* [OE-core][wrynose][PATCH] python3-numpy: fix CVE_PRODUCT
@ 2026-08-20 9:07 Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; only message in thread
From: Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-20 9:07 UTC (permalink / raw)
To: openembedded-core; +Cc: xe-linux-external
From: Tim Orling <tim.orling@konsulko.com>
The current "python3-numpy" mapping has no matching NVD CPE or
configuration identity, so eight source-aligned CVE records are missed.
Use "numpy:numpy", the active NVD dictionary CPE and configuration
identity for the packaged NumPy source.
Note: The original commit targeted python3-numpy_2.5.2.bb. This is
adjusted for Wrynose, where the recipe version is 2.4.3.
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit ad623e71fadeddcb0b70bba8fbf28c75a976e596)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
meta/recipes-devtools/python/python3-numpy_2.4.3.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-numpy_2.4.3.bb b/meta/recipes-devtools/python/python3-numpy_2.4.3.bb
index 7521a93f99..f34723b2c2 100644
--- a/meta/recipes-devtools/python/python3-numpy_2.4.3.bb
+++ b/meta/recipes-devtools/python/python3-numpy_2.4.3.bb
@@ -18,6 +18,8 @@ SRC_URI[sha256sum] = "483a201202b73495f00dbc83796c6ae63137a9bdade074f7648b3e3261
GITHUB_BASE_URI = "https://github.com/numpy/numpy/releases"
UPSTREAM_CHECK_REGEX = "releases/tag/v?(?P<pver>\d+(\.\d+)+)$"
+CVE_PRODUCT = "numpy:numpy"
+
inherit pkgconfig ptest python_mesonpy github-releases cython
S = "${UNPACKDIR}/numpy-${PV}"
--
2.35.6
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-20 9:08 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-20 9:07 [OE-core][wrynose][PATCH] python3-numpy: fix CVE_PRODUCT Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.