Vigiles can be used to monitor vulnerabilities in the Layerscape BSP components. Currently there is no direct support to extract the manifest from “Layerscape SDK” flex-builder which is required for Vigiles to track vulnerabilities. However, one can manually create a CSV file and/or use the Vigiles UI to create a manifest listing all the NXP packages (including the Linux LTS kernel) and then upload it to Vigiles to generate a vulnerability report and tracking new vulnerabilities. If assistance is needed in creating the CSV file (documentation) please contact us and we can help with the same.
We are in the process of adding support for Layerscape SDK in an upcoming release of Vigiles to enable seamless integration and it will be available by end of Q3 2020.
Thanks,
Vigiles Security Team