[yocto] Security updates question

Brian Smucker bds at bsmucker.eu.org
Fri Sep 7 13:17:24 PDT 2018


Hello all,

We have a device whose image is built using an older yocto image. It is 
based on yocto Danny, if I recall correctly.

How do users of yocto handle the need occasionally to update one or more 
component packages to deal with security vulnerabilities?

I am not a yocto expert and I was hoping there would be a clear way 
forward here.

Migrating all our recipes to the latest version of yocto probably should 
be done, but it would involve weeks of pain. I know, I started to do it 
sometime back.

So that is one option, but a very unattractive one at the moment.

When we jumped into using Yocto, I was hoping that there would be a 
clear answer to this, but I have been frustrated. Perhaps there is a 
clear answer, but it's outside of what I know.

What are my options and the tradeoffs of each?

Thanks

Brian


More information about the yocto mailing list