EMB-310 · Embedded Linux & BSP · Practitioner

SBOM & Licence Compliance — full syllabus

Producing a defensible software bill of materials and meeting open source licence obligations — now a regulatory matter, not just good practice.

Duration2 full days in person · 4 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 5,250 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Engineers and tech leads who must produce a defensible SBOM and meet open source licence obligations — now that customers and regulators ask for both in writing.

Prerequisites

Course outline

Day 1 — Licences as engineering constraints

  • Licence classes: permissive, weak copyleft, strong copyleft and what each obliges
  • The copyleft boundary in practice: linking, kernel modules and the LGPL cases
  • Reading a package's licence honestly: what upstream declares vs what the code contains
  • Yocto licence machinery: LICENSE fields, licence manifests, LICENSE_FLAGS and the archiver class
  • Source release obligations: what you must ship when asked

Day 2 — SBOM production and what it feeds

  • What an SBOM is for: vulnerability response, customer questionnaires, regulation
  • SPDX and CycloneDX generation from a Yocto build
  • SBOM quality: provenance, versions, patches and the gaps that make an SBOM misleading
  • Automating source-release artefacts so a request is a build, not a project
  • Feeding the SBOM to vulnerability monitoring: CVE matching and its false-positive problem

Hands-on labs

  1. Lab: Generate a licence manifest for a real image, audit it against the actual sources and fix the discrepancies you find
  2. Lab: Run the archiver class and produce a complete source-release bundle for a GPL-covered component set
  3. Lab: Generate SPDX and CycloneDX SBOMs for the same image and compare what each captures
  4. Lab: Match the SBOM against a CVE feed and triage the results into a defensible applies/does-not-apply record
  5. Lab: Simulate a customer source request end to end: from SBOM entry to delivered source archive, timed

Capstone project

Take a product image and produce its complete compliance pack: an audited licence manifest, SPDX and CycloneDX SBOMs, the automated source-release bundle for copyleft components, and a vulnerability-monitoring record showing each flagged CVE triaged with evidence — packaged so a customer or auditor could rerun any step.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
25 Oct – 26 Oct 20262 full days RiyadhIn person · KAFD Conference Centre 4 of 14 —SAR 5,250
25 Oct – 26 Oct 20262 full days Kuwait CityIn person · Al Hamra Tower 9 of 14 —KWD 430
1 Nov – 2 Nov 20262 full days MuscatIn person · Knowledge Oasis Muscat 4 of 14 —OMR 540
8 Nov – 11 Nov 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 18 of 20 US$900until 9 OctUS$1,000
9 Nov – 10 Nov 20262 full days OttawaIn person · Kanata North Tech Park 9 of 14 CAD 1,710until 10 OctCAD 1,900
9 Nov – 10 Nov 20262 full days TorontoIn person · MaRS Discovery District 4 of 14 CAD 1,710until 10 OctCAD 1,900
9 Nov – 12 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 7 of 20 US$900until 10 OctUS$1,000
16 Nov – 17 Nov 20262 full days LondonIn person · Shoreditch Works 9 of 14 GBP 980until 17 OctGBP 1,090
16 Nov – 19 Nov 20264 half-days Americas bandLive online · 13:00–17:00 ET 12 of 20 US$900until 17 OctUS$1,000
23 Nov – 24 Nov 20262 full days BerlinIn person · Factory Görlitzer Park 4 of 14 EUR 1,160until 24 OctEUR 1,290

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.