cancel
Showing results for 
Search instead for 
Did you mean: 

SBOM for the code generated by STM32CubeMX

Thiha2025
Associate II

I used STM32F103 in a mix configuration of bare-metal&HAL supplied by STM32CubeMX. I'm not sure ST can provide the documentation that can be referenced to generate the SBOM for cybersecurity purpose. Is there any recommended tool to scan the firmware project folder. If ST is yet to provide a way to auto-generate SBOM for cybersecurity requirement, possible to use manually curated SPDX-based JSON format for machine processing. If anyone had gone through similar process for regulatory review, can you please share the experience? Any inputs/advise would be greatly appreciated. Thank you.

2 REPLIES 2
Imen.D
ST Employee

Hello @Thiha2025 

I share the following ST wiki pages that may help you and answer your questions:

When your question is answered, please close this topic by clicking "Accept as Solution".
Thanks
Imen

Thanks so much for the link. I found this "Yes, ST has decided to publicly provide CycloneDX SBOM for any STM32Cube embedded software deliverable." However, I could not find "sbom_cdx.json" for F1 series after I downloaded the latest STM32CubeF1 package. I realized that I can find the json file for F7 series under STM32Cube_FW_F7_V1.17.4. Can you shed some light on this?