landlock-lsm / islandLinks
Sandboxing tool powered by Landlock
☆61Updated this week
Alternatives and similar repositories for island
Users that are interested in island are comparing it to the libraries listed below
Sorting:
- Usage of enabled-by-default hardening-related compiler flags across Linux distributions☆60Updated 9 months ago
- Source code of https://whatsrc.org/☆43Updated 7 months ago
- TPM 2.0 plugin for age☆113Updated 4 months ago
- Build postprocessor to reset metadata fields for build reproducibility☆139Updated 2 months ago
- Documentation about the xz backdoor created by #xz-backdoor-reversing☆59Updated last year
- Secure Boot certificates from the Framework Laptop☆31Updated 3 years ago
- UAPI Group Specifications☆124Updated last week
- Linux kernel source tree with OpenPaX patch☆100Updated 8 months ago
- 🗜️ fast r/o squashfs implementation written in C.☆49Updated last week
- An OpenPGP backend for rpm using Sequoia PGP☆20Updated last week
- SSH Certificate Authority with device attestation☆55Updated last year
- OpenBSD APIs ported to Linux userspace using SECCOMP BPF and Landlock LSM☆122Updated 2 years ago
- A collection of ideas for new kernel features☆66Updated last week
- Systemd Hardening Helper - Automatic systemd service hardening guided by strace profiling☆300Updated 3 weeks ago
- Sécurix is a NixOS-based secure operating system tailored for small to medium-sized teams. It provides a minimal, hardened environment wi…☆77Updated this week
- manage initrd cpio archives☆45Updated this week
- Calculate future (next boot) TPM PCRs after a kernel upgrade☆41Updated 6 months ago
- nscd-compatible daemon that proxies lookups, without caching☆68Updated last week
- Reconfigurable and Updateable Embedded Systems☆33Updated last year
- ssh-agent for TPMs☆532Updated last week
- Standalone portable header-based implementation of FORTIFY_SOURCE=3☆34Updated 3 weeks ago
- ☆17Updated 2 years ago
- Remote sudo authenticated via ssh-agent☆153Updated last month
- A high level language for SELinux policy☆59Updated 4 months ago
- Building reproducible and immutable NixOS images. Accompanying repository for my All Systems Go 2024 talk.☆23Updated last year
- Allow guest VMs to open windows on the host☆163Updated 5 months ago
- Systemd unit generator for a verity protected Nix Store☆30Updated last month
- The InitWare Suite of Middleware allows you to manage services and system resources as logical entities called units. Its main component …☆300Updated last year
- Age plugin to encrypt files with fido2 tokens using the hmac-secret extension and non-discoverable credentials.☆75Updated this week
- A kexec-based bootloader☆25Updated this week