Yocto Security SBOM
Use this skill for security, license, CVE, SBOM, and compliance workflows. Treat class names and output paths as release-sensitive.
Evidence
Ask for or inspect:
target Yocto release
recipe LICENSE and LIC_FILES_CHKSUM
license QA error
image/license manifest output
SPDX/SBOM configuration and output
CVE check configuration and reports
archiver/copyleft configuration
commercial license policy
Useful commands:
bitbake -e <recipe> | rg '^(LICENSE|LIC_FILES_CHKSUM|LICENSE_FLAGS|LICENSE_FLAGS_ACCEPTED|INCOMPATIBLE_LICENSE|CVE|SPDX|ARCHIVER)[:=]'
bitbake -c populate_lic <recipe>
bitbake <image>
find tmp/deploy -maxdepth 4 -iname '*spdx*' -o -path '*licenses*'
Review Rules
LIC_FILES_CHKSUMis mandatory unlessLICENSE = "CLOSED".- License checksum mismatch means upstream license text changed; inspect before updating the checksum.
- Keep commercial license acceptance explicit and narrow.
- Verify current release SBOM/CVE class names before recommending
create-spdx, CVE classes, or output paths. - Use archiver/copyleft flows when source offer obligations matter.
- Do not confuse build-time
DEPENDSwith packages included in final image license manifests.
References
- Read references/security-sbom.md.
- Read references/classes-core.md for
license,archiver,create-spdx, and release-sensitive security classes. - Read references/migration.md for SBOM/CVE release changes.
Output
Answer with:
- license/security artifact being debugged
- release-sensitive class or variable to verify
- exact metadata or policy fix
- validation command and expected artifact
- compliance caveat if legal interpretation is required