Openembedded Devel Discussions
 help / color / mirror / Atom feed
* [meta-python][PATCH] python3-filelock: set CVE_PRODUCT
@ 2026-08-20 10:30 Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 0 replies; only message in thread
From: Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-20 10:30 UTC (permalink / raw)
  To: openembedded-devel; +Cc: xe-linux-external

From: Devansh Patel <devanshp@cisco.com>

The inherited python:filelock mapping does not identify the tox-dev source packaged by this recipe, so filelock CVEs are missed.

Use tox-dev:filelock to match the source identity used by NVD and CNA.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
 meta-python/recipes-devtools/python/python3-filelock_3.32.3.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta-python/recipes-devtools/python/python3-filelock_3.32.3.bb b/meta-python/recipes-devtools/python/python3-filelock_3.32.3.bb
index 744a1b6aaf..ec9113721b 100644
--- a/meta-python/recipes-devtools/python/python3-filelock_3.32.3.bb
+++ b/meta-python/recipes-devtools/python/python3-filelock_3.32.3.bb
@@ -5,6 +5,8 @@ HOMEPAGE = "https://py-filelock.readthedocs.io/"
 LICENSE = "MIT"
 LIC_FILES_CHKSUM = "file://LICENSE;md5=2c6acbdf7bb74caa37512c3a5ca6857b"
 
+CVE_PRODUCT = "tox-dev:filelock"
+
 SRC_URI += "file://run-ptest"
 
 SRC_URI[sha256sum] = "0ffa185a3540854c95caa7fa76b76cb219d907415e2c5dc9af25fd970563487f"
-- 
2.35.6


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-20 10:30 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-20 10:30 [meta-python][PATCH] python3-filelock: set CVE_PRODUCT Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox