python3-git: fix CVE-2026-42284

This patch applies the upstream 3.1.47 backport for
CVE-2026-42284. The upstream fix merge is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] da545232d0
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284

(From OE-Core rev: 1582c80d83558b9f1e9c3137bd79ec3f0a5c643c)

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224:
The author links the fix to this advisory/CVE.
]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Darsh Kelaiya
2026-08-19 10:10:22 -07:00
committed by Richard Purdie
parent ab57645a22
commit 1e39c2a5e3
2 changed files with 39 additions and 0 deletions

View File

@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \
"
SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"
DEPENDS += " python3-gitdb"