Commit Graph
9899 Commits
Author SHA1 Message Date
Jaipaul Cheernam c4a28775b9 python3-grpcio: fix build with OpenSSL 4.0
python3-grpcio bundles grpc 1.78.0 C core which has the same
OpenSSL 4.0 const and opaque type issues as grpc 1.83.0.

Upstream-Status: Submitted [https://github.com/grpc/grpc/pull/41932]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-27 23:33:14 -07:00
Peter Marko 64dcb55dc5 recipes: correct homepage
Leading space leads to SPDX document validation errors for url in
some tools.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-27 23:33:13 -07:00
Wang Mingyu 56df2f1be7 python3-zopeinterface: upgrade 8.5 -> 8.6
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:46 -07:00
Wang Mingyu 45d8122ed6 python3-xxhash: upgrade 4.0.0 -> 4.0.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:46 -07:00
Wang Mingyu ac072962ef python3-uv-dynamic-versioning: upgrade 0.14.0 -> 0.14.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:46 -07:00
Wang Mingyu 9c5e3f2647 python3-stevedore: upgrade 5.9.0 -> 5.9.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:46 -07:00
Wang Mingyu b647c41b16 python3-ruff: upgrade 0.16.3 -> 0.16.4
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:46 -07:00
Wang Mingyu 131815f2c6 python3-reportlab: upgrade 5.0.0 -> 5.0.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:45 -07:00
Wang Mingyu 7325c82888 python3-pyzmq: upgrade 27.1.0 -> 27.2.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:45 -07:00
Wang Mingyu 6e65773b64 python3-nanobind: upgrade 2.15.0 -> 3.0.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:45 -07:00
Wang Mingyu 7421967b67 python3-httpx2: upgrade 2.10.0 -> 2.12.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:45 -07:00
Wang Mingyu f56454ea74 python3-gunicorn: upgrade 26.0.0 -> 26.1.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:45 -07:00
Wang Mingyu c4bb1da0c2 python3-filelock: upgrade 3.32.3 -> 3.32.4
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:45 -07:00
Wang Mingyu a69d0357d9 python3-faker: upgrade 40.36.0 -> 40.37.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:44 -07:00
Wang Mingyu 46a504dc43 python3-evdev: upgrade 1.9.3 -> 2.0.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:44 -07:00
Wang Mingyu e15b1ce04d python3-cmd2: upgrade 4.2.0 -> 4.2.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:44 -07:00
Wang Mingyu 0351381c28 python3-bitstruct: upgrade 8.22.2 -> 8.23.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:44 -07:00
Wang Mingyu 1a5007d4ff python3-autoflake: upgrade 2.3.3 -> 2.4.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:44 -07:00
Wang Mingyu b421cb73c8 python3-astroid: upgrade 4.3.0 -> 4.3.1
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:44 -07:00
Devansh Patel 2aa82f4b33 python3-twisted: correct CVE_PRODUCT mapping
The product-only "twisted" value emits a wildcard-vendor identity
instead of the active identity assigned to the packaged Twisted source.

Use "twisted:twisted" for its NVD dictionary CPE, NVD configuration,
and CNA affected-data identities. With sbom-cve-check 1.3.3 and the
pinned database snapshots, the generated product identity changes; the
current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 10:26:42 -07:00
Jaipaul Cheernam 2f4c38d5d6 meta-python: fix trailing whitespace
Bitbake now warns about trailing whitespace in parsed metadata lines.
Fix the affected files to silence the warnings during parsing.

Reported on:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/89/builds/4284/steps/15/logs/warnings

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-26 01:43:11 -07:00
Devansh Patel 7a393253ec python3-ujson: add CVE_PRODUCT mapping
The current inherited "python:ujson" mapping does not match the UltraJSON identities used by NVD and CVE List V5, so source-aligned CVEs are missed.

Use "ultrajson:ultrajson" for the CNA affected-data identity and "ultrajson_project:ultrajson" for the NVD dictionary CPE and configuration identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:08 -07:00
Devansh Patel 46ca829b65 python3-twitter: correct Tweepy CVE_PRODUCT mapping
The product-only "tweepy" value emits a wildcard-vendor identity and
hides the distinct NVD identities assigned to the packaged Tweepy source.

Use "josh_roesslein:tweepy" for its NVD dictionary CPE and
"tweepy:tweepy" for the NVD configuration-only identity. With
sbom-cve-check 1.3.3 and the pinned database snapshots, the generated
product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:08 -07:00
Devansh Patel 3874342e00 python3-flask-user: correct CVE_PRODUCT mapping
The current "flask-user" mapping emits the wildcard-vendor
*:flask-user CPE instead of the exact NVD identity for the packaged
lingthio/Flask-User source.

Use "flask-user_project:flask-user", which is both an NVD dictionary
CPE and an NVD configuration identity. CNA affected data uses
"n/a:Flask-User" and remains covered by scanner aliases. With
sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the generated
identity changes but CVE-2021-23401 remains reported as affected.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel 6cbb85db1a python3-flask: correct CVE_PRODUCT mapping
The current "flask" mapping emits the wildcard-vendor *:flask CPE
instead of the exact NVD identity for the packaged pallets/flask
source.

Use "palletsprojects:flask", which is both an NVD dictionary CPE and
an NVD configuration identity. CNA affected data uses "pallets:flask"
and "The Pallets Project:Flask", which remain covered by scanner
aliases. With sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the
generated identity changes but the current CVE report does not.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel 33d7be4319 python3-aiohttp: correct CVE_PRODUCT mapping
The current "aiohttp" mapping emits the wildcard-vendor *:aiohttp CPE
instead of the exact NVD identity for the packaged aio-libs/aiohttp
source.

Use "aiohttp:aiohttp", which is both an NVD dictionary CPE and an NVD
configuration identity. CNA affected data uses "aio-libs:aiohttp" and
remains covered by scanner aliases. With sbom-cve-check 1.3.3 and the
pinned 2026-08-12 data, the generated identity changes but the current
CVE report does not.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel ae093476ee python3-waitress: correct CVE_PRODUCT mapping
The current product-only "waitress" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pylons source.

Use "pylons:waitress" for the CNA affected-data identity and "agendaless:waitress" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel fd0b8a36e6 python3-werkzeug: correct CVE_PRODUCT mapping
The current product-only "werkzeug" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pallets source.

Use "pallets:werkzeug" for the CNA affected-data identity and "palletsprojects:werkzeug" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
Devansh Patel 3ea522b0ec python3-pymongo: correct CVE_PRODUCT mapping
The product-only "pymongo" value emits a wildcard-vendor identity and
omits the second authoritative name for the packaged MongoDB Python
driver.

Use "mongodb:python_driver" for its NVD dictionary CPE family and
"mongodb:pymongo" for its NVD dictionary CPE and configuration identity.
With sbom-cve-check 1.3.3 and the pinned database snapshots, the
generated product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel a5f68ce920 python3-m2crypto: correct CVE_PRODUCT mapping
The current product-only "m2crypto" mapping generates a wildcard-vendor
identity instead of the two vendors used for the packaged source.

Use "heikkitoivonen:m2crypto" and "m2crypto_project:m2crypto" for their
exact NVD dictionary CPE and NVD configuration identities. This changes
the generated CPE set, but sbom-cve-check 1.3.3 with the pinned NVD
snapshot has no current CVE report delta.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel 26fa8b053b python3-py: correct CVE_PRODUCT mapping
The product-only "py" mapping generates a wildcard-vendor identity
instead of the exact NVD identity for the packaged pytest-dev py
source. Use "pytest:py" for its NVD dictionary CPE and configuration
matches.

This changes the generated product identity. With sbom-cve-check 1.3.3,
the current CVE report is unchanged using the pinned database snapshots;
both mappings report CVE-2020-29651 and CVE-2022-42969.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel d26cd38796 python3-simpleeval: add CVE_PRODUCT mapping
The current inherited "python:simpleeval" mapping is wrong for the
packaged danthedeckie SimpleEval source and misses its vulnerability
record.

Use "danthedeckie:simpleeval" for the source-aligned NVD dictionary
CPE, NVD configuration identity, and CNA affected-data identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00
Devansh Patel 43fd2c88f1 python3-filelock: set CVE_PRODUCT
The inherited python:filelock mapping does not identify the tox-dev source packaged by this recipe, so filelock CVEs are missed.

Use tox-dev:filelock to match the source identity used by NVD and CNA.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 22:43:21 -07:00
Khem Raj 282f300817 python3-msgspec: add recipe
Fast serialization and validation library for JSON, MessagePack, YAML and
TOML. Added as a runtime dependency of the forthcoming python3-max recipe,
but useful on its own.

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-20 19:39:15 -07:00
Devansh Patel 0a8f71a643 python3-httplib2: correct CVE_PRODUCT mapping
The current product-only "httplib2" mapping generates a wildcard-vendor
product identity instead of the vendor assigned to the packaged project.

Use "httplib2_project:httplib2" for its exact NVD dictionary CPE and NVD
configuration identity. This changes the generated CPE, but sbom-cve-check
1.3.3 with the pinned NVD database snapshot has no current CVE report delta.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 11:10:53 -07:00
Devansh Patel 19ecb40f50 python3-web3: add CVE_PRODUCT mapping
The current inherited "python:web3" mapping does not match the web3.py identities used by NVD and CVE List V5, so its source-aligned CVE is missed.

