "TP-Link AD7200 v1/v2" "TP-Link Talon AD7200 v1/v2"

Signed-off-by: Christian Marangi &lt;ansuelsmth@gmail.com&gt;
(cherry picked from commit 943c153cdd695904b9b7fe44800fc3546644973e)
</content>
</entry>
<entry>
<title>scripts/getver.sh: prevent asking for negative rev-parse</title>
<updated>2023-11-12T15:19:39Z</updated>
<author>
<name>Christian Marangi</name>
</author>
<published>2023-11-12T15:15:07Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=101988c61a50e5a8094e5d90f37b75a28bd3ddeb'/>
<id>urn:sha1:101988c61a50e5a8094e5d90f37b75a28bd3ddeb</id>
<content type='text'>
With the case of asking an invalid version that is too big, getver.sh
might return an invalid output in the form of HEAD~-2260475641.

This is caused by BASE_REV - GET_REV using a negative number.

Prevent this by checking if BASE_REV - GET_REV actually return 0 or a
positive number and set REV variable accordingly. With the following
change, invalid revision number will result in unknown printed instead
of the invalid HEAD~-NUMBERS output.

Signed-off-by: Christian Marangi &lt;ansuelsmth@gmail.com&gt;
(cherry picked from commit 9e49e0a6c4535d345084cc62c594be5cad23b911)
</content>
</entry>
<entry>
<title>build: add CycloneDX SBOM JSON support</title>
<updated>2023-11-02T14:44:47Z</updated>
<author>
<name>Petr Štetiar</name>
</author>
<published>2023-10-24T08:27:13Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=21e5db97c410f4008c8fe8515fb79a7cde368dbf'/>
<id>urn:sha1:21e5db97c410f4008c8fe8515fb79a7cde368dbf</id>
<content type='text'>
CycloneDX is an open source standard developed by the OWASP foundation.
It supports a wide range of development ecosystems, a comprehensive set
of use cases, and focuses on automation, ease of adoption, and
progressive enhancement of SBOMs (Software Bill Of Materials) throughout
build pipelines.

So lets add support for CycloneDX SBOM for packages and images
manifests.

Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt;
(cherry picked from commit d604a07225c5c82b942cd3374cc113ad676a2519)
</content>
</entry>
<entry>
<title>package-dumpinfo,metadata: add ABI version information to package index</title>
<updated>2023-11-02T14:44:46Z</updated>
<author>
<name>Petr Štetiar</name>
</author>
<published>2023-10-26T16:11:47Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=4ef8899c7ab6ac9c69f7cc7138c3fc8a3fec777b'/>
<id>urn:sha1:4ef8899c7ab6ac9c69f7cc7138c3fc8a3fec777b</id>
<content type='text'>
There is no standard for ABI versioning, so its not possible to find out
from `libext2fs2`, `libiwinfo20230701` or `libss2` package names if
thats just package name or package name with ABI version included. To
help with the decision, lets make ABI version aviable in package index.

Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt;
(cherry picked from commit 649655f427932fe79b96a41f883c8054b1806191)
</content>
</entry>
</feed>
