From: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
To: buildroot@busybox.net
Subject: [Buildroot] RFC: CVE analysis
Date: Tue, 23 Sep 2014 09:43:00 +0200 [thread overview]
Message-ID: <20140923094300.01862ed4@free-electrons.com> (raw)
In-Reply-To: <CANQCQpZBHb4kSvP2FRgLEzAE+LmUxaLaE5-C+PCytUUGDzBLnQ@mail.gmail.com>
Dear Matthew Weber,
On Mon, 22 Sep 2014 16:12:56 -0500, Matthew Weber wrote:
> >> I was curious if anyone has done a script similar to the "make
> >> legal-info" that takes a package list and checks it against a CVE
> >> database? We're looking at doing some automated tracking of
> >> vulnerabilities with our nightly builds and were at a point of putting
> >> something together.
Seems really interesting.
> Would it be worth using this also to document if a package needs
> updating but hasn't been updated. Then this could be queried as part
> of the build (make cve-info) to generate a summary instead of a
> Internet CVE database query. It would require some automation work to
> generate a patch to the list to append to that file that a new CVE was
> issued against it though..... guessing doing that manually isn't
> realistic.
It's probably worth mentioning
http://patchwork.ozlabs.org/patch/337267/: it's a Python script that
checks whether a package has new versions available. It's not written
with security/CVEs in mind, but you might find it interesting, and
maybe plug some more security/CVEs oriented checks in there.
That's a script we need to review/test and then commit, as I believe it
would be very useful to have. The aim is to use it as a replacement of
support/scripts/pkg-stats, whose output is updated every day at
http://autobuild.buildroot.org/stats/.
Best regards,
Thomas
--
Thomas Petazzoni, CTO, Free Electrons
Embedded Linux, Kernel and Android engineering
http://free-electrons.com
next prev parent reply other threads:[~2014-09-23 7:43 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-22 20:21 [Buildroot] RFC: CVE analysis Matthew Weber
2014-09-22 20:38 ` Gustavo Zacarias
2014-09-22 21:12 ` Matthew Weber
2014-09-23 7:43 ` Thomas Petazzoni [this message]
2014-09-23 22:06 ` Joshua Kinard
2014-09-23 22:50 ` Matthew Weber
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140923094300.01862ed4@free-electrons.com \
--to=thomas.petazzoni@free-electrons.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox