From 604781030b6e34b7cd53a67267b33c9362c258d2 Mon Sep 17 00:00:00 2001 From: Himanshu Jadon Date: Mon, 3 Aug 2026 00:07:16 -0700 Subject: [PATCH] python3-pip: set CVE_PRODUCT CVE_PRODUCT is not set for python3-pip, so cve-check can miss or misreport pip CVEs. CVE-2026-8643 is reported in NVD with pypa:pip. Add CVE_PRODUCT to match the NVD product name and report this CVE correctly. (From OE-Core rev: 3a24c9f77622148c3894c9228e061cabf79f169f) Signed-off-by: Himanshu Jadon Signed-off-by: Richard Purdie (cherry picked from commit a486abd4889ad03e1a8ddd5311595f3ece7d61b6) Signed-off-by: Himanshu Jadon Signed-off-by: Fabien Thomas Signed-off-by: Paul Barker --- meta/recipes-devtools/python/python3-pip_24.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-pip_24.0.bb b/meta/recipes-devtools/python/python3-pip_24.0.bb index cf123a5d23..51fff41e25 100644 --- a/meta/recipes-devtools/python/python3-pip_24.0.bb +++ b/meta/recipes-devtools/python/python3-pip_24.0.bb @@ -41,6 +41,8 @@ do_install:append() { rm -f ${D}/${bindir}/pip } +CVE_PRODUCT = "pypa:pip" + do_install:append(){ # pip vendors distlib which ships Windows launcher templates (*.exe). # Keep them only when building for a Windows (mingw) host.