Vortrag
From Firmware Build to CRA Evidence: A Reproducible SBOM and Vulnerability Workflow
- von -
- Halle C5C5.100
- Sprache: Englisch
- Vortragstyp: Vortrag
Vortragsbeschreibung
Demonstrates a vendor-neutral workflow from a Zephyr firmware build to reviewable CRA evidence: producing an SPDX inventory and build provenance, mapping vulnerability records, recording VEX-based decisions, and gating releases with a policy check, covering common embedded failure modes and a checklist for CI/CD integration.