Openembedded Devel Discussions
 help / color / mirror / Atom feed
* [meta-python][PATCH] python3-web3: add CVE_PRODUCT mapping
@ 2026-08-20  9:37 Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 0 replies; only message in thread
From: Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-20  9:37 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external

From: Devansh Patel <devanshp@cisco.com>

The current inherited "python:web3" mapping does not match the web3.py identities used by NVD and CVE List V5, so its source-aligned CVE is missed.

Use "ethereum:web3.py" for the CNA affected-data identity and "apeworx:web3.py" for the NVD dictionary CPE and configuration identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
 meta-python/recipes-devtools/python/python3-web3_7.16.0.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta-python/recipes-devtools/python/python3-web3_7.16.0.bb b/meta-python/recipes-devtools/python/python3-web3_7.16.0.bb
index bb1c354934..88e224f834 100644
--- a/meta-python/recipes-devtools/python/python3-web3_7.16.0.bb
+++ b/meta-python/recipes-devtools/python/python3-web3_7.16.0.bb
@@ -6,6 +6,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=1d34d9701a1461e4bd71a904ac4cf7be"
 
 SRC_URI[sha256sum] = "b4a75a3fa94fef4d23d502eb3c2244146ef9a1ee0082cf1cb0a91586ba0510c3"
 
+CVE_PRODUCT = "ethereum:web3.py apeworx:web3.py"
+
 inherit pypi setuptools3
 
 RDEPENDS:${PN} += " \
-- 
2.35.6


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-20  9:37 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-20  9:37 [meta-python][PATCH] python3-web3: add CVE_PRODUCT mapping Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox