Lecture

From Firmware Build to CRA Evidence: A Reproducible SBOM and Vulnerability Workflow

  • at -
  • Hall C5C5.100
  • Language: English
  • Type: Lecture

Lecture description

Demonstrates a vendor-neutral workflow from a Zephyr firmware build to reviewable CRA evidence: producing an SPDX inventory and build provenance, mapping vulnerability records, recording VEX-based decisions, and gating releases with a policy check, covering common embedded failure modes and a checklist for CI/CD integration.