From patchwork Tue Mar 31 11:38:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gyorgy Sarvari X-Patchwork-Id: 84896 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8B7E01061B37 for ; Tue, 31 Mar 2026 11:38:40 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.17969.1774957118432436006 for ; Tue, 31 Mar 2026 04:38:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=qGI+SBIH; spf=pass (domain: gmail.com, ip: 209.85.128.50, mailfrom: skandigraun@gmail.com) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-486fb439299so52263955e9.0 for ; Tue, 31 Mar 2026 04:38:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1774957117; x=1775561917; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to; bh=+kJ5i1vCgZ1a+4HI8HXPaa4JhJ85NEsCGUrSM/QPXMg=; b=qGI+SBIHnJ7oGcel9eBd8FLLyagcNwQ8oRNHfXp2wJcM4BB125OXpuF7NktUWHtT3K jNMdMlAgNGkQXUnsuUjFFFQVYfDgsL5tZTlGalMZh1AMEoMXV/ROmZlsOF1Fsaosw6Ag 1CSyOCRji97+vRYy4bEseOlmMWAclGVA3dDdUJyvM7vGitiuYiWDTMR15mfoCnErM3rM yizC7daXCdQpwxIdGTm9379epKeu8aPjYM4C3xiwR2JRVjRDLI2425ExgdqRxvEY0VO3 04PhweT6V/HFQFLJC6P9WrNlQM8vDR7ymfaJZktFo2hh7QuX9Y5V7ceVtM1BcmXeWiB/ q2dA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1774957117; x=1775561917; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=+kJ5i1vCgZ1a+4HI8HXPaa4JhJ85NEsCGUrSM/QPXMg=; b=RI/3CJH8zJ8Xsv5Gdun48t1l+ZwouTaVa8ayVgjPOiUmIMvwbnZS4qzZs/Z4LJH4rd fd30UlI4gB7OfSjZNDmqV9fnZI4xWxi8N+CoJ9l4FiUK0UF7kZR4qN9mNd5saL8JpSem HOo5wY2ke9jGrkdm4gY7+cNkySl+YXW5k2okeP5Ap0j54vaazf4lfFQTTH0eculykSZ1 6yL6z4IuzP24nQzqPwk9v4bAt1GH6jLgf7OIfqSSRGtwBtz0f46S/FPMzS/N+ZEE/yiK aeBwY5F9G9di150lDiJCLe4iPCLjFiFTJ/LyzNW7zyAlz6fpoal3g99kYVi2qmJJEMek T9tg== X-Gm-Message-State: AOJu0YwtGW0seZnLZ0hMcqslF5aZMXgyrj5N4oDbK+U3EagO9k4pdkX1 vQakZk/mqO1jvw3spY9a95FkwpjSfAab0xHSm+7sCtPKpnTtPRVT7nVtb6Z42A== X-Gm-Gg: ATEYQzyn4TgUujXhZAo2kGbjTIedKV/S5+WGsSvkzLD16SO/cSYF6tpVQBpu6uNffHR npTtKXVzIDgd8lFQK2C9Wt5qv4/Go8jMcyAFNCnjapK+xv6e6r/r+dP9sggM+5LxFbo6R+hHv44 rGwEuXhuXYxyr8fJafcvettSIGhzN65BxnoXZc56Q9JQPp5+rnB/jCPegbevlc8L9HYQw7QYS14 zxu+MSpeAvpWXSVghJX4JshEPZS2pwPd1ASq2WcXKgNtWojTnPDbnWAcNX8vdTGBRbNAijcHDFW /GFeROa+11i2Dy/aJUHyPDkgqFoinBbL2ayhuKriy6PSF5nrh7eMoMS4pWIoIOzcKgj61l6CbCk Qap97scP2LJ589/CNOeBayKNha6GK5OgmTEsPjlnQF0qbU1cZ4SIKSY/FETT6szGFzzMn72Gezd VZfb10D8SIpi01ukGoTSi/ X-Received: by 2002:a05:600c:608f:b0:485:41c4:e2e4 with SMTP id 5b1f17b1804b1-48728088485mr244875475e9.23.1774957116508; Tue, 31 Mar 2026 04:38:36 -0700 (PDT) Received: from desktop ([51.154.145.205]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43cf330872asm24401846f8f.17.2026.03.31.04.38.35 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Mar 2026 04:38:36 -0700 (PDT) From: Gyorgy Sarvari To: openembedded-devel@lists.openembedded.org Subject: [meta-python][PATCH 1/2] python3-pyjwt: drop obsolete CVE_STATUS Date: Tue, 31 Mar 2026 13:38:34 +0200 Message-ID: <20260331113835.3567782-1-skandigraun@gmail.com> X-Mailer: git-send-email 2.53.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 31 Mar 2026 11:38:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/125887 This CVE is disputed, and it is now tracked with an old version of the application, it doesn't show up in the CVE report anymore. Signed-off-by: Gyorgy Sarvari --- meta-python/recipes-devtools/python/python3-pyjwt_2.12.1.bb | 1 - 1 file changed, 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-pyjwt_2.12.1.bb b/meta-python/recipes-devtools/python/python3-pyjwt_2.12.1.bb index 96f060aa4e..eb445f9c91 100644 --- a/meta-python/recipes-devtools/python/python3-pyjwt_2.12.1.bb +++ b/meta-python/recipes-devtools/python/python3-pyjwt_2.12.1.bb @@ -9,7 +9,6 @@ SRC_URI[sha256sum] = "c74a7a2adf861c04d002db713dd85f84beb242228e671280bf709d765b PYPI_PACKAGE = "pyjwt" CVE_PRODUCT = "pyjwt" -CVE_STATUS[CVE-2025-45768] = "disputed: vulnerability can be avoided if the library is used correctly" inherit pypi python_setuptools_build_meta From patchwork Tue Mar 31 11:38:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gyorgy Sarvari X-Patchwork-Id: 84897 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id ABA6E1061B3B for ; Tue, 31 Mar 2026 11:38:40 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18374.1774957118931685263 for ; Tue, 31 Mar 2026 04:38:39 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=HRP+k9Uq; spf=pass (domain: gmail.com, ip: 209.85.221.43, mailfrom: skandigraun@gmail.com) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-43cf7683a28so1407437f8f.2 for ; Tue, 31 Mar 2026 04:38:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1774957117; x=1775561917; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to; bh=ieHvxOf+daO5IOUpkWzzXMQxpt1462V7bIq7E86rMtQ=; b=HRP+k9UqyQEjBWvyMvpzc0zv2Y0F5236U0Do8e8w0AWfJbWh1PzQ+wfoA3H/M8Ors8 sG1KZ535jHYZveHU50OpAEMN9Uc5rP8G0mZ2BMTvwWGAfLEWb1wNIa+2JpCtZGMClr65 dtGgGiMtqRYRNnvpeQozdaiYManzBBYSwkJ7PNkDsTbgE7JRyBDQK7qfznRNSKIOolEk f0S4LNWO4pI3kHuaNdxtumlWbBQDrjLBEDysUeR8Z13uM4mr9atgRRyqOE8GrV65Z3IL 9rU9sZUK1YbG5+KNtYnaJ4YTnuPHtcZ5oFb0+po/iXVGzyALLiUZ9JtpsW1z8q5KJ0hH erNQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1774957117; x=1775561917; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=ieHvxOf+daO5IOUpkWzzXMQxpt1462V7bIq7E86rMtQ=; b=NCNNHVN8cHV8rkqCQruuB2Py4BNkBE/kl7K8SiisNiljEnm4u+nNDAoxYKjn30Fbgw 4AKp1/iI0ISddQK8RLpv2xNqUzwxpdFPhesO7vYRl46aU+Jvtsk1JL63JAOJuvzzJDrD 1QJ5QbLM1HgF1pcMVea7C4e/9/j4cpQ3jlt9sHJKESU1i5rHwDckeL1/cyVHS8OTwnoP jmbJpt1t3yBDlXdj7VCn1/V8MgxeUlJ/6zrhct/PHKOBfGqK+L78id80tEmLywx/KVNE wN2LFN9ZnzrGmTwAUIwzJXDQvzVhMUP5l5rq+Us7dmDxdTcKMyb0LxrkX1dn6Rv+jgwb Bdew== X-Gm-Message-State: AOJu0Yx3bgW3rsrgvVmZaHzlC/L2wYsijfx7w1L5F4RhmPRhXzzjCsY9 6V513Ic/jdAV8xA55b3ARoOZcijJ34JvlYcYgXIxaAX6VKm6dA6LG8Wa0K5/HQ== X-Gm-Gg: ATEYQzyoc581tvNtI2M2yx8axGVNpUSPqyT9KUyZdV2iK7BCCiMuJtgyh1WG3dncFMB 