Vortrag

From Firmware Build to CRA Evidence: A Reproducible SBOM and Vulnerability Workflow

  • von -
  • Halle C5C5.100
  • Sprache: Englisch
  • Vortragstyp: Vortrag

Vortragsbeschreibung

Demonstrates a vendor-neutral workflow from a Zephyr firmware build to reviewable CRA evidence: producing an SPDX inventory and build provenance, mapping vulnerability records, recording VEX-based decisions, and gating releases with a policy check, covering common embedded failure modes and a checklist for CI/CD integration.