From 4b8eedb7d26387005924e6035f178b1d56dd33e9 Mon Sep 17 00:00:00 2001 From: Devansh Patel Date: Wed, 26 Aug 2026 00:53:48 -0700 Subject: [PATCH] php: correct CVE_PRODUCT mapping The default product-only mapping generates a vendor-wildcard CPE. php:php is the active NVD dictionary CPE and configuration identity. php_group:php preserves historical NVD configurations and current authoritative PHP Security CNA affected data for the same php-src source; it is not an NVD dictionary CPE. This changes the generated identities to two exact CPEs, but the frozen sbom-cve-check database leaves the 731-entry CVE report unchanged, with no current CVE delta. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj --- meta-oe/recipes-devtools/php/php_8.5.9.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-devtools/php/php_8.5.9.bb b/meta-oe/recipes-devtools/php/php_8.5.9.bb index bc249fd0d3..710d5b0506 100644 --- a/meta-oe/recipes-devtools/php/php_8.5.9.bb +++ b/meta-oe/recipes-devtools/php/php_8.5.9.bb @@ -34,6 +34,8 @@ S = "${UNPACKDIR}/php-${PV}" SRC_URI[sha256sum] = "703c082ad9d2946ac647f3596812300d2c62b360d2f31a999021692a9b39476c" +CVE_PRODUCT = "php:php php_group:php" + CVE_STATUS_GROUPS += "CVE_STATUS_PHP" CVE_STATUS_PHP[status] = "fixed-version: The name of this product is exactly the same as github.com/emlog/emlog. CVE can be safely ignored." CVE_STATUS_PHP = " \