The pypi class default python:idna matches nothing in the CVE
databases, which track the Python idna CVEs as:
* CVE-2024-3651 (kjd:internationalized_domain_names_in_applications) [1]
* CVE-2026-45409 (kjd:idna in the CNA record, same NVD CPE as above)
Set both vendor:product pairs. Both CVEs are fixed before 3.18, so
they resolve as not affected.
The bare product name is not an option here: it would also match
"servo:idna", the Rust idna crate (e.g. CVE-2024-12224).
[1] https://nvd.nist.gov/vuln/detail/CVE-2024-3651
Signed-off-by: mark.yang <mark.yang@lge.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
RDEPENDS:${PN} += "python3-codecs"
RDEPENDS:${PN}-ptest += "python3-unittest-automake-output"
+CVE_PRODUCT = "kjd:idna kjd:internationalized_domain_names_in_applications"
+
BBCLASSEXTEND = "native nativesdk"