Quickstart — 5 minutes

Getting Started with Jochwacht

Prerequisite: An existing Yocto or Buildroot build. Jochwacht does not build anything itself — it works with the output of your build system.

Installation

Via pip (recommended for development)

pipx install jochwacht-sbom
jochwacht-sbom .

# writes sbom.cdx.json, sends nothing

Without pipx, and the suite

# If pipx is missing:
sudo apt install pipx

# Access to the full suite on request:
[email protected]

Quickstart — Yocto Example

These four steps are the full suite's work. It is not in a public package index — access on request at [email protected]. What is shown is the result of each step. The first one is already covered by the freely available collector jochwacht-sbom.

From Yocto build to CRA compliance status in 4 steps.

1

Initialise project

Jochwacht automatically detects existing Yocto outputs and generates a configuration file.

→ Found: build/tmp/deploy/licenses/ (247 recipes)
→ Found: build/tmp/deploy/spdx/ (SPDX outputs)
→ configuration file created
2

Import and merge SBOM

Imports the Yocto SPDX files and produces a unified product SBOM in CycloneDX format.

→ 247 recipes imported
→ product-sbom.cdx.json (847 components)
3

Run CVE scan

Checks all components against OSV.dev and NVD. Produces a VEX document with the status of each CVE.

→ 847 components checked
→ 12 CVEs found:
   1 CRITICAL, 3 HIGH, 8 MEDIUM
→ Triage recommended
→ vex.json created
4

Check compliance

Validates the SBOM against BSI TR-03183 mandatory fields and returns a traffic-light status.

✓ SBOM present, format valid
✓ 847 components found
⚠ 98% have supplier information — mandatory field, 17 missing
✓ 100% have exact version
✓ 100% have SPDX licence
✓ 100% have PURL
⚠ 1 CRITICAL CVE found

Overall: YELLOW — 6 warnings
Exit code: 2

Integration into CI/CD pipelines

GitLab CI — .gitlab-ci.yml

sbom:
  stage: compliance
  image: python:3.11
  script:
    - pip install jochwacht-sbom
    - jochwacht-sbom . --sbom sbom.cdx.json
  artifacts:
    paths: [sbom.cdx.json]

Jenkins — Jenkinsfile

stage('SBOM') {
  steps {
    sh 'pip install jochwacht-sbom'
    sh 'jochwacht-sbom . --sbom sbom.cdx.json'
    archiveArtifacts artifacts: 'sbom.cdx.json'
  }
}

Both examples produce the bill of materials and store it as an artifact; nothing is sent. The steps after that — merging, assessing vulnerabilities, audit report — are the suite's job. Access on request.

Jochwacht in your embedded pipeline

🔧
Build System
Yocto / Buildroot
Custom Build System
Your existing
build system
→
📋
Jochwacht
SBOM, CVE,
Release, Compliance
The missing
layer
→
🚀
OTA / Deploy
Mender / SWUpdate
RAUC
Your existing
OTA system

Questions about integration?

We are happy to help with integration into your specific Yocto or Buildroot setup.