From patchwork Sun Aug 9 23:19:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Tim Orling X-Patchwork-Id: 94823 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4335BC5AD5A for ; Sun, 9 Aug 2026 23:19:29 +0000 (UTC) Received: from mail-pf1-f172.google.com (mail-pf1-f172.google.com [209.85.210.172]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18965.1786317559652069163 for ; Sun, 09 Aug 2026 16:19:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=bRaBfpwq; spf=pass (domain: konsulko.com, ip: 209.85.210.172, mailfrom: tim.orling@konsulko.com) Received: by mail-pf1-f172.google.com with SMTP id d2e1a72fcca58-84862b0d5aeso1167728b3a.2 for ; Sun, 09 Aug 2026 16:19:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1786317559; x=1786922359; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=VvQDB1TOPAKE75weNymHpmNw/wtMEhxjFmdIyOmkddw=; b=bRaBfpwq5gw6vr4Gz7EqfNZH7J/PThFsn4/Pa4SBiJhsFvDVoCeVZYnYkbJJkHxgdO XrCXDfvvDTDvwM0L01mkN93mbI6yzMr5VyzDYio9AojjYE4HT49V0OVdE5xtDsDWB+sa MOS6LWduAfhRoR2rpfkrCnICG+YS/MLEpnJv8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786317559; x=1786922359; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VvQDB1TOPAKE75weNymHpmNw/wtMEhxjFmdIyOmkddw=; b=hdHAj9d1OuTT2yZYcfaZXn3PgyiFg1wMPnWHLY/eei8tD2ydHPJWouXJlvJB6H+Ehx CumxOmPrGNlws6N6tIw8mjFVf87+CGNaaICO/TwkBDgNBHHAJB0UwxWsmC0LTFdsEEO2 BNWR/boeEUazGnagtFmEthg+zbINtsnof8kQPZyVAl5v4fJnHkx5SE2sc4f8YcuW4kWz 9zxd2GmjNzTY/ggLTKlRhb/OXb0gfgPqd1ohBm91D/FILS21z2Eq4EQ2ETP0qOz6AGs4 jKv89wtxAjNepWS7+T0zP2RD/xajISxmLxjUVhZpBAjtbacfiES//MDS3IFexSCxapMG ZB4Q== X-Gm-Message-State: AOJu0YyUvgHpr68+dzMZGFB9muRDQE/in/jOqBz3ahMGC5+e7sJDubJJ RpI3kPaD3gsyC6mWqXWDH0L2v0sPclo2DgPALH15SOa9jtLI6NfSBog1QGqXa1wCMGXvoNa1av+ Pa3TX X-Gm-Gg: AR+sD12SYEcqKYvOO4KdNEJNVxMp2t9IT6BY0kaSW5DFlFgk8s/TThn3TW13VL8EA6h LEv1tMKAI+krs5uIhoG5tHtzNy3y0jYHL8/f5q5PNZD9TRevHAR67PhO673RCi4uumRd8Jle6E6 +N4Az58Z0wWpcbUXVjdqX1De9eElYxx4zxqJ70MzYVEP2rsMd1PdNx3NRGZ5KN7hF5xPpkwtTwr sCA9goukUrFWmYmrv1/2k85R6aLgKfK9cPJ8PKBiSmQ4BKbhvtcg0y7Yoiv7c4VTpS73XMpMslM yODAU4Q4Mk6DLDMplj4T2X2DeFFNAdfaXjQY7rSX3m7qwB1VrAb5oZpKTTQpZB0jhch1ZY2E9hy x4ByAXOYrt1J31taoHSdysPkwoT8DQ613J9iZEWqz8JQ6HViteHwJT1/C5yClzKYgipiIpvRQ8o csXauvRepcKQFdZdaYxhreyPPQz2FGAihLALh3WNxDVCNF8MDZe5FnyzCl1khxwbVRJ204EvpKG ++lQUc= X-Received: by 2002:a05:6a00:4288:b0:847:83bc:d2a4 with SMTP id d2e1a72fcca58-84f2dfc8c42mr44718348b3a.2.1786317558928; Sun, 09 Aug 2026 16:19:18 -0700 (PDT) Received: from thetis.home.local ([2606:c800:6024:2000:6f86:9ad6:671d:ec76]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84f5a58998bsm2976866b3a.55.2026.08.09.16.19.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 16:19:18 -0700 (PDT) From: tim.orling@konsulko.com To: openembedded-core@lists.openembedded.org Cc: Tim Orling Subject: [PATCH 1/3] python3-git: fix CVE_PRODUCT Date: Sun, 9 Aug 2026 16:19:00 -0700 Message-ID: <20260809231901.366919-2-tim.orling@konsulko.