diff mbox series

[meta-python,08/34] python3-eventlet: set CVE_PRODUCT

Message ID 20251231075436.771395-8-skandigraun@gmail.com
State New
Headers show
Series [meta-python,01/34] python3-pandas: set CVE_PRODUCT | expand

Commit Message

Gyorgy Sarvari Dec. 31, 2025, 7:54 a.m. UTC
The relevant CVEs are tracked using eventlet:eventlet CPE, and the default
python:eventlet CPE doesn't match relevant CVEs.

Set the correct CVE_PRODUCT.

See CVE db query:
sqlite> select * from products where product like 'eventlet';
CVE-2021-21419|eventlet|eventlet|0.10|>=|0.31.0|<
CVE-2023-29483|eventlet|eventlet|||0.35.2|<
CVE-2025-58068|eventlet|eventlet|||0.40.3|<

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
---
 meta-python/recipes-devtools/python/python3-eventlet_0.40.4.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta-python/recipes-devtools/python/python3-eventlet_0.40.4.bb b/meta-python/recipes-devtools/python/python3-eventlet_0.40.4.bb
index 21b1e095eb..213460dc70 100644
--- a/meta-python/recipes-devtools/python/python3-eventlet_0.40.4.bb
+++ b/meta-python/recipes-devtools/python/python3-eventlet_0.40.4.bb
@@ -7,6 +7,8 @@  LIC_FILES_CHKSUM = "file://LICENSE;md5=56472ad6de4caf50e05332a34b66e778"
 SRC_URI += "file://d19ad6cc086684ee74db250f5fd35227c98e678a.patch"
 SRC_URI[sha256sum] = "69bef712b1be18b4930df6f0c495d2a882bf7b63aa111e7b6eeff461cfcaf26f"
 
+CVE_PRODUCT = "eventlet"
+
 inherit pypi python_hatchling
 
 DEPENDS += "python3-hatch-vcs-native"