* [RESEND] Is it possible to correlate CVEs with packages instead of recipes?
@ 2026-07-23 15:34 Hiago De Franco
0 siblings, 0 replies; only message in thread
From: Hiago De Franco @ 2026-07-23 15:34 UTC (permalink / raw)
To: yocto; +Cc: yocto-security
[Resending since I was not subscribed to the lists, sorry]
Hello all,
I am working with a project with Yocto Wrynose. By checking all the
RPM packages installed into the OS build with Yocto I would like to
check which CVEs affects this image and which binary packages are being
affected.
Yocto here is being used to serve the RPM packages to the image, after a
'bitbake world'. Since Yocto lists the CVEs per recipe, they all apply
to all binary packages generated by the same recipe.
Example: 'openssl' produces 'libcrypto', 'libssl', 'openssl-conf', etc.,
and they all have the same affected CVEs duplicaded by each package in
my image.
I was not able to find a good way to deduplicate the CVEs or to check
which package produced by that recipe is being affected. Has anybody
faced the same issue before or have any suggestions for this duplication
problem with all the recipe CVEs?
Best regards,
Hiago.
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-07-23 15:34 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-23 15:34 [RESEND] Is it possible to correlate CVEs with packages instead of recipes? Hiago De Franco
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox