Getting Started with Jochwacht
Prerequisite: An existing Yocto or Buildroot build. Jochwacht does not build anything itself — it works with the output of your build system.
Installation
Via pip (recommended for development)
pipx install jochwacht-sbom jochwacht-sbom . # writes sbom.cdx.json, sends nothing
Without pipx, and the suite
# If pipx is missing: sudo apt install pipx # Access to the full suite on request: [email protected]
Quickstart — Yocto Example
These four steps are the full suite's work. It is not in a public package index — access on request at [email protected]. What is shown is the result of each step. The first one is already covered by the freely available collector jochwacht-sbom.
From Yocto build to CRA compliance status in 4 steps.
Initialise project
Jochwacht automatically detects existing Yocto outputs and generates a configuration file.
→ Found: build/tmp/deploy/licenses/ (247 recipes) → Found: build/tmp/deploy/spdx/ (SPDX outputs) → configuration file created
Import and merge SBOM
Imports the Yocto SPDX files and produces a unified product SBOM in CycloneDX format.
→ 247 recipes imported → product-sbom.cdx.json (847 components)
Run CVE scan
Checks all components against OSV.dev and NVD. Produces a VEX document with the status of each CVE.
→ 847 components checked → 12 CVEs found: 1 CRITICAL, 3 HIGH, 8 MEDIUM → Triage recommended → vex.json created
Check compliance
Validates the SBOM against BSI TR-03183 mandatory fields and returns a traffic-light status.
✓ SBOM present, format valid ✓ 847 components found ⚠ 98% have supplier information — mandatory field, 17 missing ✓ 100% have exact version ✓ 100% have SPDX licence ✓ 100% have PURL ⚠ 1 CRITICAL CVE found Overall: YELLOW — 6 warnings Exit code: 2
Integration into CI/CD pipelines
GitLab CI — .gitlab-ci.yml
sbom: stage: compliance image: python:3.11 script: - pip install jochwacht-sbom - jochwacht-sbom . --sbom sbom.cdx.json artifacts: paths: [sbom.cdx.json]
Jenkins — Jenkinsfile
stage('SBOM') { steps { sh 'pip install jochwacht-sbom' sh 'jochwacht-sbom . --sbom sbom.cdx.json' archiveArtifacts artifacts: 'sbom.cdx.json' } }
Both examples produce the bill of materials and store it as an artifact; nothing is sent. The steps after that — merging, assessing vulnerabilities, audit report — are the suite's job. Access on request.
Jochwacht in your embedded pipeline
Custom Build System
build system
Release, Compliance
layer
RAUC
OTA system
Questions about integration?
We are happy to help with integration into your specific Yocto or Buildroot setup.