All of lore.kernel.org
 help / color / mirror / Atom feed
* [OE-core][wrynose][PATCH] python3-attrs: fix CVE_PRODUCT
@ 2026-08-20  9:07 Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 0 replies; only message in thread
From: Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-20  9:07 UTC (permalink / raw)
  To: openembedded-core; +Cc: xe-linux-external

From: Tim Orling <tim.orling@konsulko.com>

No new CVEs are caught, but attrs_project:attrs matches the upstream
NVD dictionary CPE. The pypi.bbclass default "python:attrs" generates
the wrong product identity for the packaged attrs source.

This changes the generated product identity, but the Wrynose
sbom-cve-check database snapshot has no current CVE report delta.

Note: The original commit targeted python3-attrs_26.1.0.bb. This is
adjusted for Wrynose, where the recipe version is 25.4.0.

AI-Generated: Claude Sonnet 5
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit bc07eddb82fe42ecf86e685450ec0b5c9d3a9ce1)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
 meta/recipes-devtools/python/python3-attrs_25.4.0.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-devtools/python/python3-attrs_25.4.0.bb b/meta/recipes-devtools/python/python3-attrs_25.4.0.bb
index 7bc581b875..c3f5a155ca 100644
--- a/meta/recipes-devtools/python/python3-attrs_25.4.0.bb
+++ b/meta/recipes-devtools/python/python3-attrs_25.4.0.bb
@@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "16d5969b87f0859ef33a48b35d55ac1be6e42ae49d5e853b597db70c35
 
 inherit pypi ptest-python-pytest python_hatchling
 
+CVE_PRODUCT = "attrs_project:attrs"
+
 DEPENDS += " \
     python3-hatch-vcs-native \
     python3-hatch-fancy-pypi-readme-native \
-- 
2.35.6


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-20  9:08 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-20  9:07 [OE-core][wrynose][PATCH] python3-attrs: fix CVE_PRODUCT Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.