diff options
| author | Tim Orling <ticotimo@gmail.com> | 2023-12-08 17:40:04 -0800 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2023-12-09 19:17:11 +0000 |
| commit | 78ef0313ee6add0301d866074c4b4a23dbefd757 (patch) | |
| tree | e265fe48ab764aac1d7ab5d3558f680c12fb24cd /meta/classes-global | |
| parent | 95c187e54e2d2d134c1f9a4b97a400c961bc9bba (diff) | |
| download | poky-78ef0313ee6add0301d866074c4b4a23dbefd757.tar.gz | |
recipetool: pypi: do not clobber SRC_URI checksums
The pypi change:
"85a2a6f68af recipetool: create_buildsys_python: add pypi support"
deleted all the SRC_URI variables, including the SRC_URI checksums.
These are not generated by the pypi.bbclass (how could they be trusted?)
Without the checksum(s), we are vulnerable to a man-in-the-middle attack
and zero checks on the validity of the downloaded tarball from pypi.org.
Fix by only setting S and SRC_URI to None.
(From OE-Core rev: 560181a52111569f7bc57b09139b42510e0d0325)
Signed-off-by: Tim Orling <tim.orling@konsulko.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/classes-global')
0 files changed, 0 insertions, 0 deletions