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 09 Aug 2026 23:19:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243080 From: Tim Orling Using the pypi.bbclass default CPE of python:GitPython detects no CVEs. With CVE_PRODUCT = "gitpython_project:gitpython" we properly detect 9 CVEs, with 4 unpatched. WARNING: core-image-full-cmdline-1.0-r0 do_sbom_cve_check: python3-git-3.1.43: Found unpatched CVEs: CVE-2026-42215, CVE-2026-42284, CVE-2026-44243, CVE-2026-44244 Signed-off-by: Tim Orling --- meta/recipes-devtools/python/python3-git_3.1.43.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb index 45c988117b..ccf6def292 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb @@ -10,6 +10,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e" PYPI_PACKAGE = "GitPython" +CVE_PRODUCT = "gitpython_project:gitpython" + inherit pypi python_setuptools_build_meta SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c" From patchwork Sun Aug 9 23:19:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Tim Orling X-Patchwork-Id: 94824 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 238C1C5AD5A for ; Sun, 9 Aug 2026 23:19:49 +0000 (UTC) Received: from mail-pf1-f173.google.com (mail-pf1-f173.google.com [209.85.210.173]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.18977.1786317585244395473 for ; Sun, 09 Aug 2026 16:19:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=DhSeMhS2; spf=pass (domain: konsulko.com, ip: 209.85.210.173, mailfrom: tim.orling@konsulko.com) Received: by mail-pf1-f173.google.com with SMTP id d2e1a72fcca58-84e3007a2b7so1157703b3a.0 for ; Sun, 09 Aug 2026 16:19:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1786317585; x=1786922385; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=pTsIWvC7IOnQ533NLXByQ/qX7+6q+gtiHVsSv8G0SnE=; b=DhSeMhS2a/Ar8TYi+p1zYRNFVaQVm++DNeqjpdDd11pcIbaqwAS6UFDbDyg01+BCsC EcGHLkeWe7MqWXSY0WxcB3BdF8NxbYdAaKZePWZ8MrM3wDTpNqzYYD0z/Eyp14FYfAIx BoIydBxXvwwFhYLgf3cZaFBjlGpw/ByZL5jTw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786317585; x=1786922385; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=pTsIWvC7IOnQ533NLXByQ/qX7+6q+gtiHVsSv8G0SnE=; b=blpSxwaIal3+AMwZBDWlRQCTk3TW0uHWRqk6rNBrpHsqpSjMl0/0iOURsHibiMJ27r x67u1JmFGRKJ4fJlHi1ScVHCZZtZ0BU/p3Iltz/Zn6q5KPr3L04ZFLCYe35Nyyd3eMZR C0FYeu0BTRP/jCGEtsIfJ0Xl9z4FGWObnlnL34GhUjHvl1pZcQLzbj4BNcpQanm3hDoD KDTSOR/wMqFbyFJMFpAjQ7L9mSKnn1GKhe1J9sH3Md564TDnT7rkovy2iL9cBfiNit4y kva9fnQydVoaTFPc3pxSnfZFSIX4gTU+WuDk3339rFc8mHM9sip6zKUOnKqhPAnqffBE pA8A== X-Gm-Message-State: AOJu0YyxNkzWTK64QEe4KtZwkusKrFOyfZwsXsUrJrJTD5knqRXz585d z1DpIqCEjniir8YIwwKpcIvfQmqLsos7/GWypeNF+nl9lk1U6T04h9xwL4ZKWR7gtIPF3wqVIkK 4myYP X-Gm-Gg: AR+sD13+naTAek6TSb42DovK9cJdHo4ec94Nojn0E7R18h8uq3W5G4IQjW3sUP0Ho2J AYQMS4O3PEbOtc6mMcGtliCQjmOecV9U1p+5NXCNhQlxCM/F+cMzRgOJdaPqhJwvCyl/315zJkq VyKIcjrzADtL+TP//oh/hgb/oUUnOOkuUQfINiH3o+CXM3znnR/TO5coNqccWsVrv1FQJR8mH8x KEYpcd9pfEgQ2m+bgYxpIYbEI07oRgz2UdcMT22Z08BNGsKxmBvHR/DiwChiqNSZ4cFObPKAykS PqyejnGiHOAcFf3f0knOFi+tvtlknwtAdRH6FgVZSOur7fk0z49yDDz6QkHoz6TXCb+X1vUs/hj +lCyHD1OSl6YqM9upezCg7mDrXTKvc4TobZ1TB7iQ5KnD9d4cDV3ZDOFENR8nP+N+fLZt+a3NIg NbkfwZv6CFtYh2iQZv2KYjKhanMxOmUb49J4XKapwhJlZ8z9u7fcZ2c7ztcO7Ma9kTYpPMc8mX8 CJz9Q== X-Received: by 2002:a05:6a00:2985:b0:842:48ae:1d6c with SMTP id d2e1a72fcca58-84f696a146emr17783044b3a.24.1786317584600; Sun, 09 Aug 2026 16:19:44 -0700 (PDT) Received: from thetis.home.local ([2606:c800:6024:2000:6f86:9ad6:671d:ec76]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84f5a58998bsm2976866b3a.55.2026.08.09.16.19.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 16:19:44 -0700 (PDT) From: tim.orling@konsulko.com To: openembedded-core@lists.openembedded.org Cc: Tim Orling Subject: [PATCH 2/3] pypi.bbclass: improve UPSTREAM_CHECK_REGEX Date: Sun, 9 Aug 2026 16:19:02 -0700 Message-ID: <20260809231901.366919-4-tim.orling@konsulko.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260809231901.366919-2-tim.orling@konsulko.com> References: <20260809231901.366919-2-tim.orling@konsulko.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 09 Aug 2026 23:19:49 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243081 From: Tim Orling UPSTREAM_CHECK_REGEX was case-sensitive, but PyPI's simple index now lists lowercase sdist filenames (e.g. gitpython-*.tar.gz) for packages whose PYPI_PACKAGE is mixed-case (e.g. GitPython). Added an (?i) inline flag so the regex matches regardless of case — this fixes AUH detection for python3-git and any other pypi.bbclass recipe hit by the same upstream lowercase-normalization trend, without needing per-recipe overrides. This will not magically fix fetching, but WILL at least mean AUH will detect more upstream releases and maintainers will see when the resulting default PYPI_SRC_URI is failing. A fix for some recipes might be to set: PYPI_SRC_URI = ""${@pypi_src_uri(d).lower()}" but it is premature to set that globally, as legacy recipes with releases before the PEP-625 normalization still exist. Signed-off-by: Tim Orling --- meta/classes-recipe/pypi.bbclass | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/classes-recipe/pypi.bbclass b/meta/classes-recipe/pypi.bbclass index bd21557c60..0897994bb6 100644 --- a/meta/classes-recipe/pypi.bbclass +++ b/meta/classes-recipe/pypi.bbclass @@ -51,7 +51,7 @@ UPSTREAM_CHECK_PYPI_PACKAGE ?= "${PYPI_PACKAGE}" # # NOTE: All URLs for the simple API MUST request canonical normalized URLs per the spec UPSTREAM_CHECK_URI ?= "https://pypi.org/simple/${@pypi_normalize(d)}/" -UPSTREAM_CHECK_REGEX ?= "${UPSTREAM_CHECK_PYPI_PACKAGE}-(?P(\d+[\.\-_]*)+).(tar\.gz|tgz|zip|tar\.bz2)" +UPSTREAM_CHECK_REGEX ?= "(?i)${UPSTREAM_CHECK_PYPI_PACKAGE}-(?P(\d+[\.\-_]*)+).(tar\.gz|tgz|zip|tar\.bz2)" CVE_PRODUCT ?