Files
meta-openembedded/meta-python/recipes-devtools/python/python3-cbor2_5.9.0.bb
T
Devansh Patel 5250a6f557 python3-cbor2: use exact CVE_PRODUCT mapping
The product-only "cbor2" mapping uses a wildcard vendor. Use
"agronholm:cbor2", its NVD dictionary CPE and NVD configuration
identity for the packaged source.

The generated CPE changes, but Wrynose sbom-cve-check 1.3.1 with its
pinned 2026-05-07 databases has no current CVE report delta. This
backport applies the change to version 5.9.0 rather than 6.1.4.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 7f59d247ee)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-11 08:02:17 +05:30

21 lines
577 B
BlitzBasic

DESCRIPTION = "An implementation of RFC 7049 - Concise Binary Object Representation (CBOR)."
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=a79e64179819c7ce293372c059f1dbd8"
DEPENDS += "python3-setuptools-scm-native"
SRC_URI[sha256sum] = "85c7a46279ac8f226e1059275221e6b3d0e370d2bb6bd0500f9780781615bcea"
inherit pypi python_setuptools_build_meta ptest-python-pytest
RDEPENDS:${PN}-ptest += " \
python3-hypothesis \
python3-unixadmin \
"
RDEPENDS:${PN} += " \
python3-datetime \
"
CVE_PRODUCT = "agronholm:cbor2"
BBCLASSEXTEND = "native nativesdk"