Files
meta-openembedded/meta-python/recipes-devtools/python/python3-pymongo_4.17.0.bb
T
Devansh Patel 3ea522b0ec python3-pymongo: correct CVE_PRODUCT mapping
The product-only "pymongo" value emits a wildcard-vendor identity and
omits the second authoritative name for the packaged MongoDB Python
driver.

Use "mongodb:python_driver" for its NVD dictionary CPE family and
"mongodb:pymongo" for its NVD dictionary CPE and configuration identity.
With sbom-cve-check 1.3.3 and the pinned database snapshots, the
generated product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-22 18:50:03 -07:00

39 lines
1.1 KiB
BlitzBasic

SUMMARY = "Python driver for MongoDB <http://www.mongodb.org>"
DESCRIPTION = "\
The PyMongo distribution contains tools for interacting with MongoDB \
database from Python. The bson package is an implementation of the BSON \
format for Python. The pymongo package is a native Python driver for \
MongoDB. The gridfs package is a gridfs implementation on top of pymongo."
HOMEPAGE = "https://github.com/mongodb/mongo-python-driver"
LICENSE = "Apache-2.0"
LIC_FILES_CHKSUM = "file://LICENSE;md5=86d3f3a95c324c9479bd8986968f4327"
SRC_URI[sha256sum] = "70ffa08ba641468cc068cf46c06b34f01a8ce3489f6411309fcb5ceabe6b2fc0"
CVE_PRODUCT = "mongodb:python_driver mongodb:pymongo"
inherit pypi python_hatchling
PACKAGES =+ "python3-bson"
FILES:python3-bson = "${PYTHON_SITEPACKAGES_DIR}/bson/*"
DEPENDS += " \
python3-hatch-requirements-txt-native \
"
RDEPENDS:python3-bson += " \
python3-datetime \
python3-json \
python3-netclient \
python3-numbers \
python3-threading \
"
RDEPENDS:${PN} += " \
python3-bson \
python3-pprint \
python3-difflib \
python3-logging \
"