Yocto security sbom
Skill Higangssh/yocto-agent-skills/skills/yocto-security-sbom
Official-doc-first Yocto Project and BitBake skills for AI coding agents
npx -y skills add Higangssh/yocto-agent-skills --skill yocto-security-sbomAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 5 stars5 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Review and debug Yocto license metadata, LIC_FILES_CHKSUM, LICENSE_FLAGS, incompatible licenses, license manifests, SPDX/SBOM generation, CVE checking, archiver/copyleft source compliance, and security policy. Use for compliance, CVE, SBOM, license, commercial license, source archiving, or security review questions.
SKILL.md
2.2 KB, as published. Nobody here has run it
Yocto Security SBOM
Use this skill for security, license, CVE, SBOM, and compliance workflows. Treat class names and output paths as release-sensitive.
Evidence
Ask for or inspect:
target Yocto release
recipe LICENSE and LIC_FILES_CHKSUM
license QA error
image/license manifest output
SPDX/SBOM configuration and output
CVE check configuration and reports
archiver/copyleft configuration
commercial license policy
Useful commands:
bitbake -e <recipe> | rg '^(LICENSE|LIC_FILES_CHKSUM|LICENSE_FLAGS|LICENSE_FLAGS_ACCEPTED|INCOMPATIBLE_LICENSE|CVE|SPDX|ARCHIVER)[:=]'
bitbake -c populate_lic <recipe>
bitbake <image>
find tmp/deploy -maxdepth 4 -iname '*spdx*' -o -path '*licenses*'
Review Rules
LIC_FILES_CHKSUMis mandatory unlessLICENSE = "CLOSED".- License checksum mismatch means upstream license text changed; inspect before updating the checksum.
- Keep commercial license acceptance explicit and narrow.
- Verify current release SBOM/CVE class names before recommending
create-spdx, CVE classes, or output paths. - Use archiver/copyleft flows when source offer obligations matter.
- Do not confuse build-time
DEPENDSwith packages included in final image license manifests.
References
- Read ../../references/yocto/security-sbom.md.
- Read ../../references/bitbake/classes-core.md for
license,archiver,create-spdx, and release-sensitive security classes. - Read ../../references/yocto/migration.md for SBOM/CVE release changes.
Output
Answer with:
- license/security artifact being debugged
- release-sensitive class or variable to verify
- exact metadata or policy fix
- validation command and expected artifact
- compliance caveat if legal interpretation is required