Anders Heimer
I am Senior Specialist in Linux Build Packaging and Integration working at Ericsson Software Technology providing expertise in Yocto for the Ericsson Yocto users.
Session
08-28
15:00
30min
Hardening Your Container Supply Chain with Yocto‑Built Base Images
Anders Heimer
Software‑supply‑chain attacks increasingly exploit the dependency graphs hidden inside container base images. General‑purpose binary distributions can drag in hundreds of packages, making it difficult to generate accurate SBOMs and keep up with CVE patching. In this session you will learn how to use the Yocto Project to build lean, auditable container base images and matching package repositories that can serve as drop‑in replacements inside existing Docker or Podman build pipelines.
Studio 1