From patchwork Tue Aug 4 06:23:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 94406 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3DB6C55AB9 for ; Tue, 4 Aug 2026 06:24:06 +0000 (UTC) Received: from a27-191.smtp-out.us-west-2.amazonses.com (a27-191.smtp-out.us-west-2.amazonses.com [54.240.27.191]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.10709.1785824638428404447 for ; Mon, 03 Aug 2026 23:23:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=n47k5c34; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ybhLxlW4; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.191, mailfrom: 0101019fcb717210-a63ec09f-9f92-43db-a6f0-a267c19d1614-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1785824637; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date; bh=NU8FoJT7YOjEoFtXA7Wp5xtFzM5/aYWSsXjcijqesOk=; b=n47k5c34GvGhahdYHmPdMngDJ/IVY6m0DYylfCkvYZvklilitZ4B1luTn7yUA+ih XyEcODRPBrZELWsnU4p8PbdAi1ObEx3s6SBBRLnQi2SuiUYN6bXDgLEpWF33mBczGiO ZLvz9VuJssbAfBzkDNlbf5oY2zy82bDN/rcpmC+s= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1785824637; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date:Feedback-ID; bh=NU8FoJT7YOjEoFtXA7Wp5xtFzM5/aYWSsXjcijqesOk=; b=ybhLxlW4bqKHSU5tjkWU6GIN8aW8wH0fO63XiuHmMaVsayuhTx5nhN5EtlS4m+6S 7clldP0bhaOlssmWBFTlbFrHmz2B3WRscBAsHJOIrwdPFbpMLhpvePk3wbQEgfUuClt RfmDkFs1bRXOHaK0vQoVYyhB04B0C3ieoRWUMgqE= MIME-Version: 1.0 From: auh@yoctoproject.org To: Benjamin Robin Cc: openembedded-core@lists.openembedded.org Subject: [AUH] python3-sbom-cve-check: upgrading to 1.3.3 SUCCEEDED Message-ID: <0101019fcb717210-a63ec09f-9f92-43db-a6f0-a267c19d1614-000000@us-west-2.amazonses.com> Date: Tue, 4 Aug 2026 06:23:57 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.08.04-54.240.27.191 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 04 Aug 2026 06:24:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242705 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *python3-sbom-cve-check* to *1.3.3* has Succeeded. Next steps: - apply the patch: git am 0001-python3-sbom-cve-check-upgrade-1.3.2-1.3.3.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From 5bd82580e0ce5081caa54dcafb798328b3cdfe4a Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Tue, 4 Aug 2026 06:04:38 +0000 Subject: [PATCH] python3-sbom-cve-check: upgrade 1.3.2 -> 1.3.3 Source: CHANGELOG.md ## v1.3.3 - Updated the version of the CVE databases used for testing. - Generate a "not affected" assessment if the vulnerability is disputed. - Handle CVE List version field with multiple version expressions: a version prefixed by a comparison operator (`<`, `<=`, `>`, `>=`, or `=`). - Added support for `uv` and updated the [Developer Guide]( https://sbom-cve-check.readthedocs.io/en/v1.3.3/dev-guide.html). - Added a contributing guide. - Fixed CVE database git repository update when initially cloned from a tag and updated to a new tag. - Ignore version range if a boundary is a date (YYYY-MM-DD) and the component version is not a date (e.g., a semver). - Ignore in some cases the version range if a boundary has a distro packaging version (e.g., with a `.el7` suffix), as documented in the [design section]( https://sbom-cve-check.readthedocs.io/en/v1.3.3/design.html#compute-vex-assessment-from-semantic-version-ranges). --- ...-sbom-cve-check_1.3.2.bb => python3-sbom-cve-check_1.3.3.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.2.bb => python3-sbom-cve-check_1.3.3.bb} (82%) diff --git a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb similarity index 82% rename from meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb rename to meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb index f14901e300..2aca100569 100644 --- a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb +++ b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb @@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=570a9b3749dd0463a1778803b12a6dce" PYPI_PACKAGE = "sbom_cve_check" -SRC_URI[sha256sum] = "0a7f07a0c6ce45d40adc6d311ddc25c4466f59bafcbce149b6fb3663791a5d89" +SRC_URI[sha256sum] = "8b766be1ae92b4eceaa2f694dd4724e310886c6436f44267a6bbc6a7b81ab8b9" inherit pypi python_hatchling