mirror of
https://git.yoctoproject.org/poky
synced 2026-09-11 21:49:33 +02:00
python3-pip: set CVE_PRODUCT
CVE_PRODUCT is not set for python3-pip, so cve-check can miss or misreport pip CVEs. CVE-2026-8643 is reported in NVD with pypa:pip. Add CVE_PRODUCT to match the NVD product name and report this CVE correctly. (From OE-Core rev: 3a24c9f77622148c3894c9228e061cabf79f169f) Signed-off-by: Himanshu Jadon <hjadon@cisco.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit a486abd4889ad03e1a8ddd5311595f3ece7d61b6) Signed-off-by: Himanshu Jadon <hjadon@cisco.com> Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
committed by
Paul Barker
parent
44913c2842
commit
604781030b
@@ -41,6 +41,8 @@ do_install:append() {
|
||||
rm -f ${D}/${bindir}/pip
|
||||
}
|
||||
|
||||
CVE_PRODUCT = "pypa:pip"
|
||||
|
||||
do_install:append(){
|
||||
# pip vendors distlib which ships Windows launcher templates (*.exe).
|
||||
# Keep them only when building for a Windows (mingw) host.
|
||||
|
||||
Reference in New Issue
Block a user