| Summary: | CVE management not documented | ||
|---|---|---|---|
| Product: | [Documentation] Development Manual | Reporter: | Michael Opdenacker <michael.opdenacker> |
| Component: | development | Assignee: | Michael Opdenacker <michael.opdenacker> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium+ | CC: | michael.opdenacker, randy.macleod, richard.purdie |
| Version: | unspecified | ||
| Target Milestone: | 3.4 M3 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | Yes (doc changes required) | |
|
Description
Michael Opdenacker
2021-06-02 14:30:19 UTC
Add: INHERIT += "cve-check" to the configuration, then you can check CVE status with commands like: bitbake -c cve_check groff python3 qemu rpm wget We have a common include file to remove "known" CVE issues which can be included with: bitbake -c cve_check groff -R conf/distro/include/cve-extra-exclusions.inc CVE_PRODUCT defines the name used to match the recipe against the upstream NIST CVE database. The CVE database is created by a recipe and stored in DL_DIR. You can look inside it using sqlite3, e.g.: sqlite3 nvdcve_1.1.db .dump | grep CVE-2000-0803 Thanks for the input! I'm think about documenting this in the Dev Manual, after license management (https://docs.yoctoproject.org/dev-manual/common-tasks.html#working-with-licenses). A probably basic question here... I added "wget" (which currently has an unpatched CVE) to my image. How can I look for CVEs in all the packages included in my image? Are there any further recommendations for managing CVEs in a production project, like running the cve-check command daily on a cronjob or any better idea? Thanks in advance Michael. Found my own answer for the packages included in my image. If "cve-check" is added to the configuration, unresolved CVEs will be displayed for the packages built by BitBake. However, I'm still interested in thoughts about checking production images for vulnerability checks. Anything better than manual or cronjob checks? Thank you in advance Michael. Another question though: How to check for vulnerabilities in my image without regenerating it, and without runing "bitbake -c cve_check" on individual package names? Thanks in advance Ultimately we will generate an SBOM/manifest with the image and it would be good if we could run a new check of that manifest against the CVEs. That isn't currently implemented but should be and should perhaps be a new bug? Thanks for the advice! I was about to open a new bug, but then I found this one: https://bugzilla.yoctoproject.org/show_bug.cgi?id=8682 Could what's implemented in meta-security be a satisfactory solution, or would it be good to have a simpler one just for CVE checking? I think we'd need something specific for the CVE check and our manifests Thanks. I created the new bug on https://bugzilla.yoctoproject.org/show_bug.cgi?id=14495 My documentation patch is on its way to master. I'll be able to close this bug soon :) |