* [OE-core][PATCH] python3: correct CVE_PRODUCT mapping
@ 2026-08-26 7:53 Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; only message in thread
From: Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 7:53 UTC (permalink / raw)
To: openembedded-core; +Cc: xe-linux-external
From: Devansh Patel <devanshp@cisco.com>
The current mapping qualifies the generic Python product but leaves cpython
vendor-wildcarded. python:python is the active NVD dictionary CPE and
configuration identity. Keep python_software_foundation:python for
historical NVD configurations.
Qualify OE-Core's retained CPython alias as python:cpython, the deprecated
NVD dictionary CPE spelling that now points to python:python.
Add python_software_foundation:cpython for authoritative Python CNA affected
data for the same CPython source. It has no dictionary record.
This changes the generated CPython identities to exact CPEs, but the frozen
sbom-cve-check database leaves the 188-entry CVE report unchanged, with no
current CVE delta.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
meta/recipes-devtools/python/python3_3.14.7.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-devtools/python/python3_3.14.7.bb b/meta/recipes-devtools/python/python3_3.14.7.bb
index 1eef256a83..5764359a02 100644
--- a/meta/recipes-devtools/python/python3_3.14.7.bb
+++ b/meta/recipes-devtools/python/python3_3.14.7.bb
@@ -36,7 +36,7 @@ UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P<pver>\d+(\.\d+)+).tar"
# maintenance branches.
inherit upstream-stable-release-point
-CVE_PRODUCT = "python:python python_software_foundation:python cpython"
+CVE_PRODUCT = "python:python python_software_foundation:python python:cpython python_software_foundation:cpython"
PYTHON_MAJMIN = "3.14"
--
2.35.6
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-26 7:54 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 7:53 [OE-core][PATCH] python3: correct CVE_PRODUCT mapping Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox