Traceability and CVE ManagementΒΆ

Traceability in Bunker-Centric Architecture (BCA) covers the full software supply chain spanning both the Bunker OS and the Open World. Because these environments are built as separate Yocto targets with different purposes and content, Software Bills of Materials (SBOMs), CVE reports, and Vulnerability Exploitability eXchange (VEX) artefacts must be collected and managed for each independently, then consolidated at the project level for compliance reporting.

Regulatory RequirementsΒΆ

Traceability is mandated by emerging regulations:

  • EU Cyber Resilience Act (CRA): Requires transparent disclosure of software components and documented vulnerability management, especially for interconnected products

  • IEC 62443 (Industrial Automation Security): Mandates software component transparency and patch management processes

  • NIST Supply Chain Security (SSDF): Requires software provenance and vulnerability tracking

For production deployments, generating complete, actionable traceability artefacts at build time is not optional.

Workflow OverviewΒΆ

The traceability workflow consists of three phases:

        graph TD
    A["Yocto Build<br/>(Bunker OS + Open World)"] -->|"OE_FRAGMENTS"| P["core/yocto/sbom-cve-check fragment"]
    P --> C["CVE report<br/>(*.sbom-cve-check.yocto.json)"]
    P --> G["Enriched SPDX<br/>(*.sbom-cve-check.spdx.json)"]
    C -->|"Decision & annotation<br/>(sbom-cve-review)"| D["VEX decisions + justifications"]
    D -->|"Export BitBake metadata"| E["CVE_STATUS entries in recipes"]
    D -->|"Compliance reporting"| F["SBOM + CVE + VEX bundle"]
    G -->|"Compliance reporting"| F
    E -->|"Apply to recipes"| A
    
Phase 1: SBOM + CVE generation (core/yocto/sbom-cve-check fragment)

A single fragment activates the entire pipeline. It adds create-spdx (which generates the SPDX SBOM) as a dependency, keeps the CVE databases current via SRCREV = AUTOREV, and runs sbom-cve-check to produce two outputs: a CVE report (*.sbom-cve-check.yocto.json) and an enriched SPDX document (*.sbom-cve-check.spdx.json). All BCA reference designs adopt this fragment from Yocto Scarthgap onwards.

Phase 2: VEX Decision & Export

Use sbom-cve-review to review unpatched CVEs, record decisions with justifications, and export CVE_STATUS entries back into your recipes. This creates an audit trail suitable for regulatory submission.

Key ToolsΒΆ

  • Yocto SBOM Generation: sbom-cve-check class, adopted in all BCA reference designs from Yocto 5 (Scarthgap) onwards

  • Vulnerability Data: Cross-references the NVD and CVE feeds automatically

  • Decision Management: sbom-cve-review (GUI and CLI for reviewing CVEs and recording decisions)

  • Metadata Export: sbom-cve-review exports decisions as CVE_STATUS entries for BitBake recipes

In this SectionΒΆ

  • SBOM Generation and CVE Analysis β€” How to enable the core/yocto/sbom-cve-check fragment, what it produces, and how to verify and archive the SBOM and CVE report artefacts for each image.

  • VEX Decisions and Compliance Export β€” How to use sbom-cve-review to record engineering decisions, export CVE_STATUS entries back into recipes, and assemble a compliance-ready SBOM + CVE + VEX bundle.