From 33cf9c3f95d7db91cc4f43dd75ac27ef89eb9db3 Mon Sep 17 00:00:00 2001 From: Rami Potinkara Date: Wed, 14 May 2025 21:40:52 +0300 Subject: [PATCH] Android: qtbase/src/android/jar.../QtView.java security sensitive This patch marks following files as security sensitive: executing-external-code -QtView.java - loading library in QtView(Context context, String appLibName) function parsing the external executable library name from external CMakeList.txt file. Fixes: QTBUG-136813 Task-number: QTBUG-135178 Pick-to: 6.8 Change-Id: I095f845459741312296f278d100dedb1bc9b3355 Reviewed-by: Rami Potinkara Reviewed-by: Assam Boudjelthia (cherry picked from commit d99a7ca3c1fbbd1cc927532acea4c639465fb29b) Reviewed-by: Qt Cherry-pick Bot --- src/android/jar/src/org/qtproject/qt/android/QtView.java | 1 + 1 file changed, 1 insertion(+) diff --git a/src/android/jar/src/org/qtproject/qt/android/QtView.java b/src/android/jar/src/org/qtproject/qt/android/QtView.java index 55878209fed..1a42937fcdc 100644 --- a/src/android/jar/src/org/qtproject/qt/android/QtView.java +++ b/src/android/jar/src/org/qtproject/qt/android/QtView.java @@ -1,5 +1,6 @@ // Copyright (C) 2024 The Qt Company Ltd. // SPDX-License-Identifier: LicenseRef-Qt-Commercial OR LGPL-3.0-only OR GPL-2.0-only OR GPL-3.0-only +// Qt-Security score:critical reason:executing-external-code package org.qtproject.qt.android;