EMB-310 · Embedded Linux & BSP · Practitioner
SBOM & Licence Compliance — full syllabus
Producing a defensible software bill of materials and meeting open source licence obligations — now a regulatory matter, not just good practice.
Who this course is for
Engineers and tech leads who must produce a defensible SBOM and meet open source licence obligations — now that customers and regulators ask for both in writing.
Prerequisites
- Embedded Linux build experience (Yocto preferred, Buildroot acceptable)
- No legal background required
- Command-line fluency
Course outline
Day 1 — Licences as engineering constraints
- Licence classes: permissive, weak copyleft, strong copyleft and what each obliges
- The copyleft boundary in practice: linking, kernel modules and the LGPL cases
- Reading a package's licence honestly: what upstream declares vs what the code contains
- Yocto licence machinery: LICENSE fields, licence manifests, LICENSE_FLAGS and the archiver class
- Source release obligations: what you must ship when asked
Day 2 — SBOM production and what it feeds
- What an SBOM is for: vulnerability response, customer questionnaires, regulation
- SPDX and CycloneDX generation from a Yocto build
- SBOM quality: provenance, versions, patches and the gaps that make an SBOM misleading
- Automating source-release artefacts so a request is a build, not a project
- Feeding the SBOM to vulnerability monitoring: CVE matching and its false-positive problem
Hands-on labs
- Lab: Generate a licence manifest for a real image, audit it against the actual sources and fix the discrepancies you find
- Lab: Run the archiver class and produce a complete source-release bundle for a GPL-covered component set
- Lab: Generate SPDX and CycloneDX SBOMs for the same image and compare what each captures
- Lab: Match the SBOM against a CVE feed and triage the results into a defensible applies/does-not-apply record
- Lab: Simulate a customer source request end to end: from SBOM entry to delivered source archive, timed
Capstone project
Take a product image and produce its complete compliance pack: an audited licence manifest, SPDX and CycloneDX SBOMs, the automated source-release bundle for copyleft components, and a vulnerability-monitoring record showing each flagged CVE triaged with evidence — packaged so a customer or auditor could rerun any step.
What you leave with
- A licence manifest you can defend line by line
- Working SPDX and CycloneDX generation from your build
- Automated source-release artefacts, not a scramble
- A CVE-triage record tied to your actual component set
- A repeatable compliance pipeline instead of a heroic effort per release
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 25 Oct – 26 Oct 20262 full days | RiyadhIn person · KAFD Conference Centre | 4 of 14 | — | SAR 5,250 | |
| 25 Oct – 26 Oct 20262 full days | Kuwait CityIn person · Al Hamra Tower | 9 of 14 | — | KWD 430 | |
| 1 Nov – 2 Nov 20262 full days | MuscatIn person · Knowledge Oasis Muscat | 4 of 14 | — | OMR 540 | |
| 8 Nov – 11 Nov 20264 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 18 of 20 | US$900until 9 Oct | ||
| 9 Nov – 10 Nov 20262 full days | OttawaIn person · Kanata North Tech Park | 9 of 14 | CAD 1,710until 10 Oct | ||
| 9 Nov – 10 Nov 20262 full days | TorontoIn person · MaRS Discovery District | 4 of 14 | CAD 1,710until 10 Oct | ||
| 9 Nov – 12 Nov 20264 half-days | Europe bandLive online · 09:00–13:00 CET | 7 of 20 | US$900until 10 Oct | ||
| 16 Nov – 17 Nov 20262 full days | LondonIn person · Shoreditch Works | 9 of 14 | GBP 980until 17 Oct | ||
| 16 Nov – 19 Nov 20264 half-days | Americas bandLive online · 13:00–17:00 ET | 12 of 20 | US$900until 17 Oct | ||
| 23 Nov – 24 Nov 20262 full days | BerlinIn person · Factory Görlitzer Park | 4 of 14 | EUR 1,160until 24 Oct |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.