3P/HHUng4TTkR04GgegJS9TJqVR3lY2R+Q60F01WrWVYyVt0O3xjZJE7HkM3xMyJ2mD22rTPuWm kFKMI7NawDpN/yzUCzfJnd1xsJIEUW23wFT5VOdWv+UUGkCpuE8/uD6y+7+rZPwjA9x8sUwVrLV Jw4rIJxIMcIcA2o0p5481USrgaMCWFDP5668wyHZ1JT8I9nvNQL2B9zxhU9OZ78X+trDlmka6pU Bq+LWNXyX7atctTVUz9b9CdU2l8mpq14UiQZkmVkJSqjYqW3t6R35CUI7X1SSzGUSfDiv8xyjBK 8+IGCpHWxP4RZ3rE2d0BD7ddR+Z77hutZQLu1e5U8coCFnl+vps421xhWcWJtSZJM9jrdiiBG+v 4WqlY0cXT0Z7Ekzl006NpANOTPJj2srbc= X-Received: by 2002:a5d:5f88:0:b0:43b:6356:7d00 with SMTP id ffacd0b85a97d-43b9e990080mr29059732f8f.17.1774957117140; Tue, 31 Mar 2026 04:38:37 -0700 (PDT) Received: from desktop ([51.154.145.205]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43cf330872asm24401846f8f.17.2026.03.31.04.38.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Mar 2026 04:38:36 -0700 (PDT) From: Gyorgy Sarvari To: openembedded-devel@lists.openembedded.org Subject: [meta-python][PATCH 2/2] python3-nltk: upgrade 3.9.3 -> 3.9.4 Date: Tue, 31 Mar 2026 13:38:35 +0200 Message-ID: <20260331113835.3567782-2-skandigraun@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260331113835.3567782-1-skandigraun@gmail.com> References: <20260331113835.3567782-1-skandigraun@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 31 Mar 2026 11:38:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/125888 Changes: * Support Python 3.14 * Fix bug in Levenshtein distance when substitution_cost > 2 * Fix bug in Treebank detokeniser re quote ordering * Fix bug in Jaro similarity for empty strings * Several security enhancements * Fix GHSA-rf74-v2fm-23pw: unbounded recursion in JSONTaggedDecoder * Implement TextTiling vocabulary introduction method (Hearst 1997) * Fix ALINE feature matrix errors and add comprehensive tests * Support multiple VerbNet versions, fix longid/shortid regex for VerbNet ids * Let downloader fallback to md5 when sha256 is unavailable * Several other minor bugfixes and code cleanups Signed-off-by: Gyorgy Sarvari --- .../{python3-nltk_3.9.3.bb => python3-nltk_3.9.4.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta-python/recipes-devtools/python3-nltk/{python3-nltk_3.9.3.bb => python3-nltk_3.9.4.bb} (89%) diff --git a/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.3.bb b/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.4.bb similarity index 89% rename from meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.3.bb rename to meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.4.bb index d9f661b262..50c751ba98 100644 --- a/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.3.bb +++ b/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.4.bb @@ -24,4 +24,4 @@ RRECOMMENDS:${PN} = "\ inherit setuptools3 pypi -SRC_URI[sha256sum] = "cb5945d6424a98d694c2b9a0264519fab4363711065a46aa0ae7a2195b92e71f" +SRC_URI[sha256sum] = "ed03bc098a40481310320808b2db712d95d13ca65b27372f8a403949c8b523d0"