<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>13111</bug_id>
          
          <creation_ts>2018-12-31 01:18:38 +0000</creation_ts>
          <short_desc>Connect SRTool to YP Bugzilla</short_desc>
          <delta_ts>2024-05-09 16:56:48 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>6</classification_id>
          <classification>Yocto Project Subprojects</classification>
          <product>Security Response Tool</product>
          <component>General</component>
          <version>2.7</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>5.0 M4</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="David Reyna">david.reyna</reporter>
          <assigned_to name="David Reyna">david.reyna</assigned_to>
          <cc>akuster</cc>
    
    <cc>david.reyna</cc>
    
    <cc>randy.macleod</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>82629</commentid>
    <comment_count>0</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2018-12-31 01:18:38 +0000</bug_when>
    <thetext>The &quot;bin/yp/srtool_defect.py&quot; needs to be updated to connect the SRTool to the CVEs in YP Bugzilla.

* The &quot;init&quot; function should be able to find existing CVE-related bugs, and then instantiate &quot;Vulnerabilities&quot; and &quot;Investigations&quot; accordingly.

* Similarly, the &quot;update&quot; function should be able to update the respective defect status in the SRTool database.

* The tool should also instantiate the defect creation feature.

An example of a Jira integration script can be found in &quot;bin/acme/srtool_jira.sh&quot;.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>83080</commentid>
    <comment_count>1</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2019-02-21 20:03:47 +0000</bug_when>
    <thetext>Here is some added context.

This enhancement is about Yocto Project&apos;s desired implementation of the SRtool.

The basic implementation would be to simply track the status of CVEs in the Yocto Project code base. The data can be dynamically derived from Bugzilla defects (as per this case) and/or from data supplied by partner companies. From this, Yocto Project could generate reports and tables.

The next level of implementation would be to proactively track incoming CVEs and capture their potential impact on Yocto Project. The potential vulnerabilities can then be shared with the partner companies for assistance with the response.

The full implementation would be to use the incoming data to proactively create Yocto Project defects to track and resolve critical and common vulnerabilities.

- David</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>86147</commentid>
    <comment_count>2</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2020-01-29 16:35:41 +0000</bug_when>
    <thetext>Assigning to David so this isn&apos;t lost, but I won&apos;t be working on this any time soon.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>98989</commentid>
    <comment_count>3</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2024-05-09 16:56:48 +0000</bug_when>
    <thetext>This will not be done until a mandate exists and is scheduled. At that time we can open a new case.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>