python3-pip: set CVE_PRODUCT

CVE_PRODUCT is not set for python3-pip, so cve-check can miss or
misreport pip CVEs. CVE-2026-8643 is reported in NVD with pypa:pip.

Add CVE_PRODUCT to match the NVD product name and report this CVE
correctly.

(From OE-Core rev: 3a24c9f77622148c3894c9228e061cabf79f169f)

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit a486abd4889ad03e1a8ddd5311595f3ece7d61b6)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
Himanshu Jadon
2026-08-03 00:07:16 -07:00
committed by Paul Barker
parent 44913c2842
commit 604781030b

View File

@@ -41,6 +41,8 @@ do_install:append() {
rm -f ${D}/${bindir}/pip
}
CVE_PRODUCT = "pypa:pip"
do_install:append(){
# pip vendors distlib which ships Windows launcher templates (*.exe).
# Keep them only when building for a Windows (mingw) host.