All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE Scanners and Package Version
@ 2023-12-23 10:47 fabian.hanke
  2023-12-24  9:24 ` [yocto] " Richard Purdie
  2024-01-02  7:24 ` Mikko Rapeli
  0 siblings, 2 replies; 9+ messages in thread
From: fabian.hanke @ 2023-12-23 10:47 UTC (permalink / raw)
  To: yocto

[-- Attachment #1: Type: text/plain, Size: 1419 bytes --]

Hello Yocto community,

we must provide a SBOM for our Yocto based product which will then be used for (internal) CVE scanning by the security department. Generating the base document in cycloneDX format is fairly easy (thanks to the nature of Yocto).

But we do not know how to include information about CVE patches for each package in the document. Not providing these, will cause a lot of “false” feedback on CVEs for specific versions which are already patched (but version number did not change). This problem was also mentioned a few days ago in the presentation from David Reyna: https://youtu.be/PegU1G1bA80?t=1127. I like the proposed solution of adding a vendor specific string to the package version. But I'm still wondering: How would the CVE scanner vendor know which CVEs are included in a yocto specific version and which are not?

I hope this is the correct place to start a discussion (if not please point me to the correct place):

Does anyone else also have the same problem with false feedback from CVE scanners? How do you deal with it?

Best regards, Fabian Hanke

----------------------------------

Bosch Rexroth AG

Registered Office: Stuttgart, Registration Court: Amtsgericht Stuttgart HRB 23192 Executive Board: Dr. Steffen Haack (President), Roland Bittenauer, Thomas Fechner, Holger von Hebel, Reinhard Schäfer Chairman of the Supervisory Board: Dr. Markus Forschner

[-- Attachment #2: Type: text/html, Size: 1880 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2024-01-12  8:03 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-12-23 10:47 CVE Scanners and Package Version fabian.hanke
2023-12-24  9:24 ` [yocto] " Richard Purdie
2023-12-24  9:42   ` Vincent Prince
2024-01-02  7:24 ` Mikko Rapeli
2024-01-02 21:46   ` adrian.freihofer
2024-01-03  7:41     ` Mikko Rapeli
2024-01-03 16:54       ` Hanke Fabian (DC/PAR)
2024-01-04 13:49     ` Marta Rybczynska
2024-01-12  8:03       ` adrian.freihofer

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.