<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git/meta-python/recipes-devtools/python/python3-tornado_6.5.4.bb, branch wrynose</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=wrynose</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=wrynose'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2026-03-18T21:33:29+00:00</updated>
<entry>
<title>python3-tornado: upgrade 6.5.4 -&gt; 6.5.5</title>
<updated>2026-03-18T21:33:29+00:00</updated>
<author>
<name>Ankur Tyagi</name>
<email>ankur.tyagi85@gmail.com</email>
</author>
<published>2026-03-16T20:20:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=cdb5d4c3e78f259bdd24155293fb09d6d748ac9c'/>
<id>urn:sha1:cdb5d4c3e78f259bdd24155293fb09d6d748ac9c</id>
<content type='text'>
Security fixes including CVE-2026-31958

https://www.tornadoweb.org/en/stable/releases/v6.5.5.html

Signed-off-by: Ankur Tyagi &lt;ankur.tyagi85@gmail.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
<entry>
<title>python3-tornado: set CVE_PRODUCT</title>
<updated>2025-12-31T16:28:51+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2025-12-30T12:24:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=139cc15de304918edc0197346579162b12006faa'/>
<id>urn:sha1:139cc15de304918edc0197346579162b12006faa</id>
<content type='text'>
The default "python:tornado" CVE_PRODUCT doesn't match relevant CVEs, because
the project's CPE is "tornadoweb:tornado".

See cve db query (docmosis is an irrelevant vendor):

sqlite&gt; select * from products where PRODUCT = 'tornado';
CVE-2012-2374|tornadoweb|tornado|||2.2|&lt;=
CVE-2012-2374|tornadoweb|tornado|1.0|=||
CVE-2012-2374|tornadoweb|tornado|1.0.1|=||
CVE-2012-2374|tornadoweb|tornado|1.1|=||
CVE-2012-2374|tornadoweb|tornado|1.1.1|=||
CVE-2012-2374|tornadoweb|tornado|1.2|=||
CVE-2012-2374|tornadoweb|tornado|1.2.1|=||
CVE-2012-2374|tornadoweb|tornado|2.0|=||
CVE-2012-2374|tornadoweb|tornado|2.1|=||
CVE-2012-2374|tornadoweb|tornado|2.1.1|=||
CVE-2014-9720|tornadoweb|tornado|||3.2.2|&lt;
CVE-2023-25264|docmosis|tornado|||2.9.5|&lt;
CVE-2023-25265|docmosis|tornado|||2.9.5|&lt;
CVE-2023-25266|docmosis|tornado|||2.9.5|&lt;
CVE-2023-28370|tornadoweb|tornado|||6.3.2|&lt;
CVE-2024-42733|docmosis|tornado|||2.9.7|&lt;=
CVE-2024-52804|tornadoweb|tornado|||6.4.2|&lt;
CVE-2025-47287|tornadoweb|tornado|||6.5.0|&lt;
CVE-2025-67724|tornadoweb|tornado|||6.5.3|&lt;
CVE-2025-67725|tornadoweb|tornado|||6.5.3|&lt;
CVE-2025-67726|tornadoweb|tornado|||6.5.3|&lt;

Set the CVE_PRODUCT accordingly.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
<entry>
<title>python3-tornado: upgrade 6.5.3 -&gt; 6.5.4</title>
<updated>2025-12-24T21:18:29+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2025-12-24T09:13:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=ebca0ae79d15c5d5f1489a8b5de18c810891e7e4'/>
<id>urn:sha1:ebca0ae79d15c5d5f1489a8b5de18c810891e7e4</id>
<content type='text'>
Bug fixes
~~~~~~~~~
- The "in" operator for "HTTPHeaders" was incorrectly case-sensitive, causing
  lookups to fail for headers with different casing than the original header name.
  This was a regression in version 6.5.3 and has been fixed to restore the intended
  case-insensitive behavior from version 6.5.2 and earlier.

Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
</feed>
