Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/patches/2216253/?format=api
{ "id": 2216253, "url": "http://patchwork.ozlabs.org/api/patches/2216253/?format=api", "web_url": "http://patchwork.ozlabs.org/project/buildroot/patch/20260326081422.945900-3-titouan.christophe@mind.be/", "project": { "id": 27, "url": "http://patchwork.ozlabs.org/api/projects/27/?format=api", "name": "Buildroot development", "link_name": "buildroot", "list_id": "buildroot.buildroot.org", "list_email": "buildroot@buildroot.org", "web_url": "", "scm_url": "", "webscm_url": "", "list_archive_url": "", "list_archive_url_format": "", "commit_url_format": "" }, "msgid": "<20260326081422.945900-3-titouan.christophe@mind.be>", "list_archive_url": null, "date": "2026-03-26T08:14:22", "name": "[v2,2/2] SECURITY.md: add new file", "commit_ref": null, "pull_url": null, "state": "accepted", "archived": false, "hash": "4589445f84d423a159dfec389597204fe58e79b6", "submitter": { "id": 90763, "url": "http://patchwork.ozlabs.org/api/people/90763/?format=api", "name": "Titouan Christophe", "email": "titouan.christophe@mind.be" }, "delegate": { "id": 89618, "url": "http://patchwork.ozlabs.org/api/users/89618/?format=api", "username": "juju", "first_name": "Julien", "last_name": "Olivain", "email": "juju@cotds.org" }, "mbox": "http://patchwork.ozlabs.org/project/buildroot/patch/20260326081422.945900-3-titouan.christophe@mind.be/mbox/", "series": [ { "id": 497546, "url": "http://patchwork.ozlabs.org/api/series/497546/?format=api", "web_url": "http://patchwork.ozlabs.org/project/buildroot/list/?series=497546", "date": "2026-03-26T08:14:21", "name": "Add security policy information", "version": 2, "mbox": "http://patchwork.ozlabs.org/series/497546/mbox/" } ], "comments": "http://patchwork.ozlabs.org/api/patches/2216253/comments/", "check": "pending", "checks": "http://patchwork.ozlabs.org/api/patches/2216253/checks/", "tags": {}, "related": [], "headers": { "Return-Path": "<buildroot-bounces@buildroot.org>", "X-Original-To": [ "incoming-buildroot@patchwork.ozlabs.org", "buildroot@buildroot.org" ], "Delivered-To": [ "patchwork-incoming-buildroot@legolas.ozlabs.org", "buildroot@buildroot.org" ], "Authentication-Results": [ "legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=jbecDFA7;\n\tdkim-atps=neutral", "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=140.211.166.136; helo=smtp3.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)" ], "Received": [ "from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fhGm108Qxz1y1G\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Thu, 26 Mar 2026 19:14:57 +1100 (AEDT)", "from localhost (localhost [127.0.0.1])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id C566F60A43;\n\tThu, 26 Mar 2026 08:14:51 +0000 (UTC)", "from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id 2OO6odxcDkEP; Thu, 26 Mar 2026 08:14:51 +0000 (UTC)", "from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id D66B860A58;\n\tThu, 26 Mar 2026 08:14:50 +0000 (UTC)", "from smtp4.osuosl.org (smtp4.osuosl.org [140.211.166.137])\n by lists1.osuosl.org (Postfix) with ESMTP id 4BA86F5\n for <buildroot@buildroot.org>; Thu, 26 Mar 2026 08:14:48 +0000 (UTC)", "from localhost (localhost [127.0.0.1])\n by smtp4.osuosl.org (Postfix) with ESMTP id 3DF0B40990\n for <buildroot@buildroot.org>; Thu, 26 Mar 2026 08:14:48 +0000 (UTC)", "from smtp4.osuosl.org ([127.0.0.1])\n by localhost (smtp4.