From: Tim Orling <[email protected]>

The current "python3-numpy" mapping has no matching NVD CPE or
configuration identity, so eight source-aligned CVE records are missed.
Use "numpy:numpy", the active NVD dictionary CPE and configuration
identity for the packaged NumPy source.

Note: The original commit targeted python3-numpy_2.5.2.bb. This is
adjusted for Scarthgap, where the recipe version is 1.26.4.

Signed-off-by: Tim Orling <[email protected]>
Signed-off-by: Mathieu Dubois-Briand <[email protected]>
Signed-off-by: Richard Purdie <[email protected]>
(cherry picked from commit ad623e71fadeddcb0b70bba8fbf28c75a976e596)
Signed-off-by: Devansh Patel <[email protected]>
---
 meta/recipes-devtools/python/python3-numpy_1.26.4.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb 
b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb
index ccd08147af..9164874445 100644
--- a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb
+++ b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb
@@ -18,6 +18,8 @@ SRC_URI[sha256sum] = 
"2a02aba9ed12e4ac4eb3ea9421c420301a0c6460d9830d74a9df87efa4
 GITHUB_BASE_URI = "https://github.com/numpy/numpy/releases";
 UPSTREAM_CHECK_REGEX = "releases/tag/v?(?P<pver>\d+(\.\d+)+)$"
 
+CVE_PRODUCT = "numpy:numpy"
+
 DEPENDS += "python3-cython-native"
 
 inherit ptest setuptools3 github-releases
-- 
2.35.6
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243831): 
https://lists.openembedded.org/g/openembedded-core/message/243831
Mute This Topic: https://lists.openembedded.org/mt/120843155/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to