Openembedded Core Discussions
 help / color / mirror / Atom feed
* [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT
@ 2026-09-02  6:09 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-09-02  6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-09-02  6:09 ` [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 2 replies; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-02  6:09 UTC (permalink / raw)
  To: openembedded-core; +Cc: Gyorgy Sarvari, Khem Raj, Darsh Kelaiya

From: Gyorgy Sarvari <skandigraun@gmail.com>

The related CVEs are tracked using pytest:py CPE, so set the CVE_PRODUCT
accordingly instead of the default python:py.

See CVE db query:
sqlite> select * from products where product like 'py';
CVE-2020-29651|pytest|py|||1.9.0|<=
CVE-2022-42969|pytest|py|||1.11.0|<=

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 1fac509459c4e2d970121b66ae33cd53ef1eb8a6)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
 meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
index 31d5a377a7..a75b9c2b14 100644
--- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
+++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
@@ -5,6 +5,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
 
 SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
 
+CVE_PRODUCT = "py"
+
 DEPENDS += "python3-setuptools-scm-native"
 
 inherit pypi python_setuptools_build_meta
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping
  2026-09-02  6:09 [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-02  6:09 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-09-11  8:07   ` Yoann Congal
  2026-09-02  6:09 ` [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  1 sibling, 1 reply; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-02  6:09 UTC (permalink / raw)
  To: openembedded-core; +Cc: Devansh Patel, Khem Raj, Darsh Kelaiya

From: Devansh Patel <devanshp@cisco.com>

The product-only "py" mapping generates a wildcard-vendor identity
instead of the exact NVD identity for the packaged pytest-dev py
source. Use "pytest:py" for its NVD dictionary CPE and configuration
matches.

This changes the generated product identity. With sbom-cve-check 1.3.3,
the current CVE report is unchanged using the pinned database snapshots;
both mappings report CVE-2020-29651 and CVE-2022-42969.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 26fa8b053b71d1f3f8da359abaef578c671c692f)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
 meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
index a75b9c2b14..906410e9bb 100644
--- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
+++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
@@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
 
 SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
 
-CVE_PRODUCT = "py"
+CVE_PRODUCT = "pytest:py"
 
 DEPENDS += "python3-setuptools-scm-native"
 
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969
  2026-09-02  6:09 [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-09-02  6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-02  6:09 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  1 sibling, 0 replies; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-02  6:09 UTC (permalink / raw)
  To: openembedded-core; +Cc: Darsh Kelaiya

From: Darsh Kelaiya <dkelaiya@cisco.com>

Analysis:
- NVD marks CVE-2022-42969 as disputed because multiple parties could
  not reproduce it and argue that it is not a valid vulnerability [1].
- GitHub withdrew the advisory because the available evidence does not
  show a valid, reproducible vulnerability [2].
- Wrynose and master use the same python3-py version and carry the same
  disputed CVE status, so that disposition applies to Scarthgap [3].
- Hence ignoring the CVE for now.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
[2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
[3] https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
 meta/recipes-devtools/python/python3-py_1.11.0.bb | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
index 906410e9bb..f850be1163 100644
--- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
+++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
@@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
 SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
 
 CVE_PRODUCT = "pytest:py"
+CVE_STATUS[CVE-2022-42969] = "disputed: upstream could not reproduce it and GitHub withdrew the advisory"
 
 DEPENDS += "python3-setuptools-scm-native"
 
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping
  2026-09-02  6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-11  8:07   ` Yoann Congal
  2026-09-11  9:32     ` [scarthgap][PATCH " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 1 reply; 5+ messages in thread
From: Yoann Congal @ 2026-09-11  8:07 UTC (permalink / raw)
  To: dkelaiya, openembedded-core; +Cc: Devansh Patel, Khem Raj

On Wed Sep 2, 2026 at 8:09 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Devansh Patel <devanshp@cisco.com>
>
> The product-only "py" mapping generates a wildcard-vendor identity
> instead of the exact NVD identity for the packaged pytest-dev py
> source. Use "pytest:py" for its NVD dictionary CPE and configuration
> matches.
>
> This changes the generated product identity. With sbom-cve-check 1.3.3,
> the current CVE report is unchanged using the pinned database snapshots;
> both mappings report CVE-2020-29651 and CVE-2022-42969.
>
> Signed-off-by: Devansh Patel <devanshp@cisco.com>
> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
> (cherry picked from commit 26fa8b053b71d1f3f8da359abaef578c671c692f)
> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
> ---
>  meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
> index a75b9c2b14..906410e9bb 100644
> --- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
> +++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
> @@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
>  
>  SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
>  
> -CVE_PRODUCT = "py"
> +CVE_PRODUCT = "pytest:py"
>  
>  DEPENDS += "python3-setuptools-scm-native"
>  

Hello,

As far as I can tell, this is also needed on meta-oe/wrynose. Can you
send a backport there, please?

Since patches 2&3/3 conflicts, I'll hold both until "python3-py: correct
CVE_PRODUCT mapping" lands on meta-oe/wrynose.

Baring future issues, I'll take 1/3.

Thanks!
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping
  2026-09-11  8:07   ` Yoann Congal
@ 2026-09-11  9:32     ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 0 replies; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-11  9:32 UTC (permalink / raw)
  To: openembedded-core

[-- Attachment #1: Type: text/plain, Size: 2249 bytes --]

On Fri, Sep 11, 2026 at 01:37 PM, Yoann Congal wrote:

> 
> On Wed Sep 2, 2026 at 8:09 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> 
>> From: Devansh Patel <devanshp@cisco.com>
>> 
>> The product-only "py" mapping generates a wildcard-vendor identity
>> instead of the exact NVD identity for the packaged pytest-dev py
>> source. Use "pytest:py" for its NVD dictionary CPE and configuration
>> matches.
>> 
>> This changes the generated product identity. With sbom-cve-check 1.3.3,
>> the current CVE report is unchanged using the pinned database snapshots;
>> both mappings report CVE-2020-29651 and CVE-2022-42969.
>> 
>> Signed-off-by: Devansh Patel <devanshp@cisco.com>
>> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
>> (cherry picked from commit 26fa8b053b71d1f3f8da359abaef578c671c692f)
>> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> ---
>> meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 +-
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>> 
>> diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> b/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> index a75b9c2b14..906410e9bb 100644
>> --- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> +++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> @@ -5,7 +5,7 @@ LIC_FILES_CHKSUM =
>> "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
>> 
>> SRC_URI[sha256sum] =
>> "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
>> 
>> -CVE_PRODUCT = "py"
>> +CVE_PRODUCT = "pytest:py"
>> 
>> DEPENDS += "python3-setuptools-scm-native"
> 
> Hello,
> 
> As far as I can tell, this is also needed on meta-oe/wrynose. Can you
> send a backport there, please?
> 
> Since patches 2&3/3 conflicts, I'll hold both until "python3-py: correct
> CVE_PRODUCT mapping" lands on meta-oe/wrynose.
> 
> Baring future issues, I'll take 1/3.
> 
> Thanks!
> --
> Yoann Congal
> Smile ECS

Hello Yoann,

Thanks for highlighting this. I've sent the requested "python3-py: correct CVE_PRODUCT mapping" as shown here for Wrynose:

https://lists.openembedded.org/g/openembedded-devel/message/129959

Regards,
Darsh Kelaiya

[-- Attachment #2: Type: text/html, Size: 2516 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-11  9:33 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02  6:09 [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02  6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-11  8:07   ` Yoann Congal
2026-09-11  9:32     ` [scarthgap][PATCH " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02  6:09 ` [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox