1

I am new to Yocto and would like to know how Yocto Cve check works.

  1. Cve Check finds the patched/unpatched on version number & patch added to the recipe. Is this the only 2 methods Cve Check use?
  2. Cve Check seems to fetch the package artifactory from jFrog. If 1 is true, why do we need to do this? We could just compare the version number & patch added from the metadata of the recipe.
  3. If 1 is true, why Cve Check could take so many minutes (20 min+) for some packages to find its cve?
EzyHoo
  • 301
  • 2
  • 14

0 Answers0