diff mbox series

[meta-oe,wrynose,32/42] php: correct CVE_PRODUCT mapping

Message ID 20260923104056.457360-32-ankur.tyagi85@gmail.com
State New
Headers show
Series [meta-oe,wrynose,1/42] c-ares: mark CVEs fixed | expand

Commit Message

Ankur Tyagi Sept. 23, 2026, 10:40 a.m. UTC
From: Devansh Patel <devanshp@cisco.com>

The default product-only mapping generates a vendor-wildcard CPE. php:php
is the active NVD dictionary CPE and configuration identity. php_group:php
preserves historical NVD configurations and current authoritative PHP
Security CNA affected data for the same php-src source; it is not an NVD
dictionary CPE.

This changes the generated identities to two exact CPEs, but the frozen
sbom-cve-check database leaves the 731-entry CVE report unchanged, with no
current CVE delta.

Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 4b8eedb7d26387005924e6035f178b1d56dd33e9)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 meta-oe/recipes-devtools/php/php_8.5.10.bb | 2 ++
 1 file changed, 2 insertions(+)
diff mbox series

Patch

diff --git a/meta-oe/recipes-devtools/php/php_8.5.10.bb b/meta-oe/recipes-devtools/php/php_8.5.10.bb
index aab18777c7..130a98f634 100644
--- a/meta-oe/recipes-devtools/php/php_8.5.10.bb
+++ b/meta-oe/recipes-devtools/php/php_8.5.10.bb
@@ -34,6 +34,8 @@  S = "${UNPACKDIR}/php-${PV}"
 
 SRC_URI[sha256sum] = "d79bd4f3a9248e5cb5833766ba0d51cd35dd01b8727f23f30bcdba6fabc51d3e"
 
+CVE_PRODUCT = "php:php php_group:php"
+
 CVE_STATUS_GROUPS += "CVE_STATUS_PHP"
 CVE_STATUS_PHP[status] = "fixed-version: The name of this product is exactly the same as github.com/emlog/emlog. CVE can be safely ignored."
 CVE_STATUS_PHP = " \