[meta-python][PATCH] python3-twitter: correct Tweepy CVE_PRODUCT mapping

"Devansh Patel -X (devanshp - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Devansh Patel <[email protected]>

The product-only "tweepy" value emits a wildcard-vendor identity and
hides the distinct NVD identities assigned to the packaged Tweepy source.

Use "josh_roesslein:tweepy" for its NVD dictionary CPE and
"tweepy:tweepy" for the NVD configuration-only identity. With
sbom-cve-check 1.3.3 and the pinned database snapshots, the generated
product identity changes; the current CVE report is unchanged.

Signed-off-by: Devansh Patel <[email protected]>
---
 meta-python/recipes-devtools/python/python3-twitter_4.17.0.bb | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/meta-python/recipes-devtools/python/python3-twitter_4.17.0.bb b/meta-python/recipes-devtools/python/python3-twitter_4.17.0.bb
index 5386e90d42..6f9c886c35 100644
--- a/meta-python/recipes-devtools/python/python3-twitter_4.17.0.bb
+++ b/meta-python/recipes-devtools/python/python3-twitter_4.17.0.bb
@@ -18,5 +18,5 @@ RDEPENDS:${PN} += "\
     python3-six \
 "
 
-CVE_PRODUCT = "tweepy"
+CVE_PRODUCT = "josh_roesslein:tweepy tweepy:tweepy"
 CVE_STATUS[CVE-2012-5825] = "fixed-version: The vulnerability has been fixed since v3.1.0"
-- 
2.35.6
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.