* [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT
@ 2026-09-02 6:09 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02 6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02 6:09 ` [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 2 replies; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-02 6:09 UTC (permalink / raw)
To: openembedded-core; +Cc: Gyorgy Sarvari, Khem Raj, Darsh Kelaiya
From: Gyorgy Sarvari <skandigraun@gmail.com>
The related CVEs are tracked using pytest:py CPE, so set the CVE_PRODUCT
accordingly instead of the default python:py.
See CVE db query:
sqlite> select * from products where product like 'py';
CVE-2020-29651|pytest|py|||1.9.0|<=
CVE-2022-42969|pytest|py|||1.11.0|<=
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 1fac509459c4e2d970121b66ae33cd53ef1eb8a6)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
index 31d5a377a7..a75b9c2b14 100644
--- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
+++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
@@ -5,6 +5,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
+CVE_PRODUCT = "py"
+
DEPENDS += "python3-setuptools-scm-native"
inherit pypi python_setuptools_build_meta
--
2.35.6
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping
2026-09-02 6:09 [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-02 6:09 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-11 8:07 ` Yoann Congal
2026-09-02 6:09 ` [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
1 sibling, 1 reply; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-02 6:09 UTC (permalink / raw)
To: openembedded-core; +Cc: Devansh Patel, Khem Raj, Darsh Kelaiya
From: Devansh Patel <devanshp@cisco.com>
The product-only "py" mapping generates a wildcard-vendor identity
instead of the exact NVD identity for the packaged pytest-dev py
source. Use "pytest:py" for its NVD dictionary CPE and configuration
matches.
This changes the generated product identity. With sbom-cve-check 1.3.3,
the current CVE report is unchanged using the pinned database snapshots;
both mappings report CVE-2020-29651 and CVE-2022-42969.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 26fa8b053b71d1f3f8da359abaef578c671c692f)
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
index a75b9c2b14..906410e9bb 100644
--- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
+++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
@@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
-CVE_PRODUCT = "py"
+CVE_PRODUCT = "pytest:py"
DEPENDS += "python3-setuptools-scm-native"
--
2.35.6
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969
2026-09-02 6:09 [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02 6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-02 6:09 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
1 sibling, 0 replies; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-02 6:09 UTC (permalink / raw)
To: openembedded-core; +Cc: Darsh Kelaiya
From: Darsh Kelaiya <dkelaiya@cisco.com>
Analysis:
- NVD marks CVE-2022-42969 as disputed because multiple parties could
not reproduce it and argue that it is not a valid vulnerability [1].
- GitHub withdrew the advisory because the available evidence does not
show a valid, reproducible vulnerability [2].
- Wrynose and master use the same python3-py version and carry the same
disputed CVE status, so that disposition applies to Scarthgap [3].
- Hence ignoring the CVE for now.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2022-42969
[2] https://github.com/advisories/GHSA-w596-4wvx-j9j6
[3] https://git.openembedded.org/meta-openembedded/commit/?id=91f6b85b36316d5940ee194b1d195caf3ac040b1
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
meta/recipes-devtools/python/python3-py_1.11.0.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
index 906410e9bb..f850be1163 100644
--- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
+++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
@@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
CVE_PRODUCT = "pytest:py"
+CVE_STATUS[CVE-2022-42969] = "disputed: upstream could not reproduce it and GitHub withdrew the advisory"
DEPENDS += "python3-setuptools-scm-native"
--
2.35.6
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping
2026-09-02 6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-09-11 8:07 ` Yoann Congal
2026-09-11 9:32 ` [scarthgap][PATCH " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 1 reply; 5+ messages in thread
From: Yoann Congal @ 2026-09-11 8:07 UTC (permalink / raw)
To: dkelaiya, openembedded-core; +Cc: Devansh Patel, Khem Raj
On Wed Sep 2, 2026 at 8:09 AM CEST, Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Devansh Patel <devanshp@cisco.com>
>
> The product-only "py" mapping generates a wildcard-vendor identity
> instead of the exact NVD identity for the packaged pytest-dev py
> source. Use "pytest:py" for its NVD dictionary CPE and configuration
> matches.
