From 6e376f5f1a04fb9a2cdd00b691dd9b031e0c5494 Mon Sep 17 00:00:00 2001 From: Tim Orling Date: Thu, 20 Aug 2026 02:07:26 -0700 Subject: [PATCH] python3-numpy: fix CVE_PRODUCT Without this change, 0 CVEs are reported. With this change, 8 Patched CVEs are reported: * CVE-2014-1858 * CVE-2014-1859 * CVE-2017-12852 * CVE-2019-6446 * CVE-2021-33430 * CVE-2021-34141 * CVE-2021-41495 * CVE-2021-41496 This can be verified with a query like: $ cat .../core-image-ptest-python3-numpy-*.rootfs.sbom-cve-check.yocto.json \ | jq '.package[] | select(.name == "python3-numpy") \ | .issue[] | {id: .id, status: .status}' (From OE-Core rev: 5e73d32ea99d8e909bfb861a9f9c291c39497233) Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit ad623e71fadeddcb0b70bba8fbf28c75a976e596) The current "python3-numpy" mapping has no matching NVD CPE or configuration identity, so eight source-aligned CVE records are missed. Use "numpy:numpy", the active NVD dictionary CPE and configuration identity for the packaged NumPy source. Note: The original commit targeted python3-numpy_2.5.2.bb. This is adjusted for Scarthgap, where the recipe version is 1.26.4. Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal Signed-off-by: Richard Purdie --- meta/recipes-devtools/python/python3-numpy_1.26.4.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb index ccd08147af..9164874445 100644 --- a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb +++ b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb @@ -18,6 +18,8 @@ SRC_URI[sha256sum] = "2a02aba9ed12e4ac4eb3ea9421c420301a0c6460d9830d74a9df87efa4 GITHUB_BASE_URI = "https://github.com/numpy/numpy/releases" UPSTREAM_CHECK_REGEX = "releases/tag/v?(?P\d+(\.\d+)+)$" +CVE_PRODUCT = "numpy:numpy" + DEPENDS += "python3-cython-native" inherit ptest setuptools3 github-releases