Today, we are happy to announce the first release of a brand new open-source project: sbom-cve-check, a lightweight CVE analysis tool for your Software Bill of Materials (SBOM). Written in Python, with minimal dependencies, and a very simple workflow in mind, sbom-cve-check will parse your SBOM (SPDX v2.2 or SPDX v3.0 currently supported), and using publicly available databases of security vulnerabilities, will generate a report of known security vulnerabilities affecting the software components listed in your SBOM.
This tool will be presented tomorrow, on December 2 at 3:40 PM during the Yocto Project Virtual Summit 2025.12 during a talk titled sbom-cve-check: Lightweight Python tooling for out-of-build CVE analysis of SPDX3 SBOMs, presented by Bootlin engineers Benjamin Robin and Olivier Benjamin.
Continue reading “Announcing sbom-cve-check, a lightweight CVE analysis tool for your SBOM”

The 6.18 version of the Linux kernel has just been released, and as usual we recommend our readers to look at the 6.18 merge window coverage by LWN.net (

The
It’s been a few months already that Benoît Monin joined our team, as he started in May, just in time to participate to our yearly company-wide team week event in June. Benoît graduated from
More recently, in late August, Benjamin Robin also joined our team. This time, he joined just in time to participate to the recent Open Source Summit Europe in Amsterdam, a great opportunity to meet almost the entire Bootlin’s team, and also the embedded Linux community. Benjamin also graduated from
Bootlin had a very strong presence at the recent 