* [meta-oe][PATCH] jq: correct CVE_PRODUCT mapping
@ 2026-08-26 7:53 Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
0 siblings, 0 replies; only message in thread
From: Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-26 7:53 UTC (permalink / raw)
To: openembedded-devel; +Cc: xe-linux-external
From: Devansh Patel <devanshp@cisco.com>
The default product-only mapping generates a vendor-wildcard CPE.
Use jq_project:jq for the historical NVD dictionary CPE and configuration
identity carrying two jq 1.5 CVEs, and jqlang:jq for the active NVD
dictionary CPE and configuration identity plus CNA affected-data identity
used by the current upstream.
This changes the generated identities to two exact CPEs, but the frozen
sbom-cve-check database leaves the 26-entry CVE report unchanged, with no
current CVE delta.
Signed-off-by: Devansh Patel <devanshp@cisco.com>
---
meta-oe/recipes-devtools/jq/jq_1.8.2.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-devtools/jq/jq_1.8.2.bb b/meta-oe/recipes-devtools/jq/jq_1.8.2.bb
index c413391a7a..0bbe6e009f 100644
--- a/meta-oe/recipes-devtools/jq/jq_1.8.2.bb
+++ b/meta-oe/recipes-devtools/jq/jq_1.8.2.bb
@@ -14,6 +14,8 @@ SRC_URI = "git://github.com/jqlang/jq.git;protocol=https;branch=master;tag=jq-${
file://run-ptest \
"
+CVE_PRODUCT = "jq_project:jq jqlang:jq"
+
inherit autotools ptest
UPSTREAM_CHECK_GITTAGREGEX = "${BPN}-(?P<pver>\d+(\.\d+)+)"
--
2.35.6
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-26 7:54 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 7:53 [meta-oe][PATCH] jq: correct CVE_PRODUCT mapping Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox