Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] RFC: CVE analysis
@ 2014-09-22 20:21 Matthew Weber
  2014-09-22 20:38 ` Gustavo Zacarias
  0 siblings, 1 reply; 6+ messages in thread
From: Matthew Weber @ 2014-09-22 20:21 UTC (permalink / raw)
  To: buildroot

I was curious if anyone has done a script similar to the "make legal-info"
that takes a package list and checks it against a CVE database?  We're
looking at doing some automated tracking of vulnerabilities with our
nightly builds and were at a point of putting something together.

It might also be an interesting feature to expose on the Buildroot
website.... maybe listing the current vulnerabilities of the last release
and the current tip?

-- 
Matthew L Weber / Pr Software Engineer
Airborne Information Systems / Security Systems and Software
MS 131-100, C Ave NE, Cedar Rapids, IA, 52498, USA
www.rockwellcollins.com

Note: Any Export License Required Information and License Restricted Third
Party Intellectual Property (TPIP) content must be encrypted and sent to
matthew.weber at corp.rockwellcollins.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.busybox.net/pipermail/buildroot/attachments/20140922/758ccf5c/attachment.html>

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2014-09-23 22:50 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-09-22 20:21 [Buildroot] RFC: CVE analysis Matthew Weber
2014-09-22 20:38 ` Gustavo Zacarias
2014-09-22 21:12   ` Matthew Weber
2014-09-23  7:43     ` Thomas Petazzoni
2014-09-23 22:06   ` Joshua Kinard
2014-09-23 22:50     ` Matthew Weber

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox