mirror of
https://git.yoctoproject.org/poky
synced 2026-09-22 00:49:35 +02:00
python3-git: fix CVE-2026-42284
This patch applies the upstream 3.1.47 backport for
CVE-2026-42284. The upstream fix merge is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] da545232d0
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284
(From OE-Core rev: 1582c80d83558b9f1e9c3137bd79ec3f0a5c643c)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224:
The author links the fix to this advisory/CVE.
]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
ab57645a22
commit
1e39c2a5e3
@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
|
||||
|
||||
inherit pypi python_setuptools_build_meta
|
||||
|
||||
SRC_URI += "file://CVE-2026-42284.patch \
|
||||
"
|
||||
SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"
|
||||
|
||||
DEPENDS += " python3-gitdb"
|
||||
|
||||
Reference in New Issue
Block a user