mirror of
https://git.yoctoproject.org/poky
synced 2026-09-12 06:49:32 +02:00
python3-attrs: fix CVE_PRODUCT
No new CVEs are caught, but attrs_project:attrs matches the upstream NVD dictionary CPE. The pypi.bbclass default "python:attrs" generates the wrong product identity for the packaged attrs source. This changes the generated product identity, but the Scarthgap cve-check database snapshot has no current CVE report delta. Note: The original commit targeted python3-attrs_26.1.0.bb. This is adjusted for Scarthgap, where the recipe version is 23.2.0. AI-Generated: Claude Sonnet 5 (From OE-Core rev: dbed62df037003f1200003c6d7a590574b8f6d33) Signed-off-by: Tim Orling <tim.orling@konsulko.com> Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit bc07eddb82fe42ecf86e685450ec0b5c9d3a9ce1) Signed-off-by: Devansh Patel <devanshp@cisco.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
26a34ca08b
commit
7a00748477
@@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "935dc3b529c262f6cf76e50877d35a4bd3c1de194fd41f47a2b7ae8f19
|
||||
|
||||
inherit pypi ptest python_hatchling
|
||||
|
||||
CVE_PRODUCT = "attrs_project:attrs"
|
||||
|
||||
SRC_URI += " \
|
||||
file://0001-test_funcs-skip-test_unknown-for-pytest-8.patch \
|
||||
file://0001-conftest.py-disable-deadline.patch \
|
||||
|
||||
Reference in New Issue
Block a user