mirror of
https://git.yoctoproject.org/poky
synced 2026-09-12 06:49:32 +02:00
python3-git: fix CVE_PRODUCT
Using the pypi.bbclass default CPE of python:GitPython detects no CVEs. With CVE_PRODUCT = "gitpython_project:gitpython" we properly detect 9 CVEs, with 4 unpatched. WARNING: python3-git-3.1.42-r0 do_cve_check: Found unpatched CVEs: CVE-2026-42215, CVE-2026-42284, CVE-2026-44243, CVE-2026-44244 Note: The original commit targeted python3-git_3.1.43.bb. This is adjusted for Scarthgap, where the recipe version is 3.1.42. (From OE-Core rev: 0c9e81e2b248c15054c8a847f043aea994b8adbe) Signed-off-by: Tim Orling <tim.orling@konsulko.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit 3a6af75a33b4e007f0d3a247b6a149e32d51e510) Signed-off-by: Devansh Patel <devanshp@cisco.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
ba7e6744c6
commit
b13a89f19d
@@ -10,6 +10,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e"
|
||||
|
||||
PYPI_PACKAGE = "GitPython"
|
||||
|
||||
CVE_PRODUCT = "gitpython_project:gitpython"
|
||||
|
||||
inherit pypi python_setuptools_build_meta
|
||||
|
||||
SRC_URI += "file://CVE-2026-42284.patch \
|
||||
|
||||
Reference in New Issue
Block a user