mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-01 16:10:25 +00:00
The product-only "py" mapping generates a wildcard-vendor identity instead of the exact NVD identity for the packaged pytest-dev py source. Use "pytest:py" for its NVD dictionary CPE and configuration matches. This changes the generated product identity. With sbom-cve-check 1.3.3, the current CVE report is unchanged using the pinned database snapshots; both mappings report CVE-2020-29651 and CVE-2022-42969. Signed-off-by: Devansh Patel <devanshp@cisco.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
18 lines
596 B
BlitzBasic
18 lines
596 B
BlitzBasic
SUMMARY = "Library with cross-python path, ini-parsing, io, code, log facilities"
|
|
HOMEPAGE = "https://py.readthedocs.io/"
|
|
LICENSE = "MIT"
|
|
LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9"
|
|
|
|
SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719"
|
|
|
|
CVE_PRODUCT = "pytest:py"
|
|
CVE_STATUS[CVE-2022-42969] = "disputed: upstream could not reproduce it, github also revoked the advisory"
|
|
|
|
DEPENDS += "python3-setuptools-scm-native"
|
|
|
|
inherit pypi python_setuptools_build_meta
|
|
|
|
BBCLASSEXTEND = "native nativesdk"
|
|
|
|
RDEPENDS:${PN} += "python3-netclient"
|