R&D: create a mechanism to share/publish and reuse artifacts (especially SPDX files); integrate it with yocto
This issue maybe needs to be converted into a requirement
(Yocto has tools to create/collect SPDX data, it should be checked how to integrate it with a public a4f data pool to enable device makers to use data from the pool both in their compliance pipelines and when building images/releases intended to be distributed - in order to create SPDX SBOM at build time from a4f pool data)