Der Yocto Project Workshop ist ein Treffpunkt für Ingenieur:innen, Open-Source-Technolog:innen, Studierende und Akademiker:innen aus dem OSS-Bereich. Der Fokus liegt auf dem Präsentieren, Diskutieren und Zusammenarbeiten bezüglich aller Themen in und um das erweiterte Yocto-Project-Ökosystem. Die Inhalte sind frei gestaltet und bieten einen interaktiven Wissens- und Erfahrungsaustausch.
Wir freuen uns sehr, dass unsere Kollegin Anna-Lena Marx mit ihrem Vortrag CVE-Monitoring in GitLab CI – Ideas, Chances and Challenges vertreten sein wird.
Abstract:
By now, most Yocto developers are aware of the requirements and challenges the Cyber Resilience Act (CRA) will bring. Yocto already provides mechanisms to address them, and basic CVE monitoring is deeply embedded into the system with sbom-cve-check.
However, a CRA-compatible CVE monitoring and management lifecycle for products in the field requires more sophisticated workflows. We need to continuously store, version, and manage SBoMs to regularly scan released products against updated vulnerability databases and identify critical security issues.
In this talk, I will present a manageable, technical approach to tackle this workflow using VulnScout and GitLab CI targeting small to mid-sized companies. We will dive into the practical challenges of setting up this CI environment in a downstream project. Key topics include the automated management of SBoM artifacts, the requirements for continuously scanning all released versions of a product, what already works well, and ideas on where to go from here.
This talk does not aim to present a perfect, ready-to-go master template for every use case – such a setup is likely rather individual and not trivial on an organizational level. Instead, it serves as a technical starting point for smaller projects and aims to open up a discussion on ideas, chances, and ongoing challenges in automated CVE monitoring.