|
|
|
|
|
by Coi-l
486 days ago
|
|
May I ask what you recommend? Since it is easy for me I prefer the Yocto SBOM, but the security side forces blackduck binary scanning on us which while finding most things on the binary constantly misidentifies a lot of versions, resulting in a lot of manual work. It also does not know which patches Yocto has applied for fixing CVEs. And none of these can figure out what is in the kernel and therefor triggers an ungodly amount of CVEs in parts of the kernel we don't have compiled in. |
|