Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than multiarch arm64 / x86_64 aren't in scope. Only tags have stable history. Currently maintained at https://github.com/anthraxx/linux-hardened.
☆447Dec 4, 2025Updated 8 months ago
Alternatives and similar repositories for linux-hardened
Users that are interested in linux-hardened are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Unofficial forward ports of the last publicly available grsecurity patch☆151Aug 10, 2018Updated 8 years ago
- Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and gl…☆1,980Updated this week
- Hardware-based attestation and intrusion detection app for Android. It provides both local verification with another Android device via Q…☆691Updated this week
- PaX exception daemon - Temporarily abandoned due to the PaX and grsecurity patches becoming private☆40Jan 29, 2017Updated 9 years ago
- Base SELinux policy (extended by per-device repositories)☆22Aug 13, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Arch Linux package for the Linux Kernel and modules with grsecurity/PaX patches.☆20Apr 26, 2017Updated 9 years ago
- Pixel and Pixel XL kernel sources.☆11Oct 7, 2019Updated 6 years ago
- ☆11Aug 13, 2026Updated 2 weeks ago
- Linux 5.10 LTS branch.☆16Mar 4, 2025Updated last year
- ☆14Aug 13, 2026Updated 2 weeks ago
- Session ticket key rotation scripting / systemd units for nginx to work around the lack of built-in support. This may eventually be exten…☆12Aug 1, 2022Updated 4 years ago
- Base and recommended kernel configurations. The base configurations are enforced by the VTS and are modified to permit GrapheneOS changes…☆17Dec 4, 2025Updated 8 months ago
- A minimal Linux that runs as a coreboot or LinuxBoot ROM payload to provide a secure, flexible boot environment for laptops, workstations…☆1,586Aug 22, 2026Updated last week
- attestation.app remote attestation server. Server code for use with the Auditor app: https://github.com/GrapheneOS/Auditor. It provides t…☆164Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- grsecurity is the most advanced Linux kernel hardening patchset. This repository, not affiliated with the upstream project, aggregate mos…☆88Apr 26, 2017Updated 9 years ago
- Hardened Android standard C library. Some of the past hardening has not yet been ported from Marshmallow, Nougat and Oreo to this Android…☆173Aug 13, 2026Updated 2 weeks ago
- USBGuard is a software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as …☆1,377Jan 27, 2026Updated 7 months ago
- Linux Kernel Source Tree Reducer☆81Oct 29, 2024Updated last year
- Hardened kernel configuration optimized for virtual machines and hosts☆59Updated this week
- Automatic background updater for modern Android. See https://github.com/GrapheneOS/script/blob/-/generate-metadata for the server metadat…☆46Aug 18, 2026Updated last week
- A collection of tools to implement a simple Unix bus. https://skarnet.org/software/skabus/☆27Jun 20, 2026Updated 2 months ago
- Make Build System (being phased out upstream)☆71Aug 13, 2026Updated 2 weeks ago
- deprecated - maybe replaced by: `apparmor.d`☆85Jan 15, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A tool to build runnable Linux images with s6 and s6-rc☆40Jul 14, 2026Updated last month
- Fend off malware at Qubes VM startup☆80May 1, 2023Updated 3 years ago
- Randomizes the system clock at boot to reduce time based fingerprinting before secure time synchronization☆14Aug 23, 2026Updated last week
- Linux namespaces and seccomp-bpf sandbox☆7,620Updated this week
- More patches for MUSL, in addition to those the gentoo overlay provides.☆14Jun 30, 2018Updated 8 years ago
- CLIP OS toolkit (cosmk)☆16Oct 25, 2021Updated 4 years ago
- Scripting for generating signed production releases of AOSP and metadata for the Updater app along with partially automated maintenance o…☆45Aug 22, 2026Updated last week
- CLIP OS Manifest☆10Nov 4, 2020Updated 5 years ago
- ☆379Oct 30, 2025Updated 10 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Arch Linux Security Tracker☆135Dec 14, 2025Updated 8 months ago
- Huffman decompression for version 11.x Intel ME modules☆34Oct 3, 2017Updated 8 years ago
- Privacy and security enhanced releases of Chromium for GrapheneOS. Vanadium provides the WebView and standard user-facing browser on Grap…☆2,099Updated this week
- Hardened kernel generation - Deprecated☆48Apr 3, 2017Updated 9 years ago
- OZ: a sandboxing system targeting everyday workstation applications☆441Apr 18, 2018Updated 8 years ago
- BTC :1JUhp2T15jPM9Y5r3uWmiyzMbAaRMNdoQg,LTC: LfDZfSaoyGtm8nEmfE4tsz8MtajPXfDAYd☆17Sep 16, 2017Updated 8 years ago
- Pixel 6 and Pixel 6 Pro device sources.☆18Nov 12, 2025Updated 9 months ago