package/sdl2_image: add SDL2_IMAGE_CPE_ID_PRODUCT
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Fri, 5 Mar 2021 15:14:54 +0000 (16:14 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Fri, 5 Mar 2021 21:30:50 +0000 (22:30 +0100)
cpe:2.3:a:libsdl:sdl_image is a valid CPE identifier for this package:

  https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=cpe%3A2.3%3Aa%3Alibsdl%3Asdl2_image

Indeed, cpe:2.3:a:libsdl:sdl2_image contains a single CPE entry for
version 2.0.4, all the other entries have been deprecated in favor of
cpe:2.3:a:libsdl:sdl_image:

  <cpe-item name="cpe:/a:libsdl:sdl2_image:2.0.3" deprecated="true" deprecation_date="2020-07-28T15:42:37.767Z">
      <reference href="https://www.libsdl.org/projects/SDL_image/">Product</reference>
    <cpe-23:cpe23-item name="cpe:2.3:a:libsdl:sdl2_image:2.0.3:*:*:*:*:*:*:*">
        <cpe-23:deprecated-by name="cpe:2.3:a:libsdl:sdl_image:2.0.3:*:*:*:*:*:*:*" type="NAME_CORRECTION"/>
  <cpe-item name="cpe:/a:libsdl:sdl2_image:2.0.4">
      <reference href="http://hg.libsdl.org/SDL_image/">Version</reference>
    <cpe-23:cpe23-item name="cpe:2.3:a:libsdl:sdl2_image:2.0.4:*:*:*:*:*:*:*"/>
  <cpe-item name="cpe:/a:libsdl:sdl2_image:2.0.5" deprecated="true" deprecation_date="2020-07-28T15:42:40.500Z">
      <reference href="http://hg.libsdl.org/SDL_image/">Version</reference>
    <cpe-23:cpe23-item name="cpe:2.3:a:libsdl:sdl2_image:2.0.5:*:*:*:*:*:*:*">
        <cpe-23:deprecated-by name="cpe:2.3:a:libsdl:sdl_image:2.0.5:*:*:*:*:*:*:*" type="NAME_CORRECTION"/>:

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/sdl2_image/sdl2_image.mk

index 06f6eca30c8a9b73c0c656376cc6dee97e187eac..13de7b12686d750649206bbeef4f532e602b0b61 100644 (file)
@@ -11,6 +11,7 @@ SDL2_IMAGE_INSTALL_STAGING = YES
 SDL2_IMAGE_LICENSE = Zlib
 SDL2_IMAGE_LICENSE_FILES = COPYING.txt
 SDL2_IMAGE_CPE_ID_VENDOR = libsdl
+SDL2_IMAGE_CPE_ID_PRODUCT = sdl_image
 
 # Unconditionally enable support for image formats that don't require
 # any dependency.