mirror of
https://git.yoctoproject.org/poky
synced 2026-09-20 21:49:33 +02:00
No new CVEs are caught, but attrs_project:attrs matches the upstream NVD dictionary CPE. The pypi.bbclass default "python:attrs" generates the wrong product identity for the packaged attrs source. This changes the generated product identity, but the Scarthgap cve-check database snapshot has no current CVE report delta. Note: The original commit targeted python3-attrs_26.1.0.bb. This is adjusted for Scarthgap, where the recipe version is 23.2.0. AI-Generated: Claude Sonnet 5 (From OE-Core rev: dbed62df037003f1200003c6d7a590574b8f6d33) Signed-off-by: Tim Orling <tim.orling@konsulko.com> Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit bc07eddb82fe42ecf86e685450ec0b5c9d3a9ce1) Signed-off-by: Devansh Patel <devanshp@cisco.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>