As Dyngnosis says:
“Bill of Materials for embedded devices could/should include a list of included 3rd party libraries. (Think heartbleed on an infusion pump)”
Consumers should know a lot more about the details of what is included in firmware. U-Boot has SPDX metadata.
