From: Himanshu Jadon <[email protected]>

CVE_PRODUCT is not set for python3-pip, so cve-check can miss or
misreport pip CVEs. CVE-2026-8643 is reported in NVD with pypa:pip.

Add CVE_PRODUCT to match the NVD product name and report this CVE
correctly.

Signed-off-by: Himanshu Jadon <[email protected]>
Signed-off-by: Richard Purdie <[email protected]>
(cherry picked from commit a486abd4889ad03e1a8ddd5311595f3ece7d61b6)
Signed-off-by: Himanshu Jadon <[email protected]>
---
 meta/recipes-devtools/python/python3-pip_24.0.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-devtools/python/python3-pip_24.0.bb 
b/meta/recipes-devtools/python/python3-pip_24.0.bb
index cf123a5d23..51fff41e25 100644
--- a/meta/recipes-devtools/python/python3-pip_24.0.bb
+++ b/meta/recipes-devtools/python/python3-pip_24.0.bb
@@ -41,6 +41,8 @@ do_install:append() {
     rm -f ${D}/${bindir}/pip
 }
 
+CVE_PRODUCT = "pypa:pip"
+
 do_install:append(){
        # pip vendors distlib which ships Windows launcher templates (*.exe).
        # Keep them only when building for a Windows (mingw) host.
-- 
2.35.6

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242611): 
https://lists.openembedded.org/g/openembedded-core/message/242611
Mute This Topic: https://lists.openembedded.org/mt/120573575/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to