Published event
DeveloperTools PolicyChange 1 source(s)

At-Protocol Based Encrypted Firmware Management Project

Updated October 6, 2026 · 12:07 AM · 9 · source date October 5, 2026

Summary

At-Protocol Based Encrypted Firmware Management Project ListeningPost / open-firmware-manager Public Notifications You must be signed in to change notification settings Fork 0 Star 3 Branches Tags Open more actions menu Latest commit History 1 Commit 1 Commit Folders and files Name Name Last commit message Last commit date .github/ workflows .github/ workflows apps apps cli cli docs docs examples examples lexicons lexicons packages packages .gitignore .gitignore .npmrc .npmrc LICENSE LICENSE README.md README.md SECURITY.md SECURITY.md package.json package.json pnpm-lock.yaml pnpm-lock.yaml pnpm-workspace.yaml pnpm-workspace.yaml tsconfig.base.json tsconfig.base.json Repository files navigation Open Firmware Production system for cryptographically signed software distribution over AT Protocol . The distribution center is a PDS .

Why it matters

This PolicyChange is relevant to the technology intelligence record because it involves GitHub, Docker. The source article should remain the factual reference for follow-up coverage.

Key facts
  • ListeningPost / open-firmware-manager Public Notifications You must be signed in to change notification settings Fork 0 Star 3 Branches Tags Open more actions menu Latest commit History 1 Commit 1 Commit Folders and files Name Name Last commit message Last commit date .github/ workflows .github/ workflows apps apps cli cli docs docs examples examples lexicons lexicons packages packages .gitignore .gitignore .npmrc .npmrc LICENSE LICENSE README.md README.md SECURITY.md SECURITY.md package.json package.json pnpm-lock.yaml pnpm-lock.yaml pnpm-workspace.yaml pnpm-workspace.yaml tsconfig.base.json tsconfig.base.json Repository files navigation Open Firmware Production system for cryptographically signed software distribution over AT Protocol .
  • The distribution center is a PDS .
  • Publishers write signed release chains (records + blobs).
  • Edge agents and Sidekar pull, audit, and apply.
  • @open-firmware/core Chunking, Phase A audit, service windows No @open-firmware/atproto-lite Vanilla XRPC client No @open-firmware/host Publish releases to PDS No @open-firmware/client IoT/edge pull + verify + apply hooks No @open-firmware/sidekar Server agent; optional Docker apply Optional @open-firmware/iot Device identity, factory reset, sealed jobs No @open-firmware/utility Admin: approve join, set password, jobs No @open-firmware/server Private control plane API No ofw (Rust CLI) release / publish / pipeline-ack / audit No Trust model Author DID + PDS commit signatures authenticate records Content digests (SHA-256) on release + chunks Phase A validates the full chain before download Phase B verifies blobs and full-image hash before apply AppViews and dashboards are never the trust root.
  • Quick start (guided walkthrough) cd examples/full-stack ./scripts/gen-pds-secrets.sh docker compose up --build -d # Guided UI (plain language + live status): # http://localhost:8099 # Full written tour: # examples/full-stack/WALKTHROUGH.md ./scripts/publish-to-pds.sh " Hello from Open Firmware " # Workload: http://localhost:8080 # PDS: http://127.0.0.1:2583/xrpc/_health Production publish cd cli && cargo install --path .
Entities in this story

Companies

GitHub→

Products

Docker→
Related events