diff mbox series

[meta-python,10/10] python3-svglib: set CVE_PRODUCT

Message ID 20251230154903.736590-10-skandigraun@gmail.com
State New
Headers show
Series [meta-python,01/10] python-gunicorn: set CVE_PRODUCT | expand

Commit Message

Gyorgy Sarvari Dec. 30, 2025, 3:49 p.m. UTC
There is only one relevant CVE in the database, but it is tracked using
svglib_project:svglib CPE, not the expected python:svglib CPE, making the
cve-checker miss it.

See CVE db query:
sqlite> select * from products where product like '%svglib%';
CVE-2020-10799|svglib_project|svglib|||0.9.3|<=

Set the CVE_PRODUCT accordingly.

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
---
 meta-python/recipes-devtools/python/python3-svglib_1.6.0.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta-python/recipes-devtools/python/python3-svglib_1.6.0.bb b/meta-python/recipes-devtools/python/python3-svglib_1.6.0.bb
index 67c072c9a1..fc16e3099d 100644
--- a/meta-python/recipes-devtools/python/python3-svglib_1.6.0.bb
+++ b/meta-python/recipes-devtools/python/python3-svglib_1.6.0.bb
@@ -6,6 +6,8 @@  DESCRIPTION = "Svglib is a Python library for reading SVG files and \
 LICENSE = "LGPL-3.0-or-later"
 LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=b52f2d57d10c4f7ee67a7eb9615d5d24"
 
+CVE_PRODUCT = "svglib"
+
 SRC_URI[sha256sum] = "4c38a274a744ef0d1677f55d5d62fc0fb798819f813e52872a796e615741733d"
 
 inherit pypi python_hatchling