Conversation
|
That is not correct. We pull the changes from https://github.com/spkr-beep/beep |
|
spkr-beep is indeed a fork of https://github.com/johnath/beep as clearly stated in README.md:
The spkr-beep fixes two CVEs from the original beep (which is essentially no longer maintained). I believe it is still appropriate to use the |
|
Then we should mention this in the commit message. So you know why we don't use the original referenced in the CPE ID |
|
OK, I'll update the PR |
cpe:/a:beep_project:beep is the correct CPE ID for beep: https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:beep_project:beep Indeed, spkr-beep is a fork of https://github.com/johnath/beep as clearly stated in README.md: "This version of beep has been forked from Johnathan Nightingales' original beep when johnath/beep#11 required fixes in 2018, while Johnathan Nightingales' github.com/johnath/beep/ and johnath.com/beep/ was only maintained from around 2000 until around 2013. So, it is still appropriate to use beep_project:beep CPE ID since the code base remains the same and no new CPE has been assigned to the fork (as there have been no new CVEs since 2018). Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
cpe:/a:beep_project:beep is the correct CPE ID for beep: https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:beep_project:beep
Maintainer: @riptidewave93