Skip to main content

yocto-security-tools

CI OpenSSF Best Practices OpenSSF Scorecard PyPI version License: MIT

CVE management tools for Yocto/OpenEmbedded Linux distributions. They find the upstream commits that fix a CVE, apply them to your recipes, and optionally use an AI backend to resolve the conflicts and build failures that follow.

How it works

graph LR
    E["cve-metadata-extractor<br/>Find fix commits"] -->|cve-metadata.json| C["cve-corrector<br/>Apply patches via devtool"]
    C -->|exit code + state| A["cve-agent<br/>AI-assisted resolution"]
    A -->|subprocess| C

Each tool works standalone. Chain them with --cve-info cve-metadata.json.

Requirements

  • Python 3.10+ and Git
  • A sourced Yocto build environment (BBPATH set) for cve-corrector and cve-agent
  • An AI backend for cve-agent — see Modules below

Installation

pip install yocto-security-tools

From source:

git clone https://github.com/Ericsson/yocto-security-tools.git
cd yocto-security-tools
pip install -e .

Quick start

# 1. Find fix commits for the CVEs in a Yocto CVE summary
cve-metadata-extractor --yocto-summary cve-summary.json --output cve-metadata.json

# 2. Source your Yocto build environment
source oe-init-build-env

# 3. Apply one fix
cve-corrector --cve-id CVE-2024-1234 --cve-info cve-metadata.json

# ...or let an AI backend resolve conflicts and build failures for you
cve-agent --cve-id CVE-2024-1234 --cve-info cve-metadata.json

Modules

cve-metadata-extractor

Finds the commits that fix a CVE by querying Debian security-tracker, OSV, CVEList V5, the Ubuntu CVE Tracker, and NVD, then writes a single cve-metadata.json for the other two tools. Accepts a Yocto cve-summary.json (--yocto-summary) or explicit CVE IDs (--cve-id). Optionally checks whether a fix already landed in an OpenEmbedded branch (--check-oe).

→ Full reference

cve-corrector

Applies a fix to a recipe using devtool: cherry-picks the upstream commit into the recipe's source tree, builds, runs ptest, and finishes the change into a layer. Stops with a specific exit code when it needs help — conflict, build failure, or ptest failure — so you can fix it by hand and resume with --continue. --fix-url is repeatable and applies two or more commits as one ordered, dependent chain.

→ Full reference

cve-agent

Runs cve-corrector as a subprocess and, on a recoverable exit code, starts a guarded AI session to resolve the conflict or failure, then retries. Backends are interchangeable via --backend:

Backend --backend Needs
Kiro CLI kiro (default) kiro-cli
Claude Code claude Authenticated claude CLI on PATH
Native OpenAI-compatible openai / openai-<profile> A tool-capable OpenAI-compatible endpoint, including local Ollama
Custom plugin your own name A file in extra/ implementing AIBackend

Every backend runs under the same file-scope guard, so the AI can only modify the files the upstream fix touches. Check a backend is installed and responding with cve-agent --backend <name> --verify-backend. Use --cve-list for batch runs.

→ Full reference · OpenAI-compatible/Ollama setup

Documentation

docs/README.md indexes everything: per-tool references, configuration, and the design docs covering the result schema, agent artifacts, preflight checks, the corrector-to-agent handoff, safe patch transfer, semantic security validation, and the evaluation harness.

Plugins

Add a CVE data source or an AI backend by dropping a .py file into extra/ — no existing file needs to change. See extra/README.md for the plugin guide.

Configuration

Data and cache directories follow the XDG base directory spec and are overridable, as are the extractor's config path and the API tokens. See docs/configuration.md.

Development

python3 -m venv venv
source venv/bin/activate
pip install -e ".[dev]"
pytest

See CONTRIBUTING.md for full development guidelines.

License

MIT — see LICENSE

Metadata

Release files for yocto-security-tools 1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for yocto-security-tools 1.2
File Size Uploaded
yocto_security_tools-1.2.tar.gz 368.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for yocto-security-tools 1.2
File Interpreter ABI Platform
yocto_security_tools-1.2-py3-none-any.whl Python 3 none any Details

Total release size: 781.2 kB

Release files / yocto_security_tools-1.2.tar.gz

Download URL yocto_security_tools-1.2.tar.gz
Size 368.2 kB
Tags Source
SHA-256 checksum
How to use checksums
761724522ad4bd9cd8830d0f87f837c9f10df99645313621c6476fa0286dd1f1
BLAKE2b-256 checksum
How to use checksums
24c9ab404c07d1c434f07a2111113519f7ec104cdbdf58e1fda0d4a4ac3456ae
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / yocto_security_tools-1.2-py3-none-any.whl

Download URL yocto_security_tools-1.2-py3-none-any.whl
Size 413.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
870f59904d1a74d4801481954e03b8aa6f41cbf0c87eeb650fc49bb2e97a3180
BLAKE2b-256 checksum
How to use checksums
6a121d8450a7f5f125ee14888681d2e2db11f4c8bc0306c1b01205f0adf0c8ea
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.2 This release

2 release files

1.1

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page