{"id":13448929,"url":"https://github.com/balena-os/meta-balena","last_synced_at":"2026-05-28T16:01:15.430Z","repository":{"id":34598795,"uuid":"38546546","full_name":"balena-os/meta-balena","owner":"balena-os","description":"A collection of Yocto layers used to build balenaOS images","archived":false,"fork":false,"pushed_at":"2026-05-25T18:50:26.000Z","size":88508,"stargazers_count":988,"open_issues_count":132,"forks_count":129,"subscribers_count":41,"default_branch":"master","last_synced_at":"2026-05-25T20:32:11.404Z","etag":null,"topics":["balena","balenaos","docker","embedded","meta-resin","poky","resin","resinos","yocto"],"latest_commit_sha":null,"homepage":"https://www.balena.io/os","language":"BitBake","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/balena-os.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"COPYING.Apache-2.0","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2015-07-04T20:19:24.000Z","updated_at":"2026-05-25T16:05:39.000Z","dependencies_parsed_at":"2023-09-21T19:20:27.641Z","dependency_job_id":"ae4f379d-2c8c-47ce-a2e3-804406bbfb86","html_url":"https://github.com/balena-os/meta-balena","commit_stats":{"total_commits":5641,"total_committers":87,"mean_commits":64.83908045977012,"dds":0.8191809962772558,"last_synced_commit":"d958ab39c2c3e7fcc9a39c60961f933aeef2a189"},"previous_names":[],"tags_count":1407,"template":false,"template_full_name":null,"purl":"pkg:github/balena-os/meta-balena","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/balena-os%2Fmeta-balena","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/balena-os%2Fmeta-balena/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/balena-os%2Fmeta-balena/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/balena-os%2Fmeta-balena/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/balena-os","download_url":"https://codeload.github.com/balena-os/meta-balena/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/balena-os%2Fmeta-balena/sbom","scorecard":{"id":224588,"data":{"date":"2025-08-11","repo":{"name":"github.com/balena-os/meta-balena","commit":"9462ad02ceb4ee6ecdbe08d59e870f2531a5b2f7"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.8,"checks":[{"name":"Code-Review","score":3,"reason":"Found 7/20 approved changesets -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: tests/suites/os/tests/device-tree/vcdbg:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: COPYING.Apache-2.0:0","Info: FSF or OSI recognized license: Apache License 2.0: COPYING.Apache-2.0:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: topLevel 'actions' permission set to 'read': .github/workflows/bananapi-m1-plus.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/bananapi-m1-plus.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/bananapi-m1-plus.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/beaglebone-ai64.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/beaglebone-ai64.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/beaglebone-ai64.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/beaglebone-pocket.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/beaglebone-pocket.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/beaglebone-pocket.yml:22","Info: topLevel 'packages' permission set to 'read': .github/workflows/beaglebone.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/beaglebone.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/beaglebone.yml:19","Warn: no topLevel permission defined: .github/workflows/flowzone.yml:1","Info: topLevel 'actions' permission set to 'read': .github/workflows/generic-aarch64.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/generic-aarch64.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/generic-aarch64.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/generic-amd64.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/generic-amd64.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/generic-amd64.yml:22","Info: topLevel 'packages' permission set to 'read': .github/workflows/genericx86-64-ext.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/genericx86-64-ext.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/genericx86-64-ext.yml:19","Info: topLevel 'actions' permission set to 'read': .github/workflows/genericx86-64.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/genericx86-64.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/genericx86-64.yml:22","Info: topLevel 'packages' permission set to 'read': .github/workflows/imx6ul-var-dart.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/imx6ul-var-dart.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/imx6ul-var-dart.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/imx7-var-som.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/imx7-var-som.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/imx7-var-som.yml:19","Info: topLevel 'actions' permission set to 'read': .github/workflows/iot-gate-imx8.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/iot-gate-imx8.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/iot-gate-imx8.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/iot-gate-imx8plus.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/iot-gate-imx8plus.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/iot-gate-imx8plus.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/jetson-agx-orin-devkit.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/jetson-agx-orin-devkit.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/jetson-agx-orin-devkit.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/jetson-nano.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/jetson-nano.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/jetson-nano.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/jetson-tx2.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/jetson-tx2.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/jetson-tx2.yml:22","Warn: no topLevel permission defined: .github/workflows/meta-balena-esr.yml:1","Info: topLevel 'actions' permission set to 'read': .github/workflows/nanopi-neo-air.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/nanopi-neo-air.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/nanopi-neo-air.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/nanopi-r2c.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/nanopi-r2c.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/nanopi-r2c.yml:22","Info: topLevel 'contents' permission set to 'read': .github/workflows/orangepi-plus2.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/orangepi-plus2.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/orangepi-plus2.yml:21","Info: topLevel 'actions' permission set to 'read': .github/workflows/owa5x.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/owa5x.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/owa5x.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/raspberrypi.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/raspberrypi.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/raspberrypi.yml:22","Info: topLevel 'packages' permission set to 'read': .github/workflows/raspberrypi2.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/raspberrypi2.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/raspberrypi2.yml:19","Info: topLevel 'actions' permission set to 'read': .github/workflows/raspberrypi3-64.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/raspberrypi3-64.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/raspberrypi3-64.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/raspberrypi3.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/raspberrypi3.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/raspberrypi3.yml:22","Info: topLevel 'packages' permission set to 'read': .github/workflows/raspberrypi4-64.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/raspberrypi4-64.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/raspberrypi4-64.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/revpi-connect-4.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/revpi-connect-4.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/revpi-connect-4.yml:21","Info: topLevel 'actions' permission set to 'read': .github/workflows/revpi-connect-s.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/revpi-connect-s.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/revpi-connect-s.yml:22","Info: topLevel 'packages' permission set to 'read': .github/workflows/revpi-connect.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/revpi-connect.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/revpi-connect.yml:19","Info: topLevel 'actions' permission set to 'read': .github/workflows/revpi-core-3.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/revpi-core-3.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/revpi-core-3.yml:22","Info: topLevel 'packages' permission set to 'read': .github/workflows/rockpi-4b-rk3399.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/rockpi-4b-rk3399.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/rockpi-4b-rk3399.yml:19","Info: topLevel 'actions' permission set to 'read': .github/workflows/surface-go.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/surface-go.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/surface-go.yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/surface-pro-6.yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/surface-pro-6.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/surface-pro-6.yml:22","Warn: no topLevel permission defined: .github/workflows/update-backports.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/var-som-mx6..yml:22","Info: topLevel 'actions' permission set to 'read': .github/workflows/var-som-mx6..yml:19","Info: topLevel 'packages' permission set to 'read': .github/workflows/var-som-mx6..yml:21","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: 'allow deletion' enabled on branch 'master'","Warn: 'force pushes' enabled on branch 'master'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'master'","Warn: 'stale review dismissal' is disabled on branch 'master'","Warn: branch 'master' does not require approvers","Warn: codeowners review is not required on branch 'master'","Warn: 'last push approval' is disabled on branch 'master'","Info: 'up-to-date branches' is required to merge on branch 'master'","Info: status check found to merge onto on branch 'master'","Info: PRs are required in order to make changes on branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 20 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Pinned-Dependencies","score":2,"reason":"dependency not pinned by hash detected -- score normalized to 2","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/bananapi-m1-plus.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/bananapi-m1-plus.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/beaglebone-ai64.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/beaglebone-ai64.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/beaglebone-pocket.