[yocto] cve-checker tool

Patrick Ohly patrick.ohly at intel.com
Fri Oct 28 10:08:44 PDT 2016


On Fri, 2016-10-28 at 09:28 -0500, Mariano Lopez wrote:
> 
> On 10/27/2016 06:03 AM, Sona Sarmadi wrote:
> >> Can this tool be used together with "meta-security-isafw" and get a fancy
> >> report?
> 
> When I was working on this it was the transition to python3 so, 
> meta-security-isafw didn't behave as expected.

It does now.

>  To be honest I haven't 
> checked again but it will be a good test. I'll try to do this during the 
> weekend.

meta-security-isafw has its own support for generating CVE reports, for
example in the XMLunit format. Here's an example how Jenkins displays
that:
https://ostroproject.org/jenkins/view/Code-Analysis/job/code_isafw_reports/checker=cve,label=coordinator,machine=beaglebone/lastCompletedBuild/testReport/

-- 
Best Regards, Patrick Ohly

The content of this message is my personal opinion only and although
I am an employee of Intel, the statements I make here in no way
represent Intel's position on the issue, nor am I authorized to speak
on behalf of Intel on this matter.






More information about the yocto mailing list