Files
meta-openembedded/meta-python/recipes-devtools/python/python3-twitter_4.17.0.bb
T
Devansh Patel 46ca829b65 python3-twitter: correct Tweepy CVE_PRODUCT mapping
The product-only "tweepy" value emits a wildcard-vendor identity and
hides the distinct NVD identities assigned to the packaged Tweepy source.

Use "josh_roesslein:tweepy" for its NVD dictionary CPE and
"tweepy:tweepy" for the NVD configuration-only identity. With
sbom-cve-check 1.3.3 and the pinned database snapshots, the generated
product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:08 -07:00

23 lines
600 B
BlitzBasic

SUMMARY = "Twitter for Python"
DESCRIPTION = "Python module to support twitter API"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://LICENSE;md5=48c84b17f84a9a623754604ab73f28fe"
SRC_URI[sha256sum] = "c232e9fffa0b15b81d5ff8ec59d46af85e330285ffc3e64614d2418fb9af71b5"
PYPI_PACKAGE = "tweepy"
inherit pypi python_flit_core
RDEPENDS:${PN} += "\
python3-pip \
python3-pysocks \
python3-requests \
python3-requests-oauthlib \
python3-six \
"
CVE_PRODUCT = "josh_roesslein:tweepy tweepy:tweepy"
CVE_STATUS[CVE-2012-5825] = "fixed-version: The vulnerability has been fixed since v3.1.0"