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id TioWm8mMaybp for <buildroot@buildroot.org>;\n Thu, 26 Mar 2026 08:14:47 +0000 (UTC)", "from mail-ej1-x62a.google.com (mail-ej1-x62a.google.com\n [IPv6:2a00:1450:4864:20::62a])\n by smtp4.osuosl.org (Postfix) with ESMTPS id 2DC5540969\n for <buildroot@buildroot.org>; Thu, 26 Mar 2026 08:14:46 +0000 (UTC)", "by mail-ej1-x62a.google.com with SMTP id\n a640c23a62f3a-b79f8f7ea43so129441466b.2\n for <buildroot@buildroot.org>; Thu, 26 Mar 2026 01:14:46 -0700 (PDT)", "from dragon.home ([109.136.97.112]) by smtp.gmail.com with ESMTPSA\n id\n a640c23a62f3a-b9b2043e7cesm83315866b.57.2026.03.26.01.14.44\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Thu, 26 Mar 2026 01:14:44 -0700 (PDT)" ], "X-Virus-Scanned": [ "amavis at osuosl.org", "amavis at osuosl.org" ], "X-Comment": "SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ", "DKIM-Filter": [ "OpenDKIM Filter v2.11.0 smtp3.osuosl.org D66B860A58", "OpenDKIM Filter v2.11.0 smtp4.osuosl.org 2DC5540969" ], "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1774512890;\n\tbh=rdgf0PK7eBlbFugaCv/5+iuOT1sstvWl75wF5UyrZLs=;\n\th=To:Date:In-Reply-To:References:Subject:List-Id:List-Unsubscribe:\n\t List-Archive:List-Post:List-Help:List-Subscribe:From:Reply-To:Cc:\n\t From;\n\tb=jbecDFA7mjZQjFzAYWpzn4KY9IOnwg6dpJqZiTvfFfm4DdBniRlNDlgRBj1eiwVGM\n\t pFoTpuG3g+JFnv2T6u3QMladOIDiKaKAJGxkfSfniOU5fmxYznOvkf5ecf6c7e9wmP\n\t Xk7MnqWUlV0KKKSVm/PaIsRV9KloCtyzjGlXW2GhPKvuQ2EHeNIsLleCIBZWbsq6+a\n\t luA7Fp5qd7KyWVCq/2RNDYMLG7iuKVfsi1Hnz1jXHm0LYMZ6P5atGlWXrqGAVyzYob\n\t GcNoBEEh2tBtO/fiXDhyAAFVNRk6nQNWA0YSGhNEOXa8CH3ypaCMVhBn8TG879K0g0\n\t xaYZ4Y9fJVQEg==", "Received-SPF": "Pass (mailfrom) identity=mailfrom;\n client-ip=2a00:1450:4864:20::62a; helo=mail-ej1-x62a.google.com;\n envelope-from=titouan.christophe@essensium.com; receiver=<UNKNOWN>", "DMARC-Filter": "OpenDMARC Filter v1.4.2 smtp4.osuosl.org 2DC5540969", "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1774512885; x=1775117685;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from\n :to:cc:subject:date:message-id:reply-to;\n bh=p0imTyOiaR2D+T0jbNOxxRCRJ20RGrp8kTuvYuZFQs4=;\n b=srpVxDmrzR5pReCT5X538xdwVnw/CL8kPV5r4fd56GhvGuO8FwbyAXQotUa47BIPEv\n 8ZgSeTkguA2s6ducKeurWMu+TobaIZ4ODsMTZM3BqooPTU9hnWr9WtZ97bUbRkBjIizz\n svVuqHBQlCCcdFylUN+wulhGCe7Wsa38LZIibrDn1826kewJdHAQnHl15ArSJRHTKP8H\n uMqclWonJ4DXYzj7/O/JdqZIxzeWB5uyCGGQNUFXAmXCkhxV9DUQjWzYzKGSQ/sUFSWX\n lDzUWaHBzRcWlwpT5gKal/WVAopbWEz8jP4SZYzN1SEpXBxTgR9tqid5AhMshXxJhdTf\n RzZw==", "X-Gm-Message-State": "AOJu0Yz7CcgLctwf2lGcpYXMNYBnEz/lAin5lG5NiiuHWk82Zc2O0FPh\n Lu3gTzz35y2ZcXVdR4fYIaJA7+rRqouB5I0A6wSsX7wNEubbM+8U+3DMUFGi5k7Hf9mBgS1bGgQ\n 0t9KdZp0=", "X-Gm-Gg": "ATEYQzwU8pcy2uj6ZXcS2NXFw9M1r5W0PqZ9yyAgzP7sLeXNSMRVxdcSvyTl4a0nMUO\n RPsbPL8y9Bw8NplbqIQK5EehwjRQ1EPugUsymnO+Il78UkWw/9mhB/2PgLT/chBgETYSkRx8dTg\n Pfre96k5qEfbIpt1IKOtFTpkAeQ8MQE8xvIbLhPo6baZ6D6u1MqSpdp3690asTzm01suOcBjlel\n a99I/38UUIFssxgegGqL2hwrv7fGhdWvcEK+Uni0p7KUUGfTcB1aw/LuN/W3ptOKy77u3hGsE+0\n YTjqbSNL2KhKbOsJEVB9sdEv2Le4euj/lIdPPUBGgEkXbC3RbWIXZShAX6of8gwIg7J2i6NlneB\n 9tmsVF/Gq8o9G0uUTwaI1Uny7DbUYFnn6/lIj7bMM+tnFFiCahi+4K1dWRtxGofl4zm5cPEJnDO\n bD43cSIISam4Ut7NjRYDn6C1OT06oCj06v", "X-Received": "by 2002:a17:907:7b9c:b0:b98:47a3:b41 with SMTP id\n a640c23a62f3a-b9a5420da89mr524600266b.29.1774512884767;\n Thu, 26 Mar 2026 01:14:44 -0700 (PDT)", "To": "buildroot@buildroot.org", "Date": "Thu, 26 Mar 2026 09:14:22 +0100", "Message-ID": "<20260326081422.945900-3-titouan.christophe@mind.be>", "X-Mailer": "git-send-email 2.53.0", "In-Reply-To": "<20260326081422.945900-1-titouan.christophe@mind.be>", "References": "<20260326081422.945900-1-titouan.christophe@mind.be>", "MIME-Version": "1.0", "X-Mailman-Original-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=mind.be; s=google; t=1774512885; x=1775117685; darn=buildroot.org;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:from:to:cc:subject:date\n :message-id:reply-to;\n bh=p0imTyOiaR2D+T0jbNOxxRCRJ20RGrp8kTuvYuZFQs4=;\n b=N76+W0abOL33yG+3jQa+5FvYKcERdSyrc627/FA5zt8hABVblkE7Iy6zD4p6YZWL+w\n mPaWJTyZT1uR0lXaMeC4broawQxCP2dg1BHoDzfAPz5Vld3GdCgZ5vTdN2xpZuhAI3/+\n WPB41KyOBNTsqD+opTERjGon24eNH+S5KHq4Q+8uUrQCV1Gc0Pp7Ttmr1HkB4YLTjAMw\n ZO4oOyoRYnyu/ftBvX2CU31zRqf4LW8ed/9YT4cddnL3AKXzJN4akVCc0dDdkI6MwBKC\n 48j4fa6mo2DG8YPqOPwnHMBSfhjPC/wkrys/aiUFup/+Oc4yEYodlFE1hS+e4PbLUe3g\n uBZA==", "X-Mailman-Original-Authentication-Results": [ "smtp4.osuosl.org;\n dmarc=pass (p=quarantine dis=none)\n header.from=mind.be", "smtp4.osuosl.org;\n dkim=pass (2048-bit key) header.d=mind.be header.i=@mind.be\n header.a=rsa-sha256 header.s=google header.b=N76+W0ab" ], "Subject": "[Buildroot] [PATCH v2 2/2] SECURITY.md: add new file", "X-BeenThere": "buildroot@buildroot.org", "X-Mailman-Version": "2.1.30", "Precedence": "list", "List-Id": "Discussion and development of buildroot <buildroot.buildroot.org>", "List-Unsubscribe": "<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>", "List-Archive": "<http://lists.buildroot.org/pipermail/buildroot/>", "List-Post": "<mailto:buildroot@buildroot.org>", "List-Help": "<mailto:buildroot-request@buildroot.org?subject=help>", "List-Subscribe": "<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>", "From": "Titouan Christophe via buildroot <buildroot@buildroot.org>", "Reply-To": "Titouan Christophe <titouan.christophe@mind.be>", "Cc": "Julien Olivain <ju.o@free.fr>,\n Thomas Petazzoni <thomas.petazzoni@bootlin.com>,\n Romain Naour <romain.naour@gmail.com>, Thomas Perale <thomas.perale@mind.be>,\n Marcus Hoffmann <bubu@bubu1.eu>", "Content-Type": "text/plain; charset=\"us-ascii\"", "Content-Transfer-Encoding": "7bit", "Errors-To": "buildroot-bounces@buildroot.org", "Sender": "\"buildroot\" <buildroot-bounces@buildroot.org>" }, "content": "This is an in-tree description of Buildroot's security policies\n\nSigned-off-by: Titouan Christophe <titouan.christophe@mind.be>\n---\nChanges v1->v2:\n- Add references to the Buildroot User Manual for vulnerability tracking\n- Add links to autobuilder pkg-stats and Buildroot security website\n- Link to CPE info for Buildroot\n- Explicitely say that security@buildroot.org is a private ML\n---\n SECURITY.md | 36 ++++++++++++++++++++++++++++++++++++\n 1 file changed, 36 insertions(+)\n create mode 100644 SECURITY.md", "diff": "diff --git a/SECURITY.md b/SECURITY.md\nnew file mode 100644\nindex 0000000000..6b21ffd2b9\n--- /dev/null\n+++ b/SECURITY.md\n@@ -0,0 +1,36 @@\n+# Security Policy\n+\n+## Security advisories\n+\n+Advisories for Buildroot security vulnerabilities are reported on the\n+developer's mailing list. A public archive can be consulted on\n+https://lists.buildroot.org/mailman/listinfo/buildroot\n+\n+Buildroot itself has a CPE to track its published vulnerabilities:\n+https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&keyword=buildroot\n+\n+The Buildroot project provides some ways for its users to track known\n+vulnerabilites in the packages included in the generated images, see:\n+- https://nightly.buildroot.org/manual.html#_details_about_packages\n+\n+In addition, detailed informations for all packages integrated with Buildroot\n+are updated daily on the following public web pages:\n+- https://security.buildroot.org/\n+- https://autobuild.buildroot.org/stats/\n+\n+## Reporting a Vulnerability\n+\n+To report a security vulnerability found in the Buildroot build system itself,\n+please send an email to [security@buildroot.org](mailto:security@buildroot.org).\n+\n+This is a private mailing list contacting the Buildroot maintainers only.\n+\n+## Vulnerabilities in packages\n+\n+Buildroot is a build system that cross-compiles packages from third-party\n+sources. The Buildroot developers are not responsible for security\n+vulnerabilities in these packages. Such vulnerabilities should be reported\n+directly to the upstream project that maintains the affected package.\n+\n+When vulnerabilities are fixed upstream, send a patch to update the affected\n+packages in Buildroot.\n", "prefixes": [ "v2", "2/2" ] }