
Author
Joshua Watt
Software Developer at Garmin, member of the OpenEmbedded Technical Steering Committee, and member of the Yocto Project Technical Steering Committee. Joshua works extensively on SBOM generation in the Yocto Project, including the SPDX 2.2 and SPDX 3.0 implementations in OpenEmbedded-Core, and maintains standalone tooling for working with SPDX 3.0 documents.
Posts by Joshua Watt
SPDX 3.0 in Yocto: What Changed and Why It Matters
SPDX 3.0 support was added in the Styhead release (Yocto 5.1) and represents a significant architectural leap. The implementation lives in...
A Deep Dive into Yocto's SPDX 2.2 Pipeline
The SPDX 2.2 implementation in the Yocto Project has been stable since the Honister release (Yocto 3.4, October 2021). It is the...
How Yocto Generates SBOMs Behind the Scenes: A Deep Dive into SPDX 2.2 and SPDX 3.0
If you are building embedded Linux products with the Yocto Project, you are sitting on one of the most mature and sophisticated SBOM...