{"repo":"priv-kweihmann/meta-sca","free":true,"listed":false,"github":"https://github.com/priv-kweihmann/meta-sca","clone":"git clone https://github.com/priv-kweihmann/meta-sca.git","description":"Layer for static code analysis and security hardening","language":"BitBake","stars":110,"topics":["yocto","poky","static-code-analysis","bitbake","security-hardening","defense-in-depth","python","shellscript","c","cxx"],"license":null,"category":"deployment-docker-iac","readme_excerpt":"meta-sca For the list of current findings from pipelines see meta-sca report Important note As announced by this discussion at the end of April 2022 this layer will undergo a major change in support. Support will be given only for master branch What can I do when I'm affected by the changes A maintainers guide can be found here. Feel free to raise pull requests against not officially supported branches. Support for these branches, including quality control, has to be done fully by the community Table of content - Purpose - Getting started - Installation - Prerequisites - Use of containers - Use in CI - Setup - Kas - Web monitor - Support - Releases - Compatibility - Licensing - Zero impact - Available tools - Overview of tools - Further documentation - Contributing - Get involved - Security Policy Purpose Purpose of this layer is to provide a proper set of static analysis tools for your YOCTO build. All provided tools can be easily configured and integrated into any CI service (like e.g. Jenkins). All results are stored to SCA EXPORT DIR (which defaults to ${DEPLOY DIR IMAGE}/sca ). The results will be stored in the raw-format of the corresponding tool and in checkstyle-format. Getting started For a quick start how to use this layer see getting started guide You can also watch the following talk I gave for YS2023.11 to get started. Installation To install clone the needed branch(es) to any path on your local system. Prerequisites - You need the current standard poky -layer in","default_branch":null,"files":null,"tree":[],"storefront":"/r/priv-kweihmann","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/priv-kweihmann/meta-sca/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}