Skip to content

utils/beep: assign PKG_CPE_ID#28880

Open
ffontaine wants to merge 1 commit intoopenwrt:masterfrom
ffontaine:add-beep-cpe
Open

utils/beep: assign PKG_CPE_ID#28880
ffontaine wants to merge 1 commit intoopenwrt:masterfrom
ffontaine:add-beep-cpe

Conversation

@ffontaine
Copy link
Contributor

cpe:/a:beep_project:beep is the correct CPE ID for beep: https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:beep_project:beep

Maintainer: @riptidewave93

@feckert
Copy link
Member

feckert commented Mar 18, 2026

@ffontaine
Copy link
Contributor Author

spkr-beep is indeed a fork of https://github.com/johnath/beep as clearly stated in README.md:

This version of beep has been forked from Johnathan Nightingales' original beep when johnath/beep#11 required fixes in 2018, while Johnathan Nightingales' github.com/johnath/beep/ and johnath.com/beep/ was only maintained from around 2000 until around 2013.

The spkr-beep fixes two CVEs from the original beep (which is essentially no longer maintained). I believe it is still appropriate to use the beep_project:beep CPE ID since the code base remains the same and no new CPE has been assigned to the fork (as there have been no new CVEs since 2018).

@feckert
Copy link
Member

feckert commented Mar 18, 2026

Then we should mention this in the commit message. So you know why we don't use the original referenced in the CPE ID

@ffontaine
Copy link
Contributor Author

OK, I'll update the PR

cpe:/a:beep_project:beep is the correct CPE ID for beep:
https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:beep_project:beep

Indeed, spkr-beep is a fork of https://github.com/johnath/beep as
clearly stated in README.md: "This version of beep has been forked from
Johnathan Nightingales' original beep when johnath/beep#11 required
fixes in 2018, while Johnathan Nightingales' github.com/johnath/beep/
and johnath.com/beep/ was only maintained from around 2000 until around
2013.

So, it is still appropriate to use beep_project:beep CPE ID since the
code base remains the same and no new CPE has been assigned to the fork
(as there have been no new CVEs since 2018).

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants