Lecture
From Firmware Build to CRA Evidence: A Reproducible SBOM and Vulnerability Workflow
- at -
- Hall C5C5.100
- Language: English
- Type: Lecture
Lecture description
Demonstrates a vendor-neutral workflow from a Zephyr firmware build to reviewable CRA evidence: producing an SPDX inventory and build provenance, mapping vulnerability records, recording VEX-based decisions, and gating releases with a policy check, covering common embedded failure modes and a checklist for CI/CD integration.