SBOM (Software Bill-of-Materials)

Overview

IoT Yocto adopts the built-in mechanism provided by upstream Yocto for generating the Software Bill-of-Materials (SBOM). The SBOM is produced directly by Yocto’s native SPDX support during the build.

Starting with Scarthgap, the SBOM is automatically generated every time a Yocto image is built; no manual step or extra build flag is required to produce it.

SBOM Output

Each build produces the SBOM as two separate tarballs under the image folder:

  • Boot assets SBOM: covers the bootloader components

  • Rootfs SBOM: covers the root filesystem components

The file names follow this pattern (example shown for the Genio 360-EVK):

  • rity-bsp-image-genio-360-evk.bootassets.spdx.tar.zst

  • rity-bsp-image-genio-360-evk.rootfs.spdx.tar.zst

How to Parse the SBOM

The IoT Yocto SBOM consists of an index file (index.json) and a large number of JSON files, each holding information for a single package. Each JSON file is formatted according to the SPDX spec v2.2. The relationships between these files are specified by the relationship fields inside each JSON file — see the SPDX spec: Relationships between SPDX Elements for details.

Note

To understand the file structure and the relationships of the Yocto SBOM, watch the introduction video.

Because the SBOM is standard SPDX v2.2 JSON, you can parse it with any SPDX-compliant tooling, for example the open-source spdx-tools library, or implement your own parser directly against the SPDX spec.

A typical workflow looks like this:

mkdir sbom_tmp
tar --zstd -xf rity-bsp-image-genio-360-evk.bootassets.spdx.tar.zst -C sbom_tmp
cd sbom_tmp

Each package’s JSON document carries fields such as its name, version, license expression, source URLs, and file checksums. The image-level SPDX document (named after the image recipe, e.g. rity-bsp-image-genio-360-evk.bootassets-<timestamp>.spdx.json) lists all the packages included in that image via relationship entries, and each individual package’s own SPDX document (e.g. trusted-firmware-a.spdx.json) provides its detailed metadata, associated files, and build/runtime dependencies.