Use "ethereum:web3.py" for the CNA affected-data identity and "apeworx:web3.py" for the NVD dictionary CPE and configuration identity.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-20 11:10:53 -07:00
Devansh Patel 7f59d247ee python3-cbor2: use exact CVE_PRODUCT mapping
The product-only cbor2 mapping uses a wildcard vendor. Use
agronholm:cbor2, the NVD identity for the packaged source.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:56 -07:00
Wang Mingyu ec82b31e81 python3-xxhash: upgrade 3.8.1 -> 4.0.0
License-Update: Copyright year updated to 2026

Changelog:
===========
- Breaking change: Drop support for Python 3.8, require Python >= 3.9
- Breaking change: Remove deprecated xxhash.VERSION_TUPLE
- Breaking change: The input keyword argument is renamed to data in
  constructors and one-shot functions. update() additionally gains a data
  keyword argument (it accepted no keyword arguments before).
- Breaking change: str input is no longer accepted and raises TypeError:
  Strings must be encoded before hashing; encode to bytes before hashing
- Upgrade xxHash from v0.8.2 to v0.8.3. Note: on GCC/Clang source builds that
  target AVX2 (e.g. -march=x86-64-v3), upstream v0.8.3 autovectorizes
  XXH64_update() and makes the xxh64 streaming path about 2x slower. The shipped
  wheels are built for baseline x86-64 and are unaffected. Source builds can work
  around it by adding -fno-tree-vectorize to the compiler flags.
- Add per-object locking for thread safety, with sub-interpreter and
  free-threaded (no-GIL) Python support. The GIL is now released only while
  hashing inputs larger than 64 KiB; previously update() released it
  unconditionally and one-shot functions always held it.
- Speed up hash constructors by switching them to tp_vectorcall.
- Build pyodide wasm32 wheels
- Add s390x big-endian test job
- Add Python 3.15 classifier
- CI: shard the PyPI upload into parallel groups and create the GitHub Release
  automatically

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:52 -07:00
Wang Mingyu 51739905cd python3-virtualenv: upgrade 21.7.1 -> 21.7.4
Changelog:
==========
- Upgrade embedded pip/setuptools/wheel
- fix(config): return a real list from ListType.split_values
- Upgrade embedded pip/setuptools/wheel

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:52 -07:00
Wang Mingyu 498130ed30 python3-typing-inspection: upgrade 0.4.2 -> 0.4.4
Changelog:
==========
- Add typing_objects.DEPRECATED_ALIASES_ID
- Drop support for Python 3.9
- Avoid module getattr() calls in typing_objects functions
- Add Python 3.15 support

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:52 -07:00
Wang Mingyu 215c198a04 python3-trio: upgrade 0.33.0 -> 0.34.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:52 -07:00
Wang Mingyu 0491aaeccf python3-tox: upgrade 4.58.0 -> 4.60.0
Changelog:
===========
- fix(type): cast set value in _render_options
- docs: fix typo 'set the the' -> 'set then the' in config reference
- ci: pin coverage to the ctrace core
- chore: remove the misc changelog category
- test: seed the virtualenv wheel image up front
- feat(plugin): type the plugin and internal API surfaces
- test: raise timeout for missing-interpreter discovery tests
- docs: mark the INI configuration format as deprecated
- docs: publish llms.txt from the docs build
- Provision before loading env_list
- docs: repoint nine dead source links in the onboarding guide
- Add {home} and {tox_root_name} substitutions

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:51 -07:00
Wang Mingyu f9fccb9df5 python3-tornado: upgrade 6.5.7 -> 6.5.8
Changelog:
===========
- Form-encoded ''POST'' bodies are now subject to a limit of 1000 arguments by default. This
  prevents a CPU and memory denial of service attack. This limit can be overridden via the
  '.set_parse_body_config' function.
- Multipart parsing now rejects requests with an excessive number of parts earlier in the parsing
  process, limiting memory consumption.
- The deprecated mixed-case arguments to '.RequestHandler.set_cookie' now enforce the same
  restrictions on invalid characters that were introduced in Tornado 6.5.5 for the standard
  lowercase arguments.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:51 -07:00
Wang Mingyu 3748dd50e4 python3-telnetlib3: upgrade 4.0.5 -> 5.0.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:51 -07:00
Wang Mingyu 5808f8ac78 python3-starlette: upgrade 1.3.1 -> 1.6.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:50 -07:00
Wang Mingyu a412757da1 python3-sqlparse: upgrade 0.5.5 -> 0.6.0
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:50 -07:00
Wang Mingyu 58dcdc7869 python3-sqlalchemy: upgrade 2.0.51 -> 2.0.52
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:50 -07:00
Wang Mingyu 6140ec59e2 python3-soupsieve: upgrade 2.9.1 -> 2.9.2
Changelog:
==========
- FIX: Fix issue where :is() and :where() were not accounting for empty selectors in the max selector count as they should
- FIX: Fix issue where :has() was allowing empty selectors in some circumstances even though it is not forgiving.
- FIX: Reduce selector object size when :is() and :where() contain empty selectors.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:49 -07:00
Wang Mingyu fb3ebc53a9 python3-ruff: upgrade 0.16.1 -> 0.16.3
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:49 -07:00
Wang Mingyu 7b0c96f287 python3-qface: upgrade 2.0.13 -> 2.0.14
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-19 14:27:49 -07:00