Files
meta-openembedded/meta-python/recipes-devtools/python
Devansh Patel fd0b8a36e6 python3-werkzeug: correct CVE_PRODUCT mapping
The current product-only "werkzeug" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pallets source.

Use "pallets:werkzeug" for the CNA affected-data identity and "palletsprojects:werkzeug" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-24 12:14:07 -07:00
..
2026-08-04 10:47:40 -07:00
2026-07-09 09:11:53 -07:00
2026-07-10 15:08:46 -07:00