>
> This changes the generated product identity. With sbom-cve-check 1.3.3,
> the current CVE report is unchanged using the pinned database snapshots;
> both mappings report CVE-2020-29651 and CVE-2022-42969.
>
> Signed-off-by: Devansh Patel <devanshp@cisco.com>
> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
> (cherry picked from commit 26fa8b053b71d1f3f8da359abaef578c671c692f)
> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
> ---
> meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb
> index a75b9c2b14..906410e9bb 100644
> --- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
> +++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
> @@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
>
> SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
>
> -CVE_PRODUCT = "py"
> +CVE_PRODUCT = "pytest:py"
>
> DEPENDS += "python3-setuptools-scm-native"
>
Hello,
As far as I can tell, this is also needed on meta-oe/wrynose. Can you
send a backport there, please?
Since patches 2&3/3 conflicts, I'll hold both until "python3-py: correct
CVE_PRODUCT mapping" lands on meta-oe/wrynose.
Baring future issues, I'll take 1/3.
Thanks!
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping
2026-09-11 8:07 ` Yoann Congal
@ 2026-09-11 9:32 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; 5+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-09-11 9:32 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 2249 bytes --]
On Fri, Sep 11, 2026 at 01:37 PM, Yoann Congal wrote:
>
> On Wed Sep 2, 2026 at 8:09 AM CEST, Darsh Kelaiya -X (dkelaiya - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
>
>> From: Devansh Patel <devanshp@cisco.com>
>>
>> The product-only "py" mapping generates a wildcard-vendor identity
>> instead of the exact NVD identity for the packaged pytest-dev py
>> source. Use "pytest:py" for its NVD dictionary CPE and configuration
>> matches.
>>
>> This changes the generated product identity. With sbom-cve-check 1.3.3,
>> the current CVE report is unchanged using the pinned database snapshots;
>> both mappings report CVE-2020-29651 and CVE-2022-42969.
>>
>> Signed-off-by: Devansh Patel <devanshp@cisco.com>
>> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
>> (cherry picked from commit 26fa8b053b71d1f3f8da359abaef578c671c692f)
>> Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
>> ---
>> meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 +-
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> b/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> index a75b9c2b14..906410e9bb 100644
>> --- a/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> +++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb
>> @@ -5,7 +5,7 @@ LIC_FILES_CHKSUM =
>> "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
>>
>> SRC_URI[sha256sum] =
>> "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
>>
>> -CVE_PRODUCT = "py"
>> +CVE_PRODUCT = "pytest:py"
>>
>> DEPENDS += "python3-setuptools-scm-native"
>
> Hello,
>
> As far as I can tell, this is also needed on meta-oe/wrynose. Can you
> send a backport there, please?
>
> Since patches 2&3/3 conflicts, I'll hold both until "python3-py: correct
> CVE_PRODUCT mapping" lands on meta-oe/wrynose.
>
> Baring future issues, I'll take 1/3.
>
> Thanks!
> --
> Yoann Congal
> Smile ECS
Hello Yoann,
Thanks for highlighting this. I've sent the requested "python3-py: correct CVE_PRODUCT mapping" as shown here for Wrynose:
https://lists.openembedded.org/g/openembedded-devel/message/129959
Regards,
Darsh Kelaiya
[-- Attachment #2: Type: text/html, Size: 2516 bytes --]
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-11 9:33 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 6:09 [OE-core][scarthgap][PATCH v2 1/3] python3-py: set CVE_PRODUCT Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02 6:09 ` [OE-core][scarthgap][PATCH v2 2/3] python3-py: correct CVE_PRODUCT mapping Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-11 8:07 ` Yoann Congal
2026-09-11 9:32 ` [scarthgap][PATCH " Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-09-02 6:09 ` [OE-core][scarthgap][PATCH v2 3/3] python3-py: ignore CVE-2022-42969 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox