cve-update-db-native: use SQL placeholders instead of format strings

(From OE-Core rev: 91770338f76ef35f3c4eeac216eb9d2b3188e575)

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Ross Burton
2019-07-17 11:45:38 +01:00
committed by Richard Purdie
parent 7f5f884e55
commit c0017bee41

View File

@@ -62,7 +62,7 @@ python do_populate_cve_db() {
break
# Compare with current db last modified date
c.execute("select DATE from META where YEAR = '%d'" % year)
c.execute("select DATE from META where YEAR = ?", (year,))
meta = c.fetchone()
if not meta or meta[0] != last_modified:
# Update db with current year json file