SBOM (Software Bill-of-Materials)
Overview
IoT Yocto adopts the built-in mechanism provided by upstream Yocto for generating the Software Bill-of-Materials (SBOM). The SBOM is produced directly by Yocto’s native SPDX support during the build.
Starting with Scarthgap, the SBOM is automatically generated every time a Yocto image is built; no manual step or extra build flag is required to produce it.
SBOM Output
Each build produces the SBOM as two separate tarballs under the image folder:
Boot assets SBOM: covers the bootloader components
Rootfs SBOM: covers the root filesystem components
The file names follow this pattern (example shown for the Genio 360-EVK):
rity-bsp-image-genio-360-evk.bootassets.spdx.tar.zstrity-bsp-image-genio-360-evk.rootfs.spdx.tar.zst
How to Parse the SBOM
The IoT Yocto SBOM consists of an index file (index.json) and a large number of JSON
files, each holding information for a single package. Each JSON file is formatted
according to the SPDX spec v2.2. The
relationships between these files are specified by the relationship fields inside each
JSON file — see the
SPDX spec: Relationships between SPDX Elements
for details.
Note
To understand the file structure and the relationships of the Yocto SBOM, watch the introduction video.
Because the SBOM is standard SPDX v2.2 JSON, you can parse it with any SPDX-compliant tooling, for example the open-source spdx-tools library, or implement your own parser directly against the SPDX spec.
A typical workflow looks like this:
mkdir sbom_tmp
tar --zstd -xf rity-bsp-image-genio-360-evk.bootassets.spdx.tar.zst -C sbom_tmp
cd sbom_tmp
Each package’s JSON document carries fields such as its name, version, license
expression, source URLs, and file checksums. The image-level SPDX document (named after
the image recipe, e.g. rity-bsp-image-genio-360-evk.bootassets-<timestamp>.spdx.json)
lists all the packages included in that image via relationship entries, and each
individual package’s own SPDX document (e.g. trusted-firmware-a.spdx.json) provides
its detailed metadata, associated files, and build/runtime dependencies.