{"repo":"embetrix/meta-raspberrypi-secure","free":true,"listed":false,"github":"https://github.com/embetrix/meta-raspberrypi-secure","clone":"git clone https://github.com/embetrix/meta-raspberrypi-secure.git","description":"meta-raspberrypi add-on yocto layer for enhanced security/OTA update🔒","language":"BitBake","stars":70,"topics":["cm4","cm5","cybersecurity","linux-kernel","raspberry-pi","secure-boot","selinux","yocto","yocto-layer","raspberry-pi-4b"],"license":null,"category":"security-tools","readme_excerpt":"meta-raspberrypi-secure A Yocto layer that provides a security-hardened baseline for Raspberry Pi images, extending meta-raspberrypi layer with secure boot, verified and encrypted storage, runtime integrity and a hardened kernel and userspace. Disclaimer: This layer is a starting point, not a finished secure product. You are still responsible for threat modeling your product, removing unused software and services, tailoring defaults (SELinux, firewall, USBGuard, SW Updates, keys management) to your use case, performing license compliance checks, monitoring and remediating CVEs for all included software and independently testing the results. Moreover the maintainers accept no liability for bricked devices from incorrect OTP fuse programming, lost or leaked signing keys or misconfiguration. Provided as is with no warranty and no certification implied (see LICENSE). Features - Hardware root of trust with signed boot chain anchored in the SoC boot ROM - Read-only encrypted/authenticated rootfs with state isolated to data partitions - Encrypted writable data partitions (dm-crypt + trusted key bound to the SoC) - Runtime integrity via IMA/EVM - A/B partitioning for atomic updates of boot and root slots - OTA Update using SWUpdate - Hardened kernel & userspace (SELinux, sysctl, systemd, OpenSSH, busybox) - Network & USB protection (default-drop firewall, USBGuard) - Optional TPM 2.0 support (Infineon SLB9670) - Compliance & auditability (Audit, persistent logs, static code analysis,","default_branch":null,"files":null,"tree":[],"storefront":"/r/embetrix","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/embetrix/meta-raspberrypi-secure/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}