Peter Marko
|
b465d9cf61
|
python3-protobuf: set status for CVE-2024-7254
Version 4.28.2 is correctly set in [1].
Unfortunately also protoc version 28.2 with the same CPE is mentioned
which creates a false positive which needs to be handled.
[1] https://github.com/CVEProject/cvelistV5/blob/main/cves/2024/7xxx/CVE-2024-7254.json
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
|
2026-07-20 23:08:11 -07:00 |
|
Khem Raj
|
8f3df8b447
|
recipes: Convert licenses to SPDX expressions
- Automatically convert all licenses to valid SPDX license expressions
using convert-spdx-licenses.py
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
|
2026-07-20 22:35:47 -07:00 |
|
Gyorgy Sarvari
|
aef8bc3422
|
protobuf, python3-protobuf: ignore CVE-2026-6409
Details: https://nvd.nist.gov/vuln/detail/CVE-2026-6409
The vulnerability impacts only the PHP library component, not the
cpp/python one. Ignore this CVE due to this.
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
|
2026-04-20 07:35:37 -07:00 |
|
Peter Marko
|
7dd437eb03
|
python3-protobuf: upgrade 6.33.5 -> 6.33.6
Release information [1] does not list python changes, but we should
match protobuf (C++) recipe version.
[1] https://github.com/protocolbuffers/protobuf/releases/tag/v33.6
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
|
2026-03-23 13:34:20 -07:00 |
|