Files
poky/meta/recipes-devtools/python/python3-git_3.1.42.bb
Darsh Kelaiya 1e39c2a5e3 python3-git: fix CVE-2026-42284
This patch applies the upstream 3.1.47 backport for
CVE-2026-42284. The upstream fix merge is referenced in [1],
and the public CVE advisory is referenced in [2].

[1] da545232d0
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284

(From OE-Core rev: 1582c80d83558b9f1e9c3137bd79ec3f0a5c643c)

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC:
See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224:
The author links the fix to this advisory/CVE.
]
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2026-09-11 14:32:08 +01:00

35 lines
1.1 KiB
BlitzBasic

SUMMARY = "Python library used to interact with Git repositories"
DESCRIPTION = "GitPython provides object model read and write access to \
a git repository. Access repository information conveniently, alter the \
index directly, handle remotes, or go down to low-level object database \
access with big-files support."
HOMEPAGE = "http://github.com/gitpython-developers/GitPython"
SECTION = "devel/python"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e"
PYPI_PACKAGE = "GitPython"
inherit pypi python_setuptools_build_meta
SRC_URI += "file://CVE-2026-42284.patch \
"
SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"
DEPENDS += " python3-gitdb"
RDEPENDS:${PN} += " \
python3-datetime \
python3-gitdb \
python3-io \
python3-logging \
python3-math \
python3-netclient \
python3-stringold \
python3-unittest \
python3-unixadmin \
git \
"
BBCLASSEXTEND = "native nativesdk"