CVE Triage, CVE Checker Analysis, and Vendor PR in Yocto Project Security - YPS 2023.11
Offered By: Yocto Project via YouTube
Course Description
Overview
Explore a comprehensive presentation on CVE management and security initiatives within the Yocto Project ecosystem. Learn about the Security Response Tool (SRTool) and its role in CVE triage, as well as new proposals to address staffing challenges in this critical process. Discover recent enhancements to SRTool that integrate with Yocto Project's CVE Checker tool, improving analysis capabilities. Delve into the community-wide issue of CVE scanners not recognizing patched packages when version numbers remain unchanged, and examine potential solutions, including the proposed "vendor_pr" system. Gain valuable insights into improving security practices and addressing misconceptions about Yocto Project's security posture.
Syllabus
YPS 2023.11 - 2023/11/30 - David Reyna - CVE Triage, CVE Checker analysis, and “vendor_pr"
Taught by
Yocto Project
Related Courses
The Foundations of CybersecurityUniversity System of Georgia via Coursera Introduction to Cybersecurity
SecurityScoreCard via Udacity TOTAL: CompTIA CySA+ Cybersecurity Analyst (CS0-003)
Udemy Fundamentals of Internet Security | Secure Your Environment
Udemy Ciberseguridad en linea
Udemy