python3-git: fix CVE_PRODUCT

Using the pypi.bbclass default CPE of python:GitPython detects no CVEs.
With CVE_PRODUCT = "gitpython_project:gitpython" we properly detect
9 CVEs, with 4 unpatched.

WARNING: python3-git-3.1.42-r0 do_cve_check:
Found unpatched CVEs: CVE-2026-42215, CVE-2026-42284,
CVE-2026-44243, CVE-2026-44244

Note: The original commit targeted python3-git_3.1.43.bb. This is
adjusted for Scarthgap, where the recipe version is 3.1.42.

(From OE-Core rev: 0c9e81e2b248c15054c8a847f043aea994b8adbe)

Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 3a6af75a33b4e007f0d3a247b6a149e32d51e510)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Tim Orling
2026-08-20 02:07:26 -07:00
committed by Richard Purdie
parent ba7e6744c6
commit b13a89f19d

View File

@@ -10,6 +10,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e"
PYPI_PACKAGE = "GitPython"
CVE_PRODUCT = "gitpython_project:gitpython"
inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \