Traceability and CVE ManagementΒΆ
Traceability in Bunker-Centric Architecture (BCA) covers the full software supply chain spanning both the Bunker OS and the Open World. Because these environments are built as separate Yocto targets with different purposes and content, Software Bills of Materials (SBOMs), CVE reports, and Vulnerability Exploitability eXchange (VEX) artefacts must be collected and managed for each independently, then consolidated at the project level for compliance reporting.
Regulatory RequirementsΒΆ
Traceability is mandated by emerging regulations:
EU Cyber Resilience Act (CRA): Requires transparent disclosure of software components and documented vulnerability management, especially for interconnected products
IEC 62443 (Industrial Automation Security): Mandates software component transparency and patch management processes
NIST Supply Chain Security (SSDF): Requires software provenance and vulnerability tracking
For production deployments, generating complete, actionable traceability artefacts at build time is not optional.
Workflow OverviewΒΆ
The traceability workflow consists of three phases:
graph TD
A["Yocto Build<br/>(Bunker OS + Open World)"] -->|"OE_FRAGMENTS"| P["core/yocto/sbom-cve-check fragment"]
P --> C["CVE report<br/>(*.sbom-cve-check.yocto.json)"]
P --> G["Enriched SPDX<br/>(*.sbom-cve-check.spdx.json)"]
C -->|"Decision & annotation<br/>(sbom-cve-review)"| D["VEX decisions + justifications"]
D -->|"Export BitBake metadata"| E["CVE_STATUS entries in recipes"]
D -->|"Compliance reporting"| F["SBOM + CVE + VEX bundle"]
G -->|"Compliance reporting"| F
E -->|"Apply to recipes"| A
- Phase 1: SBOM + CVE generation (
core/yocto/sbom-cve-checkfragment) A single fragment activates the entire pipeline. It adds
create-spdx(which generates the SPDX SBOM) as a dependency, keeps the CVE databases current viaSRCREV = AUTOREV, and runssbom-cve-checkto produce two outputs: a CVE report (*.sbom-cve-check.yocto.json) and an enriched SPDX document (*.sbom-cve-check.spdx.json). All BCA reference designs adopt this fragment from Yocto Scarthgap onwards.- Phase 2: VEX Decision & Export
Use
sbom-cve-reviewto review unpatched CVEs, record decisions with justifications, and exportCVE_STATUSentries back into your recipes. This creates an audit trail suitable for regulatory submission.
Key ToolsΒΆ
Yocto SBOM Generation:
sbom-cve-checkclass, adopted in all BCA reference designs from Yocto 5 (Scarthgap) onwardsVulnerability Data: Cross-references the NVD and CVE feeds automatically
Decision Management:
sbom-cve-review(GUI and CLI for reviewing CVEs and recording decisions)Metadata Export:
sbom-cve-reviewexports decisions asCVE_STATUSentries for BitBake recipes
In this SectionΒΆ
SBOM Generation and CVE Analysis β How to enable the
core/yocto/sbom-cve-checkfragment, what it produces, and how to verify and archive the SBOM and CVE report artefacts for each image.VEX Decisions and Compliance Export β How to use
sbom-cve-reviewto record engineering decisions, exportCVE_STATUSentries back into recipes, and assemble a compliance-ready SBOM + CVE + VEX bundle.