= "python:${PYPI_PACKAGE}" From patchwork Sun Aug 9 23:19:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Tim Orling X-Patchwork-Id: 94825 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 254B9C5AD4E for ; Sun, 9 Aug 2026 23:19:59 +0000 (UTC) Received: from mail-pf1-f181.google.com (mail-pf1-f181.google.com [209.85.210.181]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.18646.1786317596752872502 for ; Sun, 09 Aug 2026 16:19:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=MCu9EF1S; spf=pass (domain: konsulko.com, ip: 209.85.210.181, mailfrom: tim.orling@konsulko.com) Received: by mail-pf1-f181.google.com with SMTP id d2e1a72fcca58-84862b0d5aeso1167955b3a.2 for ; Sun, 09 Aug 2026 16:19:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1786317596; x=1786922396; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=89+j0zqT17ngr3p0d56RXaLr1RgMtdRfhUB9IBsh5og=; b=MCu9EF1SGCRpy0NlZniu0HCxXzVfhviN3Motlf1UtMBEAOdnkP8BtEAD0Kp6YQHw7j rGKXPkkzgBtEzlq2x4GsPk310bdLTaZ5voE3dNofqelJtba6AWSLN9jDAka7yCFKjHzb O/nJzT0lgsiYqjFqhDmMyP6597hqOGxbFQCLM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786317596; x=1786922396; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=89+j0zqT17ngr3p0d56RXaLr1RgMtdRfhUB9IBsh5og=; b=rYE/wII8Uoe8cDnmYEgKfdKnV5FvNXWjBgX1A7jrO5eN54UPmzZsfxtpdUsboBQl3w 219WIRcRJ0e3Ja9hI69jH4t1/6T+ypO/ya4B0vlkie8N5S7Pe5oKaFm/Qzgwq0/7Mimt 5Jg/b7Fd6HQSJO25o/aetj7NxB4jvYpQctiSIjkP+kD5R4AquKoPU+ETxc1EdoUEYuRD vQPPZrafrGxt3BQXQyxxpG6bHjRV2n87ndzvI8Kp3AWYXxQve6TPjoWpRvU24QRCQTzy c1hkgHCJqte2ECq75RuNWbrtBR/eMCqrDtgCSuwGXLuJZe/qxzw8mF3OpKe34D6t3q2K IijA== X-Gm-Message-State: AOJu0YzWgaVv6E7SgGOdzewwtFIkYhrPAhv51IuEDudLKuHaCV0p8QQl /JIMzudH2kOHH3wNcFUgt2GedVTtuO/iQ+oIeJ9Qee+wm4QGap/Iv4IJYjPwLTttPJX7BOK0UvD 0Vj3w X-Gm-Gg: AR+sD12ONzZd2IXlxgHDGmD1/rklJWLSytcTU8ru6nx3sX87tQnsbmOFIxXPAODUm0d MZRdBBfRtDqAso9qWqpWFTRNFvJISQ6LQTHEU1F8vuo7veN24pEtn/f8KIR08V2HLiC9oen67hX kT9m5zHryiZZ6GEHeQqOySi3+61zE+nlqwEc4xHu8lRCrbVjzoVicUyYuVikE/y+AV8yufPmWzL DnPhmDw9f9h7djnVDGiU4UCub0+rcew/lwa3ROD59H0Iz7s0b84XGzeVhu4PvTmILWnbBWf9LKp qwtCP2PQh4W/GYxfc/8YsTWJoBiP/yq5Iny8wNs8fSFJeCvwkRFevvA0lQBjKQwM3IIFqyILg8g A3oCHgpr6O16sasS1nB2NsrkNxPVa0sTHM5ifcFy8AgxgnAY6J6c0GGJTwBXARXGf4tvYjBRlH4 gjIVvEFj/1ei9/vjWbT4yWo2baqPyMUfatxqa7spXpa6fKqiBY8sl5puVXUe39U4UXdnh1hhAKG Bk9Fw== X-Received: by 2002:a05:6a00:99c:b0:847:80f5:c616 with SMTP id d2e1a72fcca58-84f2dfc89b0mr42781918b3a.10.1786317596083; Sun, 09 Aug 2026 16:19:56 -0700 (PDT) Received: from thetis.home.local ([2606:c800:6024:2000:6f86:9ad6:671d:ec76]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84f5a58998bsm2976866b3a.55.2026.08.09.16.19.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 16:19:55 -0700 (PDT) From: tim.orling@konsulko.com To: openembedded-core@lists.openembedded.org Cc: Tim Orling Subject: [PATCH 3/3] python3-gitpython: upgrade 3.1.43 -> 3.1.58 Date: Sun, 9 Aug 2026 16:19:04 -0700 Message-ID: <20260809231901.366919-6-tim.orling@konsulko.