FW: [SECURITY] Missing vendor name in postgresql96 rpms

Поиск
Список
Период
Сортировка
От Ziyun Audrey Wang
Тема FW: [SECURITY] Missing vendor name in postgresql96 rpms
Дата
Msg-id DB5PR07MB0789241284D8FE8F598199D5E9370@DB5PR07MB0789.eurprd07.prod.outlook.com
обсуждение исходный текст
Ответы Re: FW: [SECURITY] Missing vendor name in postgresql96 rpms  (Devrim Gündüz <devrim@gunduz.org>)
Список pgsql-pkg-yum

Hello

 

We are using the following postgresql rpms, we download from https://yum.postgresql.org/9.6/redhat/rhel-6.6-x86_64/

 postgresql96-libs-9.6.6-1PGDG.rhel6.x86_64

postgresql96-server-9.6.6-1PGDG.rhel6.x86_64

postgresql96-9.6.6-1PGDG.rhel6.x86_64

postgresql96-contrib-9.6.6-1PGDG.rhel6.x86_64

The following rpms does not have any vendor name. It is needed for the SVL (Software Vendor List)

(none),postgresql96,9.6.6
(none),postgresql96-contrib,9.6.6
(none),postgresql96-libs,9.6.6
(none),postgresql96-server,9.6.6

rpm -qi postgresql96 
Name : postgresql96 Relocations: (not relocatable) 
Version : 9.6.6 Vendor: (none) 

 

Note that as part of our security process, it is needed to report all used 3PP in order to be informed automatically of any new vulnerability (CVE) . The database needs Vendor, Name and Version from the rpm as input and actually it is needed to add manually a Vendor for postgresql rpm before uploading the information otherwise the upload would failed. 

Thanks!

Best Regards

Audrey

В списке pgsql-pkg-yum по дате отправления:

Предыдущее
От: Pierre-Alain TORET
Дата:
Сообщение: Re: patch postgres user .bash_profile
Следующее
От: Devrim Gündüz
Дата:
Сообщение: Re: 9.3 RPMs not signed