From: Tim Orling <[email protected]> The current "python3-numpy" mapping has no matching NVD CPE or configuration identity, so eight source-aligned CVE records are missed. Use "numpy:numpy", the active NVD dictionary CPE and configuration identity for the packaged NumPy source.
Note: The original commit targeted python3-numpy_2.5.2.bb. This is adjusted for Scarthgap, where the recipe version is 1.26.4. Signed-off-by: Tim Orling <[email protected]> Signed-off-by: Mathieu Dubois-Briand <[email protected]> Signed-off-by: Richard Purdie <[email protected]> (cherry picked from commit ad623e71fadeddcb0b70bba8fbf28c75a976e596) Signed-off-by: Devansh Patel <[email protected]> --- meta/recipes-devtools/python/python3-numpy_1.26.4.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb index ccd08147af..9164874445 100644 --- a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb +++ b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb @@ -18,6 +18,8 @@ SRC_URI[sha256sum] = "2a02aba9ed12e4ac4eb3ea9421c420301a0c6460d9830d74a9df87efa4 GITHUB_BASE_URI = "https://github.com/numpy/numpy/releases" UPSTREAM_CHECK_REGEX = "releases/tag/v?(?P<pver>\d+(\.\d+)+)$" +CVE_PRODUCT = "numpy:numpy" + DEPENDS += "python3-cython-native" inherit ptest setuptools3 github-releases -- 2.35.6
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243831): https://lists.openembedded.org/g/openembedded-core/message/243831 Mute This Topic: https://lists.openembedded.org/mt/120843155/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
