| Summary: | Connect SRTool to YP Bugzilla | ||
|---|---|---|---|
| Product: | [Yocto Project Subprojects] Security Response Tool | Reporter: | David Reyna <david.reyna> |
| Component: | General | Assignee: | David Reyna <david.reyna> |
| Status: | RESOLVED WONTFIX | QA Contact: | |
| Severity: | enhancement | ||
| Priority: | Medium | CC: | akuster, david.reyna, randy.macleod |
| Version: | 2.7 | ||
| Target Milestone: | 5.0 M4 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
David Reyna
2018-12-31 01:18:38 UTC
Here is some added context. This enhancement is about Yocto Project's desired implementation of the SRtool. The basic implementation would be to simply track the status of CVEs in the Yocto Project code base. The data can be dynamically derived from Bugzilla defects (as per this case) and/or from data supplied by partner companies. From this, Yocto Project could generate reports and tables. The next level of implementation would be to proactively track incoming CVEs and capture their potential impact on Yocto Project. The potential vulnerabilities can then be shared with the partner companies for assistance with the response. The full implementation would be to use the incoming data to proactively create Yocto Project defects to track and resolve critical and common vulnerabilities. - David Assigning to David so this isn't lost, but I won't be working on this any time soon. This will not be done until a mandate exists and is scheduled. At that time we can open a new case. |