-
Notifications
You must be signed in to change notification settings - Fork 11
Apply cve-2025-nov patch series #29
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
- Bump SBAT 'grub' entry to 6 - Set DPKG_VENDOR to Deepin, SB_EFI_VENDOR to deepin
Reviewer's guide (collapsed on small PRs)Reviewer's GuideApplies the November 2025 CVE patch set to grub, wires the new patches into the Debian packaging, and updates SBAT/packaging metadata for the Deepin vendor, including bumping the grub SBAT generation to 6. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
TAG Bot TAG: 2.12-7deepin7 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey there - I've reviewed your changes - here's some feedback:
- Since you’ve bumped the SBAT generation and added multiple
*.csv.invariants, double-check that the grub SBAT level and component names are kept consistent acrossdebian/sbat.debian.csv.in,sbat.deepin.csv.in, andsbat.uos.csv.into avoid mismatched revocations between vendors. - The introduction of
DPKG_VENDORandSB_EFI_VENDORfor Deepin builds indebian/rulesshould be guarded so it doesn’t affect non-Deepin derivatives; consider scoping or conditioning these variables so they only apply when building for that specific vendor.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- Since you’ve bumped the SBAT generation and added multiple `*.csv.in` variants, double-check that the grub SBAT level and component names are kept consistent across `debian/sbat.debian.csv.in`, `sbat.deepin.csv.in`, and `sbat.uos.csv.in` to avoid mismatched revocations between vendors.
- The introduction of `DPKG_VENDOR` and `SB_EFI_VENDOR` for Deepin builds in `debian/rules` should be guarded so it doesn’t affect non-Deepin derivatives; consider scoping or conditioning these variables so they only apply when building for that specific vendor.Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/integrate |
|
AutoIntegrationPr Bot |
Summary by Sourcery
Apply November 2025 CVE patch set to grub and update Debian packaging metadata accordingly.
Bug Fixes:
Enhancements:
Build: