Re: [yocto] Yocto Lens - Static Analysis and Style Review Tool for Yocto Metadata
[email protected] Sun, 14 Jun 2026 23:11:58 -0700
| Newsgroups | org.yoctoproject.lists.yocto |
|---|---|
| Message-ID | <[email protected]> |
--ZXHhRodpCQiw0YD0lVU2 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Thanks, Alexander and Ayoub. Those are both very fair questions. Regarding running against oe-core/meta-yocto/meta-openembedded: I haven't y= et done a systematic benchmark against the reference layers, but I agree th= at's an important next step. It will help identify false positives and also= show whether Yocto Lens is finding anything genuinely useful beyond existi= ng tooling. I'll post results once I've had a chance to run it against thos= e layers and review the findings. Regarding differentiation from oelint-adv, meta-sca, and the official Yocto= tooling: my goal is not to replace those projects. In fact, many of the ch= ecks overlap and I've been using them as references while learning more abo= ut Yocto metadata validation. The main idea behind Yocto Lens is currently: *=20 a standalone workflow that can run directly on layer repositories *=20 An interactive terminal dashboard for reviewing findings *=20 recipe health scoring and metadata quality insights *=20 SARIF export for CI systems *=20 a single interface that combines static-analysis and style-review results That said, I completely agree that accuracy and the usefulness of the check= s matter more than UI. Running against oe-core and meta-openembedded is pro= bably the right next step to evaluate where Yocto Lens provides value and w= here it still needs improvement. I appreciate the feedback and suggestions. --ZXHhRodpCQiw0YD0lVU2 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <div> <p>Thanks, Alexander and Ayoub.</p> <p>Those are both very fair questions.</p> <p>Regarding running against oe-core/meta-yocto/meta-openembedded: I haven'= t yet done a systematic benchmark against the reference layers, but I agree= that's an important next step. It will help identify false positives and a= lso show whether Yocto Lens is finding anything genuinely useful beyond exi= sting tooling. I'll post results once I've had a chance to run it against t= hose layers and review the findings.</p> <p>Regarding differentiation from oelint-adv, meta-sca, and the official Yo= cto tooling: my goal is not to replace those projects. In fact, many of the= checks overlap and I've been using them as references while learning more = about Yocto metadata validation.</p> <p>The main idea behind Yocto Lens is currently:</p> <ul> <li> <p>a standalone workflow that can run directly on layer repositories</p> </li> <li> <p>An interactive terminal dashboard for reviewing findings</p> </li> <li> <p>recipe health scoring and metadata quality insights</p> </li> <li> <p>SARIF export for CI systems</p> </li> <li> <p>a single interface that combines static-analysis and style-review result= s</p> </li> </ul> <p>That said, I completely agree that accuracy and the usefulness of the ch= ecks matter more than UI. Running against oe-core and meta-openembedded is = probably the right next step to evaluate where Yocto Lens provides value an= d where it still needs improvement.</p> <p>I appreciate the feedback and suggestions.</p> </div> --ZXHhRodpCQiw0YD0lVU2--