Files
poky/meta
Hetvi Thakar b24d56a0b3 python3-pip: Fix CVE-2026-8643
Apply the primary upstream fix referenced in [4] with commit [1]. Then
apply the two follow-up regression-fix commits [2] and [3].

The primary fix rejects entry-point names that escape the configured
scripts directory. The follow-up fixes handle doubled-slash roots and
reuse the existing directory-containment helper.

[1] 8eb178480b
[2] 7ff8bdd81e
[3] fa7854f6b3
[4] https://github.com/advisories/GHSA-wf93-45jw-7689

(From OE-Core rev: 2c276677d619bc6205872eb2b5a9948a4605d8ea)

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-09-21 08:53:17 +01:00
..
2026-07-02 13:42:26 +01:00
2026-08-24 11:43:45 +01:00
2026-09-04 10:39:10 +01:00
2023-09-02 07:45:29 +01:00
2019-08-29 14:05:12 +01:00