Главная
Study mode:
on
1
Intro
2
Yocto Project and OpenEmbedded
3
Why is the Software Supply Chain Important?
4
Addressing The Supply Chain
5
Build Images from Source Code
6
Simplified Build Flow
7
What is an SBOM?
8
Recipe Metadata
9
SBOM Relationships
10
Enabling SPDX Generation
11
Future Improvements
12
Why do we need reproducible builds?
13
Binary output should associate with recipe hashes
14
Tracing target images back to recipe outputs
15
Reproducibility Testing
16
Extending Quality Assurance Test
17
CVE Tracking from Yocto Project
18
CVE Metrics
19
Buildtools replaces Host tools
20
Using Buildtools to extend the Supply Chain
Description:
Explore the Yocto Project's approach to software supply chain management in this 32-minute conference talk by Joshua Watt from Garmin. Delve into the importance of software supply chains and learn how Yocto Project addresses key concerns. Discover the process of building images from source code, understand the concept of Software Bill of Materials (SBOM), and examine recipe metadata and SBOM relationships. Gain insights into enabling SPDX generation and future improvements in the pipeline. Investigate the significance of reproducible builds, binary output association with recipe hashes, and tracing target images. Learn about reproducibility testing, extending quality assurance tests, and CVE tracking within the Yocto Project. Explore CVE metrics and how buildtools replace host tools to extend the supply chain.

Software Supply Chain with the Yocto Project

Linux Foundation
Add to list