VulnTrack: a browser-based dashboard for reviewing Yocto CVE reports and SBOM/SPDX data. #bitbake #linux #yocto

[email protected]
Newsgroups org.yoctoproject.lists.yocto
Message-ID <[email protected]>
Hello Yocto community,

I wanted to share a small tool I have been working on called *VulnTrack*.

VulnTrack is a lightweight, browser-based dashboard for reviewing Yocto vulnerability data and SBOM/SPDX files. It helps make Yocto-generated security data easier to inspect, understand, and share.

GitHub:
https://github.com/prashantdivate/VulnTrack

Live demo:
https://prashantdivate.github.io/VulnTrack/

The basic idea is simple: instead of manually opening large JSON files and going through long package entries, CVE strings, patch status fields, vulnerability summaries, and SBOM component data, VulnTrack provides a visual dashboard on top of that information.

It currently supports:

* 

Yocto cve-summary.json review

* 

Yocto-generated SBOM/SPDX file review

* 

Package-level vulnerability analysis

* 

CVE severity and status summaries

* 

Affected package drill-down

* 

SBOM component inspection

* 

HTML, PDF, Markdown, JSON, and CSV report exports

The exported reports include useful sections such as executive summary, severity/status charts, priority CVEs, package risk summary, and remediation-focused findings.

I know the first question may be: why another tool, when Yocto/OpenEmbedded already has cve-check , patchtest, VulnScout, and other security-related tooling?

VulnTrack is not intended to replace those tools.

The way I see it:

* 

cve-check generates Yocto CVE data.

* 

Yocto-generated SPDX/SBOM output provides component and software bill of materials visibility.

* 

patchtest and existing Yocto/OE workflows help with patch validation and development process quality.

* 

VulnScout and related efforts help with vulnerability monitoring and security workflows.

* 

VulnTrack sits after this data is generated and focuses on human review, visualization, and report export.

*So the goal is not to duplicate scanning, patch validation, or vulnerability detection. The goal is to make already-generated Yocto CVE and SBOM data easier to review, explain, share, and document.*

This can be useful when security data needs to be discussed with embedded Linux engineers, product security teams, release teams, managers, customers, or compliance stakeholders who may not want to inspect raw JSON files directly.

VulnTrack runs fully in the browser:

* 

No backend

* 

No database

* 

No account

* 

No vulnerability data upload

All processing is local in the browser.

Some possible use cases:

* 

Quick review of Yocto cve-summary.json

* 

Review of Yocto-generated SBOM/SPDX files

* 

Release readiness vulnerability summary

* 

Sharing CVE and SBOM status with product/security teams

* 

Generating HTML/PDF vulnerability reports

* 

Creating evidence for internal security review

* 

Supporting CRA-oriented vulnerability management documentation

I would be happy to get feedback from Yocto and OpenEmbedded users:

* 

Is this useful for your CVE or SBOM review workflow?

* 

Are there fields from cve-summary.json or SPDX/SBOM files that should be represented better?

* 

Would comparison between two builds be useful?

* 

Would triage notes or review decisions be useful?

* 

Are there better ways to align this with existing Yocto/OE security workflows?

Feedback, suggestions, issues, and contributions are welcome.

Thanks,
Prashant Divate
summary.png (image/png, 478.8 KB) - not displayed
packages.png (image/png, 262.2 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.