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260809231901.366919-2-tim.orling@konsulko.com> References: <20260809231901.366919-2-tim.orling@konsulko.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 09 Aug 2026 23:19:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/243082 From: Tim Orling Upstream tarballs changed from mixed case GitPython-3.1.43.tar.gz to all lowercase gitpython-3.1.44.gz and the regex in pypi.bbclass was not catching it. Similarly, per PEP-625, the PYPI_SRC_URI since 3.1.44 needs to be lowercase. It appears the proper fix for fetching is to set PYPI_PACKAGE = "gitpython". Multiple security releases, see the change logs: https://gitpython.readthedocs.io/en/3.1.58/changes.html https://gitpython.readthedocs.io/en/3.1.57/changes.html https://gitpython.readthedocs.io/en/3.1.56/changes.html https://gitpython.readthedocs.io/en/3.1.55/changes.html https://gitpython.readthedocs.io/en/3.1.54/changes.html https://gitpython.readthedocs.io/en/3.1.53/changes.html https://gitpython.readthedocs.io/en/3.1.52/changes.html https://gitpython.readthedocs.io/en/3.1.51/changes.html CVE: CVE-2026-42215 CVE: CVE-2026-42284 CVE: CVE-2026-44243 CVE: CVE-2026-44244 To see the details of each release: https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.57 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.56 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.55 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.54 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.53 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.52 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.50 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.46 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.45 https://github.com/gitpython-developers/GitPython/releases/tag/3.1.44 For the full comparison changes (1292 commits, 201 files changed), see: https://github.com/gitpython-developers/GitPython/compare/3.1.43...3.1.58 Signed-off-by: Tim Orling --- .../python/{python3-git_3.1.43.bb => python3-git_3.1.58.bb} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename meta/recipes-devtools/python/{python3-git_3.1.43.bb => python3-git_3.1.58.bb} (90%) diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.58.bb similarity index 90% rename from meta/recipes-devtools/python/python3-git_3.1.43.bb rename to meta/recipes-devtools/python/python3-git_3.1.58.bb index ccf6def292..82c8076a97 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.58.bb @@ -8,13 +8,13 @@ SECTION = "devel/python" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e" -PYPI_PACKAGE = "GitPython" +PYPI_PACKAGE = "gitpython" CVE_PRODUCT = "gitpython_project:gitpython" inherit pypi python_setuptools_build_meta -SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c" +SRC_URI[sha256sum] = "621416df10ef3fd0e19fabf9172ddeed0fa704d353d04f194eec56a625a95b22" DEPENDS += " python3-gitdb"