Machine-readable ingredient lists — CycloneDX or SPDX JSON — versioned per app release and per firmware image, vulnerability-scanned in place. Private by default; public documents are listed below. The full CRA checklist →
For a connected device the SBOM must cover the firmware image, not just the companion app. Two ways to produce it, both landing in this registry:
create-spdx) or Zephyr (west spdx). Most accurate: it knows every recipe and version.Either way the document is pushed to this registry versioned per image, and vulnerability scans (Grype, Dependency-Track) run against the registry copy — that is the “stays current” half of the CRA row.
Practical guidance, not legal advice. For scope questions — especially whether the CRA applies to you — confirm with counsel.