python3-twitter: correct Tweepy CVE_PRODUCT mapping

The product-only "tweepy" value emits a wildcard-vendor identity and
hides the distinct NVD identities assigned to the packaged Tweepy source.

Use "josh_roesslein:tweepy" for its NVD dictionary CPE and
"tweepy:tweepy" for the NVD configuration-only identity. With
sbom-cve-check 1.3.3 and the pinned database snapshots, the generated
product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
This commit is contained in:
Devansh Patel
2026-08-24 12:14:08 -07:00
committed by Khem Raj
parent 3874342e00
commit 46ca829b65
@@ -18,5 +18,5 @@ RDEPENDS:${PN} += "\
python3-six \
"
CVE_PRODUCT = "tweepy"
CVE_PRODUCT = "josh_roesslein:tweepy tweepy:tweepy"
CVE_STATUS[CVE-2012-5825] = "fixed-version: The vulnerability has been fixed since v3.1.0"