Major U.S. A&D Space and Mission Systems Organization

Embedded Software Supply-Chain Security with MOSA.ic.SCA

 

HERO-L~1.PNG
Flag

Challenge

  • Repeatable SBOM + CVE evidence

  • Fit Yocto/PetaLinux CI/CD builds

  • Run on air-gapped networks

solution

Solution

  • Build-integrated SBOM + CVE scan

  • On-prem Vigiles, CycloneDX/SPDX

  • Low-risk hosted trial first

value

Value

  • Compliance evidence per release

  • Target-aware, embedded-Linux depth

  • Foothold to expand across programs

long arrow

Key Capabilities

GitLab CI/CD

DOORS

VectorCAST

AdaCore

SaFe Agile

Key Capabilities:     MOSA.ic.SCA          Vigiles          SBOM/CVE          Yocto/PetaLinux           Air-gapped

Customer Challenge

A leading aerospace & defense (A&D) organization’s space & mission systems division needed a repeatable way to manage software-supply-chain risk in embedded systems across satellite, mission-computing, sensor, and ground-system programs. The core requirement was to generate software bills of materials (SBOMs), identify and manage known vulnerabilities (CVEs), and preserve compliance evidence to meet growing cybersecurity requirements.

Crucially, this could not be a one-time report. Engineering needed to produce SBOM and vulnerability evidence repeatedly across builds and releases, integrated with existing embedded-Linux builds, CI/CD pipelines, and an artifact repository. The immediate focus was Yocto/PetaLinux, with broader interest spanning Linux, VxWorks®, and FreeRTOS. Results had to use standard CycloneDX and SPDX SBOM formats and operate across both connected and air-gapped / disconnected networks.

Lynx Solution & Capabilities

LYNX MOSA.ic.SCA, deployed on-premises and powered by on-premises Vigiles, fit both the technical workflow and the deployment constraints. Built-in Yocto integration generates an SBOM and performs CVE analysis as part of the build itself, while Vigiles APIs and a CLI enable automated pipelines with standard CycloneDX/SPDX output. This matched the customer’s CI/CD and artifact-repository processes and its need to operate across enterprise and disconnected networks.

MOSA.ic.SCA is purpose-built for embedded Linux rather than general-purpose repository or container scanning. Its target-aware CVE analysis reflects what is deployed — kernel, U-Boot, CPU/SoC, and target package context, so teams focus on the vulnerabilities that genuinely matter for the fielded system. As an on-premises, customer-controlled solution, it satisfies multi-network and disconnected-environment requirements while complementing the broader LYNX MOSA.ic platform and integration work.

A decisive element was a low-risk path to proof: a limited, read-only hosted Vigiles trial with a preloaded PetaLinux SBOM let the evaluation team validate the end-to-end workflow on a representative build before any on-premises commitment, removing risk from the buying decision without an infrastructure lift.

capabilities

Customer Value & Outcomes

The customer gained a repeatable, build-integrated way to produce SBOM and vulnerability evidence for every release, with compliance artifacts preserved across builds, replacing ad-hoc, one-time reporting. Target-aware analysis reduces noise by prioritizing the CVEs that apply to the deployed embedded target, and standard CycloneDX/SPDX output plugs directly into existing CI/CD and artifact-repository workflows.

Because the solution runs on-premises and supports disconnected operation, the same workflow works across enterprise and air-gapped networks — a hard requirement for mission-critical A&D programs. The initial adoption also establishes a foothold within a large A&D account, with clear room to expand to additional programs and business units and to adjacent Lynx capabilities such as secure Linux and MOSA.ic.AI.

Key Skills & Differentiators

    • Build-integrated SBOM generation (CycloneDX / SPDX)
    • Target-aware CVE analysis and filtering for embedded Linux (kernel, U-Boot, CPU/SoC, target packages)
    • Yocto / PetaLinux integration; applicable to Buildroot and OpenWrt
    • Vigiles API and CLI automation for CI/CD pipelines and artifact repositories
    • On-premises, customer-controlled deployment across connected and air-gapped / disconnected networks
    • Repeatable evidence and disposition tracking across builds and releases
    • Multi-OS breadth of interest (Linux, VxWorks, FreeRTOS)
    • Low-risk, read-only hosted trial to validate the workflow before on-premises commitment

MOSA.ic.SCA in the Embedded Build & Compliance

Build-integrated SBOM generation and target-aware CVE analysis - powered by on-premises Vigiles

Embedded Build

  • Yocti/PetaLinus

  • Buildroot/OpenWrt
  • BSP, kernel, U-Boot
  • CPU/SoC and target
  • Packages

Connected

MOSA.ic.SCA

  • SBOM generation

  • Target-aware CVE

  • Vigiles API/CLI

  • CycloneDX/SPDX

Air-gapped
 

Pipeline Integration

  • CI/CD pipelines

  • Artifactory

  • Issue tracker

  • Repeatable, automated

  • Per build

Connected

Compliance Outputs

  • SBOM (CycloneDX/SPDX)

  • Prioritized, relevant CVEs

  • Disposition decisions

  • Release compliance

  • Evidence

Repeatable across every build and release, ongoing SBOM and vulnerability evidence, not a one-time report

Validated first through a low risk, read-only hosted trial on a representative build, then deployed on-premises.

See How MOSA.ic.SCA Strengthens Embedded Software Assurance

Discover how MOSA.ic.SCA helps aerospace and defense teams generate repeatable SBOMs, prioritize target-relevant vulnerabilities, and maintain compliance evidence across connected and air-gapped environments.