Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than multiarch arm64 / x86_64 aren't in scope. Only tags have stable history. Currently maintained at https://github.com/anthraxx/linux-hardened.
☆441Dec 4, 2025Updated 3 months ago
Alternatives and similar repositories for linux-hardened
Users that are interested in linux-hardened are comparing it to the libraries listed below
Sorting:
- Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than m…☆696Feb 21, 2026Updated last week
- Unofficial forward ports of the last publicly available grsecurity patch☆152Aug 10, 2018Updated 7 years ago
- Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and gl…☆1,743Updated this week
- Arch Linux package for the Linux Kernel and modules with grsecurity/PaX patches.☆20Apr 26, 2017Updated 8 years ago
- Hardware-based attestation and intrusion detection app for Android. It provides both local verification with another Android device via Q…☆636Feb 23, 2026Updated last week
- Base SELinux policy (extended by per-device repositories)☆20Feb 13, 2026Updated 2 weeks ago
- PaX exception daemon - Temporarily abandoned due to the PaX and grsecurity patches becoming private☆40Jan 29, 2017Updated 9 years ago
- A minimal Linux that runs as a coreboot or LinuxBoot ROM payload to provide a secure, flexible boot environment for laptops, workstations…☆1,534Updated this week
- ☆10Feb 13, 2026Updated 2 weeks ago
- Hardened kernel configuration optimized for virtual machines. - https://www.kicksecure.com/wiki/Hardened-kernel☆53Feb 14, 2026Updated 2 weeks ago
- Hardened Android standard C library. Some of the past hardening has not yet been ported from Marshmallow, Nougat and Oreo to this Android…☆148Feb 13, 2026Updated 2 weeks ago
- Pixel and Pixel XL kernel sources.☆11Oct 7, 2019Updated 6 years ago
- grsecurity is the most advanced Linux kernel hardening patchset. This repository, not affiliated with the upstream project, aggregate mos…☆86Apr 26, 2017Updated 8 years ago
- Automatic background updater for modern Android. See https://github.com/GrapheneOS/script/blob/16-qpr2/generate-metadata for the server m…☆43Feb 13, 2026Updated 2 weeks ago
- USBGuard is a software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as …☆1,304Jan 27, 2026Updated last month
- Linux Kernel Source Tree Reducer☆81Oct 29, 2024Updated last year
- attestation.app remote attestation server. Server code for use with the Auditor app: https://github.com/GrapheneOS/Auditor. It provides t…☆150Updated this week
- ☆10Feb 13, 2026Updated 2 weeks ago
- Fend off malware at Qubes VM startup☆81May 1, 2023Updated 2 years ago
- PKGBUILDs to build SELinux enabled packages for Arch Linux☆168Feb 9, 2026Updated 3 weeks ago
- Session ticket key rotation scripting / systemd units for nginx to work around the lack of built-in support. This may eventually be exten…☆12Aug 1, 2022Updated 3 years ago
- Repo manifest for the GrapheneOS mobile privacy and security hardening project.☆459Updated this week
- Arch Linux Security Tracker☆128Dec 14, 2025Updated 2 months ago
- deprecated - maybe replaced by: `apparmor.d`☆85Jan 15, 2024Updated 2 years ago
- AppArmor profile for The Tor Browser Bundle (TBB) - https://www.whonix.org/wiki/AppArmor - for better security (hardening).☆21Sep 19, 2025Updated 5 months ago
- Tor Browser Starter. Open Link Confirmation; Qubes integration; Command line --new-tab, --new-window; start menu entry; This package is p…☆14Feb 1, 2026Updated last month
- Linux namespaces and seccomp-bpf sandbox☆7,100Updated this week
- Scripts that help with administration and usage of Qubes OS☆39Jun 6, 2021Updated 4 years ago
- Base and recommended kernel configurations. The base configurations are enforced by the VTS and are modified to permit GrapheneOS changes…☆17Dec 4, 2025Updated 3 months ago
- Linux 5.10 LTS branch.☆15Mar 4, 2025Updated last year
- Tool for partial deblobbing of Intel ME/TXE firmware images☆4,906May 28, 2024Updated last year
- Zen Patched Kernel Sources☆2,452Updated this week
- A tool for checking the security hardening options of the Linux kernel☆2,037Dec 27, 2025Updated 2 months ago
- [MIRROR] musl development overlay☆102Oct 6, 2025Updated 4 months ago
- Wrapper scripts for building hardened executables by default (deprecated, replaced by standard Arch Linux toolchain changes)☆29Aug 18, 2015Updated 10 years ago
- (read-only mirror)☆19Jan 10, 2023Updated 3 years ago
- a radical and experimental distribution based on musl libc and busybox☆565Sep 24, 2025Updated 5 months ago
- Platform Security Assessment Framework☆3,187Feb 24, 2026Updated last week
- Make Build System (being phased out upstream)☆68Feb 13, 2026Updated 2 weeks ago