diff --git a/app-forensics/yara/metadata.xml b/app-forensics/yara/metadata.xml
index d98a389725d03..e0c4ac4ff2836 100644
--- a/app-forensics/yara/metadata.xml
+++ b/app-forensics/yara/metadata.xml
@@ -22,6 +22,7 @@
Enable macho module
Enable magic module
Enable rules profiling
+ Pulls in python binding via dev-python/yara-python
VirusTotal/yara
diff --git a/app-forensics/yara/yara-4.1.3.ebuild b/app-forensics/yara/yara-4.1.3.ebuild
index ffb30cc26e3a8..0e064fd15d7bc 100644
--- a/app-forensics/yara/yara-4.1.3.ebuild
+++ b/app-forensics/yara/yara-4.1.3.ebuild
@@ -12,7 +12,7 @@ SRC_URI="https://github.com/virustotal/yara/archive/v${PV}.tar.gz -> ${P}.tar.gz
LICENSE="Apache-2.0"
SLOT="0"
KEYWORDS="~amd64 ~x86"
-IUSE="+dex +dotnet +cuckoo +macho +magic profiling"
+IUSE="+dex +dotnet +cuckoo +macho +magic profiling python"
DEPEND="
dev-libs/openssl:0=
@@ -20,6 +20,7 @@ DEPEND="
magic? ( sys-apps/file:0= )
"
RDEPEND="${DEPEND}"
+PDEPEND="python? ( =dev-python/yara-python-4* )"
src_prepare() {
default
diff --git a/app-forensics/yara/yara-4.2.0_rc1.ebuild b/app-forensics/yara/yara-4.2.0_rc1.ebuild
index 38659ddcaa364..a514ff8e46905 100644
--- a/app-forensics/yara/yara-4.2.0_rc1.ebuild
+++ b/app-forensics/yara/yara-4.2.0_rc1.ebuild
@@ -12,7 +12,7 @@ SRC_URI="https://github.com/virustotal/yara/archive/v${PV/_/-}.tar.gz -> ${P}.ta
LICENSE="Apache-2.0"
SLOT="0"
KEYWORDS=""
-IUSE="+dex +dotnet +cuckoo +macho +magic profiling"
+IUSE="+dex +dotnet +cuckoo +macho +magic profiling python"
DEPEND="
dev-libs/openssl:0=
@@ -20,6 +20,7 @@ DEPEND="
magic? ( sys-apps/file:0= )
"
RDEPEND="${DEPEND}"
+PDEPEND="python? ( =dev-python/yara-python-4* )"
S="${WORKDIR}/${PN}-${PV/_/-}"
diff --git a/dev-python/yara-python/Manifest b/dev-python/yara-python/Manifest
new file mode 100644
index 0000000000000..eaf58cf3e4457
--- /dev/null
+++ b/dev-python/yara-python/Manifest
@@ -0,0 +1 @@
+DIST yara-python-4.1.3.tar.gz 33712 BLAKE2B 7878d12620f2834578c98a99bc259422d8ac54efc04ebd29ffa604c15b0462607ce950b3e19f8e80db07195e61dedb4efc8c2ffb18a0c5de0bf2755fe62776d1 SHA512 9c96ae78df7694dd55b8bdde4fad49043f120b94477fa9d7090610665072626eba4fa410cd9292205e0b18bb9f384f07288c0340232e163294b91051b84dcab2
diff --git a/dev-python/yara-python/metadata.xml b/dev-python/yara-python/metadata.xml
new file mode 100644
index 0000000000000..05c387a64124f
--- /dev/null
+++ b/dev-python/yara-python/metadata.xml
@@ -0,0 +1,20 @@
+
+
+
+
+ mario.haustein@hrz.tu-chemnitz.de
+ Mario Haustein
+
+
+ sam@gentoo.org
+ Sam James
+
+
+ With this library you can use YARA from your Python programs. It covers
+ all YARA's features, from compiling, saving and loading rules to
+ scanning files, strings and processes.
+
+
+ VirusTotal/yara-python
+
+
diff --git a/dev-python/yara-python/yara-python-4.1.3.ebuild b/dev-python/yara-python/yara-python-4.1.3.ebuild
new file mode 100644
index 0000000000000..54194680cc20f
--- /dev/null
+++ b/dev-python/yara-python/yara-python-4.1.3.ebuild
@@ -0,0 +1,27 @@
+# Copyright 1999-2022 Gentoo Authors
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=8
+
+PYTHON_COMPAT=( python3_{8..10} )
+
+inherit distutils-r1
+
+DESCRIPTION="Python interface for a malware identification and classification tool"
+HOMEPAGE="https://github.com/VirusTotal/yara-python"
+SRC_URI="https://github.com/virustotal/yara-python/archive/v${PV}.tar.gz -> ${P}.tar.gz"
+
+LICENSE="Apache-2.0"
+SLOT="0"
+KEYWORDS="~amd64 ~x86"
+
+RDEPEND="${PYTHON_DEPS}
+ =app-forensics/yara-4.1*"
+DEPEND="${RDEPEND}"
+
+src_compile() {
+ compile_python() {
+ distutils-r1_python_compile --dynamic-linking
+ }
+ python_foreach_impl compile_python
+}