mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-01 16:10:25 +00:00
The product-only "py" mapping generates a wildcard-vendor identity instead of the exact NVD identity for the packaged pytest-dev py source. Use "pytest:py" for its NVD dictionary CPE and configuration matches. This changes the generated product identity. With sbom-cve-check 1.3.3, the current CVE report is unchanged using the pinned database snapshots; both mappings report CVE-2020-29651 and CVE-2022-42969. Signed-off-by: Devansh Patel <devanshp@cisco.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>