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/beaglebone-pocket.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/beaglebone.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/beaglebone.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/flowzone.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/flowzone.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/generic-aarch64.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/generic-aarch64.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/generic-amd64.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/generic-amd64.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/genericx86-64-ext.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/genericx86-64-ext.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/genericx86-64.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/genericx86-64.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/imx6ul-var-dart.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/imx6ul-var-dart.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/imx7-var-som.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/imx7-var-som.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/iot-gate-imx8.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/iot-gate-imx8.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/iot-gate-imx8plus.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/iot-gate-imx8plus.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/jetson-agx-orin-devkit.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/jetson-agx-orin-devkit.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/jetson-nano.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/jetson-nano.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/jetson-tx2.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/jetson-tx2.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/nanopi-neo-air.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/nanopi-neo-air.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/nanopi-r2c.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/nanopi-r2c.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/orangepi-plus2.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/orangepi-plus2.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/owa5x.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/owa5x.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/raspberrypi.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/raspberrypi.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/raspberrypi2.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/raspberrypi2.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/raspberrypi3-64.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/raspberrypi3-64.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/raspberrypi3.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/raspberrypi3.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/raspberrypi4-64.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/raspberrypi4-64.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/revpi-connect-4.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/revpi-connect-4.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/revpi-connect-s.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/revpi-connect-s.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/revpi-connect.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/revpi-connect.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/revpi-core-3.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/revpi-core-3.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/rockpi-4b-rk3399.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/rockpi-4b-rk3399.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/surface-go.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/surface-go.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/surface-pro-6.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/surface-pro-6.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/var-som-mx6..yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/balena-os/meta-balena/var-som-mx6..yml/master?enable=pin","Warn: containerImage not pinned by hash: meta-balena-common/recipes-containers/docker-disk/files/Dockerfile:1: pin your Docker image by updating docker:19.03.10-dind to docker:19.03.10-dind@sha256:764b33780a4306808b7b29b1efde759c6d581fbb5d303660716fcb4eb6a490cd","Warn: containerImage not pinned by hash: meta-balena-common/recipes-containers/mkfs-hostapp-native/files/Dockerfile:1: pin your Docker image by updating debian:trixie to debian:trixie@sha256:6d87375016340817ac2391e670971725a9981cfc24e221c47734681ed0f6c0f5","Warn: containerImage not pinned by hash: meta-balena-common/recipes-kernel/linux/files/Dockerfile:1: pin your Docker image by updating balenalib/intel-nuc-debian:bullseye-20230328 to balenalib/intel-nuc-debian:bullseye-20230328@sha256:999172aba934e845e82467774e55f36df0c782bc56889cb4fe3cc99661b43341","Warn: containerImage not pinned by hash: tests/suites/Dockerfile:3","Warn: containerImage not pinned by hash: tests/suites/Dockerfile:13","Warn: containerImage not pinned by hash: tests/suites/Dockerfile:16","Warn: pipCommand not pinned by hash: .github/workflows/meta-balena-esr.yml:136","Warn: pipCommand not pinned by hash: .github/workflows/meta-balena-esr.yml:137","Warn: pipCommand not pinned by hash: .github/workflows/update-backports.yml:65","Warn: pipCommand not pinned by hash: .github/workflows/update-backports.yml:66","Info:   4 out of   4 GitHub-owned GitHubAction dependencies pinned","Info:   2 out of  35 third-party GitHubAction dependencies pinned","Info:   8 out of  14 containerImage dependencies pinned","Info:   1 out of   1 npmCommand dependencies pinned","Info:   0 out of   4 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":0,"reason":"20 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-p8p7-x288-28g6","Warn: Project is vulnerable to: GHSA-pq67-2wwv-3xjx","Warn: Project is vulnerable to: GHSA-8cj5-5rvv-wf4v","Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3","Warn: Project is vulnerable to: GHSA-cf4h-3jhx-xvhq","Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h","Warn: Project is vulnerable to: GHSA-w7q9-p3jq-fmhm","Warn: Project is vulnerable to: GHSA-xvf7-4v9q-58w6","Warn: Project is vulnerable to: GHSA-hrpp-h998-j3pp","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-v88g-cgmw-v5xw","Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-9c47-m6qq-7p4h","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-hj48-42vr-x3v9","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-j8xg-fqg3-53r7"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T03:24:55.281Z","repository_id":34598795,"created_at":"2025-08-17T03:24:55.281Z","updated_at":"2025-08-17T03:24:55.281Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33615490,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-28T02:00:06.440Z","response_time":99,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["balena","balenaos","docker","embedded","meta-resin","poky","resin","resinos","yocto"],"created_at":"2024-07-31T06:00:24.926Z","updated_at":"2026-05-28T16:01:15.374Z","avatar_url":"https://github.com/balena-os.png","language":"BitBake","funding_links":[],"categories":["BitBake","Operation System","System"],"sub_categories":["Embedded Operation System","Embedded Operation Systems"],"readme":"# Balena.io layers for Yocto\n\n## Description\nThis repository enables building balenaOS for various devices.\n\n## Layers Structure\n* meta-balena-common : layer which contains common recipes for all our supported platforms.\n* meta-balena-* : layers which contain recipes specific to yocto versions.\n* other files : README, COPYING, etc.\n\n## Dependencies\n\n* https://docs.yoctoproject.org/brief-yoctoprojectqs/#build-host-packages\n* docker\n* jq\n\n## Versioning\n\nThe `meta-balena` version is kept in the `DISTRO_VERSION` variable. The `balena-\u003cboard\u003e` version is kept in the file called VERSION located in the root of the `balena-\u003cboard\u003e` repository and read in the build as the variable HOSTOS_VERSION.\n\n* The version of `meta-balena` is in semver format being 3 numbers separated by a dot. The patch number can have a `beta` label. e.g. 1.2.3, 1.2.3-beta1, 2.0.0-beta1.\n* The first `balena-\u003cboard\u003e` release based on a specific `meta-balena` release X.Y.Z, will be X.Y.Z, the same as the `meta-balena` version. Example: the first `balena-\u003cboard\u003e` version based on `meta-balena` 1.2.3 will be 1.2.3.\n* Subsequent `balena-\u003cboard\u003e` releases are constructed by appending to the `meta-balena` version a `rev` label. For example a meta-balena 1.2.3 can go through 3 board revisions, being 1.2.3 the initial revision, and 1.2.3+revN the subsequent ones, with the final version being 1.2.3+rev2 .\n* When updating `meta-balena` version in `balena-\u003cboard\u003e`, the version will reset to the `meta-balena` version. Ex: 1.2.3+rev4 will be updated to 1.2.4 .\n\nWe define host OS version as the `balena-\u003cboard\u003e` version and we use this version as HOSTOS_VERSION.\n\n## Build flags\n\nBefore bitbake-ing with meta-balena support, a few flags can be changed in the conf/local.conf from the build directory.\nEditing of local.conf is to be done after source-ing.\nSee below for explanation on such build flags.\n\n### Configure custom network manager\n\nBy default balena uses NetworkManager on host OS to provide connectivity. If you want to change and use other providers, list your packages using NETWORK_MANAGER_PACKAGES. You can add this variable to local.conf. Here is an example:\n\nNETWORK_MANAGER_PACKAGES = \"mynetworkmanager mynetworkmanager-client\"\n\n### Customizing splash\n\nWe configure all of our initial images to produce a balena logo at boot, shutdown or reboot. But we encourage any user to go and replace that logo with their own.\nAll you have to do is replace the `splash/balena-logo.png` file that you will find in the first partition of our images (boot partition) with your own image.\nNOTE: As it currently stands plymouth expects the image to be named `balena-logo.png`. In older releases this file was called `resin-logo.png`.\n\n### Docker storage driver\n\nBy default the build system will set all the bits needed for the docker to be able to use the `aufs` storage driver. This can be changed by defining `BALENA_STORAGE` in your local.conf. It supports `aufs` and `overlay2`.\n\n### OS development\n\nTo configure a development build that disables quiet boot and allows bootloader shell access, edit the build's `local.conf` adding:\n\n```\nOS_DEVELOPMENT = \"1\"\n```\n\nThis is a development only setting and no `OS_DEVELOPMENT` configured images are deployed.