Re: CPE as a consistent element of pkg annotations

From: Dag-Erling_Smørgrav <des_at_FreeBSD.org>
Date: Mon, 12 May 2025 06:54:45 UTC
Dewayne Geraghty <dewayne@heuristicsystems.com.au> writes:
> Dag-Erling Smørgrav <des@FreeBSD.org> writes:
> > No, because we can't just make up CPEs.
> I suspect you're conflating CPE with a CVE.  The CPE is a construct
> defined in the /usr/ports/Mk/Uses/cpe.mk file.

Do me a favor and run `git log` on that file.  And then maybe check who
was Security Officer at the time it was added to the ports tree.

DES
-- 
Dag-Erling Smørgrav - des@FreeBSD.org