Files
meta-openembedded/meta-python/recipes-devtools/python
Devansh Patel 5891d513a9 python3-web3: add CVE_PRODUCT mapping
The current inherited "python:web3" mapping does not match the web3.py
identities used by NVD and CVE List V5, so its source-aligned CVE is
missed.

Use "ethereum:web3.py" for the CNA affected-data identity and
"apeworx:web3.py" for the NVD dictionary CPE and NVD configuration
identity.

Backport note: Scarthgap has web3.py 6.17.0 rather than 7.16.0;
CVE-2026-40072 applies to this release and is reported as unpatched.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 19ecb40f50)
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-01 10:18:02 +05:30
..
2024-04-07 08:36:34 -07:00
2024-03-04 08:56:51 -08:00
2025-04-26 15:50:27 -04:00
2024-02-19 23:22:24 -08:00
2025-04-26 15:50:27 -04:00