EMB-310 · Embedded Linux & BSP
SBOM & Licence Compliance
Producing a defensible software bill of materials and meeting open source licence obligations — now a regulatory matter, not just good practice.
Who this course is for
Engineers and tech leads who must produce a defensible SBOM and meet open source licence obligations — now that customers and regulators ask for both in writing.
Prerequisites
Course outline
Day 1 — Licences as engineering constraints
- Licence classes: permissive, weak copyleft, strong copyleft and what each obliges
- The copyleft boundary in practice: linking, kernel modules and the LGPL cases
- Reading a package's licence honestly: what upstream declares vs what the code contains
- Yocto licence machinery: LICENSE fields, licence manifests, LICENSE_FLAGS and the archiver class
- Source release obligations: what you must ship when asked
Day 2 — SBOM production and what it feeds
- What an SBOM is for: vulnerability response, customer questionnaires, regulation
- SPDX and CycloneDX generation from a Yocto build
- SBOM quality: provenance, versions, patches and the gaps that make an SBOM misleading
- Automating source-release artefacts so a request is a build, not a project
- Feeding the SBOM to vulnerability monitoring: CVE matching and its false-positive problem
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: Generate a licence manifest for a real image, audit it against the actual sources and fix the discrepancies you find
- Lab: Run the archiver class and produce a complete source-release bundle for a GPL-covered component set
- Lab: Generate SPDX and CycloneDX SBOMs for the same image and compare what each captures
- Lab: Match the SBOM against a CVE feed and triage the results into a defensible applies/does-not-apply record
- Lab: Simulate a customer source request end to end: from SBOM entry to delivered source archive, timed
Capstone project
Take a product image and produce its complete compliance pack: an audited licence manifest, SPDX and CycloneDX SBOMs, the automated source-release bundle for copyleft components, and a vulnerability-monitoring record showing each flagged CVE triaged with evidence — packaged so a customer or auditor could rerun any step.
What you leave with
- A licence manifest you can defend line by line
- Working SPDX and CycloneDX generation from your build
- Automated source-release artefacts, not a scramble
- A CVE-triage record tied to your actual component set
- A repeatable compliance pipeline instead of a heroic effort per release
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers and tech leads who must produce a defensible SBOM and meet open source licence obligations — now that customers and regulators ask for both in writing. It sits at practitioner level within the Embedded Linux & BSP track.
What do I need to know already?
Specific prerequisites for this course: Embedded Linux build experience (Yocto preferred, Buildroot acceptable); No legal background required; Command-line fluency. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 25 Oct – 26 Oct 20262 full days | RiyadhIn person · KAFD Conference Centre | 4 of 14 | — | SAR 5,250 | |
| 25 Oct – 26 Oct 20262 full days | Kuwait CityIn person · Al Hamra Tower | 9 of 14 | — | KWD 430 | |
| 1 Nov – 2 Nov 20262 full days | MuscatIn person · Knowledge Oasis Muscat | 4 of 14 | — | OMR 540 | |
| 8 Nov – 11 Nov 20264 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 18 of 20 | US$900until 9 Oct | ||
| 9 Nov – 10 Nov 20262 full days | OttawaIn person · Kanata North Tech Park | 9 of 14 | CAD 1,710until 10 Oct | ||
| 9 Nov – 10 Nov 20262 full days | TorontoIn person · MaRS Discovery District | 4 of 14 | CAD 1,710until 10 Oct | ||
| 9 Nov – 12 Nov 20264 half-days | Europe bandLive online · 09:00–13:00 CET | 7 of 20 | US$900until 10 Oct | ||
| 16 Nov – 17 Nov 20262 full days | LondonIn person · Shoreditch Works | 9 of 14 | GBP 980until 17 Oct | ||
| 16 Nov – 19 Nov 20264 half-days | Americas bandLive online · 13:00–17:00 ET | 12 of 20 | US$900until 17 Oct | ||
| 23 Nov – 24 Nov 20262 full days | BerlinIn person · Factory Görlitzer Park | 4 of 14 | EUR 1,160until 24 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Embedded Linux & BSP
EMB-1014 days
Yocto Project Fundamentals
BitBake, layers and recipes, from a first build to an image you would actually ship.
Practitioner-taught
SAR 10,500Next 15 Nov
EMB-1104 days
Custom BSP Layers
Writing a board support layer from scratch: machine configuration, kernel recipe, bootloader and device tree.
Practitioner-taught
SAR 12,000Next 25 Oct
EMB-1203 days
Buildroot in Practice
The lighter alternative to Yocto: when Buildroot is the right call and how to use it well.
Practitioner-taught
SAR 7,880Next 11 Oct
EMB-2013 days
U-Boot Porting & Customisation
The bootloader layer: board bring-up, environment, boot scripts and recovery paths.
Practitioner-taught
SAR 9,000Next 18 Oct
EMB-2103 days
Secure Boot & Chain of Trust
Establishing and maintaining a verified boot chain from ROM to userspace, including key management reality.
Practitioner-taught
SAR 9,000Next 15 Nov
EMB-2202 days
Init Systems & Fast Boot
systemd and the alternatives, plus measuring and cutting boot time to a target.
Practitioner-taught
SAR 5,250Next 1 Nov
EMB-3013 days
Read-Only Rootfs & OTA Updates
Update strategies that survive power loss in the field, and the filesystem layout that makes them possible.
Practitioner-taught
SAR 7,880Next 8 Nov
EMB-3202 days
Long-Term Maintenance Strategy
Keeping a shipped product secure and buildable for a decade, which is where most embedded programmes fail.
Practitioner-taught
SAR 6,000Next 22 Nov