EMB-310 · Embedded Linux & BSP

SBOM & Licence Compliance

Producing a defensible software bill of materials and meeting open source licence obligations — now a regulatory matter, not just good practice.

Practitioner 2 days in person4 half-days online Max 14 in person

Who this course is for

Engineers and tech leads who must produce a defensible SBOM and meet open source licence obligations — now that customers and regulators ask for both in writing.

Prerequisites

Embedded Linux build experience (Yocto preferred, Buildroot acceptable)No legal background requiredCommand-line fluency

Course outline

Day 1 — Licences as engineering constraints

  • Licence classes: permissive, weak copyleft, strong copyleft and what each obliges
  • The copyleft boundary in practice: linking, kernel modules and the LGPL cases
  • Reading a package's licence honestly: what upstream declares vs what the code contains
  • Yocto licence machinery: LICENSE fields, licence manifests, LICENSE_FLAGS and the archiver class
  • Source release obligations: what you must ship when asked

Day 2 — SBOM production and what it feeds

  • What an SBOM is for: vulnerability response, customer questionnaires, regulation
  • SPDX and CycloneDX generation from a Yocto build
  • SBOM quality: provenance, versions, patches and the gaps that make an SBOM misleading
  • Automating source-release artefacts so a request is a build, not a project
  • Feeding the SBOM to vulnerability monitoring: CVE matching and its false-positive problem

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Generate a licence manifest for a real image, audit it against the actual sources and fix the discrepancies you find
  2. Lab: Run the archiver class and produce a complete source-release bundle for a GPL-covered component set
  3. Lab: Generate SPDX and CycloneDX SBOMs for the same image and compare what each captures
  4. Lab: Match the SBOM against a CVE feed and triage the results into a defensible applies/does-not-apply record
  5. Lab: Simulate a customer source request end to end: from SBOM entry to delivered source archive, timed

Capstone project

Take a product image and produce its complete compliance pack: an audited licence manifest, SPDX and CycloneDX SBOMs, the automated source-release bundle for copyleft components, and a vulnerability-monitoring record showing each flagged CVE triaged with evidence — packaged so a customer or auditor could rerun any step.

What you leave with

  • A licence manifest you can defend line by line
  • Working SPDX and CycloneDX generation from your build
  • Automated source-release artefacts, not a scramble
  • A CVE-triage record tied to your actual component set
  • A repeatable compliance pipeline instead of a heroic effort per release

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Engineers and tech leads who must produce a defensible SBOM and meet open source licence obligations — now that customers and regulators ask for both in writing. It sits at practitioner level within the Embedded Linux & BSP track.

What do I need to know already?

Specific prerequisites for this course: Embedded Linux build experience (Yocto preferred, Buildroot acceptable); No legal background required; Command-line fluency. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
25 Oct – 26 Oct 20262 full days RiyadhIn person · KAFD Conference Centre 4 of 14 —SAR 5,250
25 Oct – 26 Oct 20262 full days Kuwait CityIn person · Al Hamra Tower 9 of 14 —KWD 430
1 Nov – 2 Nov 20262 full days MuscatIn person · Knowledge Oasis Muscat 4 of 14 —OMR 540
8 Nov – 11 Nov 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 18 of 20 US$900until 9 OctUS$1,000
9 Nov – 10 Nov 20262 full days OttawaIn person · Kanata North Tech Park 9 of 14 CAD 1,710until 10 OctCAD 1,900
9 Nov – 10 Nov 20262 full days TorontoIn person · MaRS Discovery District 4 of 14 CAD 1,710until 10 OctCAD 1,900
9 Nov – 12 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 7 of 20 US$900until 10 OctUS$1,000
16 Nov – 17 Nov 20262 full days LondonIn person · Shoreditch Works 9 of 14 GBP 980until 17 OctGBP 1,090
16 Nov – 19 Nov 20264 half-days Americas bandLive online · 13:00–17:00 ET 12 of 20 US$900until 17 OctUS$1,000
23 Nov – 24 Nov 20262 full days BerlinIn person · Factory Görlitzer Park 4 of 14 EUR 1,160until 24 OctEUR 1,290

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Embedded Linux & BSP

EMB-1014 days Yocto Project Fundamentals BitBake, layers and recipes, from a first build to an image you would actually ship. Practitioner Practitioner-taught SAR 10,500Next 15 Nov EMB-1104 days Custom BSP Layers Writing a board support layer from scratch: machine configuration, kernel recipe, bootloader and device tree. Advanced Practitioner-taught SAR 12,000Next 25 Oct EMB-1203 days Buildroot in Practice The lighter alternative to Yocto: when Buildroot is the right call and how to use it well. Practitioner Practitioner-taught SAR 7,880Next 11 Oct EMB-2013 days U-Boot Porting & Customisation The bootloader layer: board bring-up, environment, boot scripts and recovery paths. Advanced Practitioner-taught SAR 9,000Next 18 Oct EMB-2103 days Secure Boot & Chain of Trust Establishing and maintaining a verified boot chain from ROM to userspace, including key management reality. Advanced Practitioner-taught SAR 9,000Next 15 Nov EMB-2202 days Init Systems & Fast Boot systemd and the alternatives, plus measuring and cutting boot time to a target. Practitioner Practitioner-taught SAR 5,250Next 1 Nov EMB-3013 days Read-Only Rootfs & OTA Updates Update strategies that survive power loss in the field, and the filesystem layout that makes them possible. Practitioner Practitioner-taught SAR 7,880Next 8 Nov EMB-3202 days Long-Term Maintenance Strategy Keeping a shipped product secure and buildable for a decade, which is where most embedded programmes fail. Advanced Practitioner-taught SAR 6,000Next 22 Nov