]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commitdiff
python3-pip: set CVE_PRODUCT
authorHimanshu Jadon <hjadon@cisco.com>
Thu, 23 Jul 2026 12:54:17 +0000 (05:54 -0700)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 27 Jul 2026 16:32:11 +0000 (17:32 +0100)
CVE_PRODUCT is not set for python3-pip, so cve-check can miss or
misreport pip CVEs. CVE-2026-8643 is reported in NVD with pypa:pip.

Add CVE_PRODUCT to match the NVD product name and report this CVE
correctly.

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-devtools/python/python3-pip_26.1.2.bb

index 9a024092980ae180ae0e277f032e27dd9fb87e9c..945aad18340ac24f68985557c760a15a0a369750 100644 (file)
@@ -28,6 +28,8 @@ SRC_URI += "file://no_shebang_mangling.patch"
 
 SRC_URI[sha256sum] = "f49cd134c61cf2fd75e0ce2676db03e4054504a5a4986d00f8299ae632dc4605"
 
+CVE_PRODUCT = "pypa:pip"
+
 do_install:append(){
        # pip vendors distlib which ships Windows launcher templates (*.exe).
        # Keep them only when building for a Windows (mingw) host.