yocto-security-tools
CVE management tools for Yocto/OpenEmbedded Linux distributions. They find the upstream commits that fix a CVE, apply them to your recipes, and optionally use an AI backend to resolve the conflicts and build failures that follow.
How it works
graph LR
E["cve-metadata-extractor<br/>Find fix commits"] -->|cve-metadata.json| C["cve-corrector<br/>Apply patches via devtool"]
C -->|exit code + state| A["cve-agent<br/>AI-assisted resolution"]
A -->|subprocess| C
Each tool works standalone. Chain them with --cve-info cve-metadata.json.
Requirements
- Python 3.10+ and Git
- A sourced Yocto build environment (
BBPATHset) forcve-correctorandcve-agent - An AI backend for
cve-agent— see Modules below
Installation
pip install yocto-security-tools
From source:
git clone https://github.com/Ericsson/yocto-security-tools.git
cd yocto-security-tools
pip install -e .
Quick start
# 1. Find fix commits for the CVEs in a Yocto CVE summary
cve-metadata-extractor --yocto-summary cve-summary.json --output cve-metadata.json
# 2. Source your Yocto build environment
source oe-init-build-env
# 3. Apply one fix
cve-corrector --cve-id CVE-2024-1234 --cve-info cve-metadata.json
# ...or let an AI backend resolve conflicts and build failures for you
cve-agent --cve-id CVE-2024-1234 --cve-info cve-metadata.json
Modules
cve-metadata-extractor
Finds the commits that fix a CVE by querying Debian security-tracker, OSV,
CVEList V5, the Ubuntu CVE Tracker, and NVD, then writes a single
cve-metadata.json for the other two tools. Accepts a Yocto cve-summary.json
(--yocto-summary) or explicit CVE IDs (--cve-id). Optionally checks whether
a fix already landed in an OpenEmbedded branch (--check-oe).
cve-corrector
Applies a fix to a recipe using devtool: cherry-picks the upstream commit into
the recipe's source tree, builds, runs ptest, and finishes the change into a
layer. Stops with a specific exit code when it needs help — conflict, build
failure, or ptest failure — so you can fix it by hand and resume with
--continue. --fix-url is repeatable and applies two or more commits as one
ordered, dependent chain.
cve-agent
Runs cve-corrector as a subprocess and, on a recoverable exit code, starts a
guarded AI session to resolve the conflict or failure, then retries. Backends
are interchangeable via --backend:
| Backend | --backend |
Needs |
|---|---|---|
| Kiro CLI | kiro (default) |
kiro-cli |
| Claude Code | claude |
Authenticated claude CLI on PATH |
| Native OpenAI-compatible | openai / openai-<profile> |
A tool-capable OpenAI-compatible endpoint, including local Ollama |
| Custom plugin | your own name | A file in extra/ implementing AIBackend |
Every backend runs under the same file-scope guard, so the AI can only modify
the files the upstream fix touches. Check a backend is installed and responding
with cve-agent --backend <name> --verify-backend. Use --cve-list for batch
runs.
→ Full reference · OpenAI-compatible/Ollama setup
Documentation
docs/README.md indexes everything: per-tool references, configuration, and the design docs covering the result schema, agent artifacts, preflight checks, the corrector-to-agent handoff, safe patch transfer, semantic security validation, and the evaluation harness.
Plugins
Add a CVE data source or an AI backend by dropping a .py file into extra/ —
no existing file needs to change. See
extra/README.md for the plugin guide.
Configuration
Data and cache directories follow the XDG base directory spec and are overridable, as are the extractor's config path and the API tokens. See docs/configuration.md.
Development
python3 -m venv venv
source venv/bin/activate
pip install -e ".[dev]"
pytest
See CONTRIBUTING.md for full development guidelines.
License
MIT — see LICENSE
Metadata
Release files for yocto-security-tools 1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| yocto_security_tools-1.2.tar.gz | 368.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| yocto_security_tools-1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 781.2 kB
Release files / yocto_security_tools-1.2.tar.gz
| Download URL | yocto_security_tools-1.2.tar.gz |
|---|---|
| Size | 368.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
761724522ad4bd9cd8830d0f87f837c9f10df99645313621c6476fa0286dd1f1
|
|
BLAKE2b-256 checksum How to use checksums |
24c9ab404c07d1c434f07a2111113519f7ec104cdbdf58e1fda0d4a4ac3456ae
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency logRelease files / yocto_security_tools-1.2-py3-none-any.whl
| Download URL | yocto_security_tools-1.2-py3-none-any.whl |
|---|---|
| Size | 413.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
870f59904d1a74d4801481954e03b8aa6f41cbf0c87eeb650fc49bb2e97a3180
|
|
BLAKE2b-256 checksum How to use checksums |
6a121d8450a7f5f125ee14888681d2e2db11f4c8bc0306c1b01205f0adf0c8ea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency log