BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//yocto-project-summit-2025-12//talk//WNE7XA
BEGIN:VEVENT
SUMMARY:sbom-cve-check: Lightweight Python tooling for out-of-build CVE an
 alysis of SPDX3 SBOMs - Olivier Benjamin\, Benjamin Robin
DTSTART:20251202T154000Z
DTEND:20251202T161000Z
DTSTAMP:20260818T212033Z
UID:pretalx-yocto-project-summit-2025-12-WNE7XA@pretalx.com
DESCRIPTION:We are happy to announce the first release of a brand new open
 -source project: **sbom-cve-check**\, a lightweight CVE analysis tool for 
 your Software Bill of Materials (SBOM). Written in Python\, with minimal d
 ependencies and a very simple workflow in mind\, **sbom-cve-check** will p
 arse your SBOM (SPDX v2.2 or SPDX v3.0 currently supported)\, and using pu
 blicly available databases of security vulnerabilities\, will generate a r
 eport of known security vulnerabilities affecting the software components 
 listed in your SBOM.
LOCATION:Walnascar
URL:https://pretalx.com/yocto-project-summit-2025-12/talk/WNE7XA/
END:VEVENT
END:VCALENDAR