\n\n## The OS\n\n### SSH and Avahi services\n\nThe OS runs SSH (openSSH) on port 22222. Running this service takes advantage of the socket activation systemd feature so the SSH daemon will only run when there is a SSH connection to the device saving idle resources in this way. In order to connect to a device, one can use it's IP when known or resolve the hostname over mDNS as its hostname is advertised over network using an avahi service. When the latter is used, configuration of the client is needed (see for example https://wiki.archlinux.org/index.php/Avahi#Hostname_resolution).\n\n### Time synchronization\n\nAt boot, time is set and synchronized as follows:\n\n* Build time\n* Previous boot system time\n* RTC time when available\n* HTTPs time\n* Network time\n\n#### Build time\n\nInitially time is set from the image build time timestamp, stored in `/etc/timestamp` and generated by the build system when the image is generated.\n\n#### Previous boot system time\n\nThe system then checks whether the previous boot system time was stored in persistent storage and uses it to correct the time. Time is stored in persistent storage on an hourly timer and on system reboot or shutdown. Logging starts after the last boot system time is set.\n\n#### RTC time\n\nWhen an RTC is available (`/dev/rtc`), a `timeinit-rtc` service is started that updates the system clock using the value read from the RTC. If there is no RTC available, the service will not do anything.\n\n#### HTTPs time\n\nAfter a network connectivity event, an HTTPs time synchronization service `timesync-https`, is then used to correct the time from HTTP headers timestamps, assuming the correct system time has not been set from the RTC previously. This guarantees the time is broadly correct and certificates expiration checks won't fail. Other network services are held until this time synchronization happens. By default, the time synchronization uses the NetworkManager connectivity URL defined in the `connectivity` section of `config.json`. To disable the HTTPs time sync and allow other services to run, set the connectivity check URI to 'null'. This will also disable [connectivity checks](#connectivity) too.\n\n#### Network time\n\nThe `chronyd` services is responsible of managing the time afterwards using NTP. It is configured to synchronize every 4h approximately to save bandwidth. If the NTP servers become unreachable, the service will continuously try to update the time. If the time gets unsynchronized, the NTP client service will be restarted to correct failures.\n\nThe time keeping framework explained above provides robust time initialization and management both when RTC is available and when not.\n\n### Bootloader\n\nThe bootloader needs to select the active root filesystem, load, and launch the Linux kernel. It also manages boot counts and rollbacks. BalenaOS supports several bootloaders across the supported devices line-up.\n\n* Balena bootloader\n  * This is the preferred bootloader for new kexec capable devices\n  * It is a minimal Linux kernel that contains all balena's logic, [like rollback support](https://github.com/balena-os/meta-balena/blob/master/meta-balena-common/recipes-core/initrdscripts/files/abroot), in the initramfs so that it does not have to be replicated across different bootloaders\n  * It fetches the final kernel from the active root partition and kexecs into it\n  * The balena bootloader is a requirement for secure boot enabled platforms as it needs to mount and decrypt root filesystems to launch the final kernel. Decrypting disks is not usually supported on standard bootloaders.\n  * It also provides a central environment file, [bootenv](https://github.com/balena-os/meta-balena/blob/bbfe78062182eaacc9a524383144a24b731a7372/meta-balena-common/recipes-support/hostapp-update-hooks/files/99-balena-bootloader#L26), to perform bootloader configuration by the system\n  * Ideally, the balena booloader can be built as an EFI binary and directly launched by an EFI capable bootROM\n  * Alternatively, a vendor bootloader like U-Boot can be minimally configured to launch it\n  * Using the balena bootloader reduces the friction of porting new hardware as modifications to vendor bootloaders are minimal, usually just launch configuration, and all balena logic has already been implemented and tested, and     is the same across all devices\n\n* Other bootloaders supported that can be used to launch the balena bootloader if needed, or on non-kexec capable devices are:\n* U-boot\n  * Is used on most of the legacy supported ARM device-types\n  * Only block devices can be used with BalenaOS, RAW flash devices are not supported\n  * Common functionality is implemented in the [u-boot environment](https://github.com/balena-os/meta-balena/blob/master/meta-balena-common/recipes-bsp/u-boot/patches/env_resin.h), which is provided by the [common OS Yocto layer](https://github.com/balena-os/meta-balena/blob/master/meta-balena-common)\n  * The environment is embedded in the u-boot binary. This allows for the intended configuration to be used with the matching version of BalenaOS and avoids interference from any pre-programmed environment\n  * Device-specific functions are provided by the device repository, either in a [u-boot script](https://github.com/balena-os/balena-raspberrypi/blob/master/layers/meta-balena-raspberrypi/recipes-bsp/rpi-u-boot-scr/rpi-u-boot-scr/raspberrypi4-64/boot.cmd.in) or in the enviroment defined by the [board configuration files](https://github.com/balena-os/balena-iot-gate-imx8plus/blob/master/layers/meta-balena-imx8mplus/recipes-bsp/u-boot/patches/0003-integrate-with-balenaOS.patch)\n  * Specific Jetson modules (TX2, Nano) use an extra extlinux.conf file, which is loaded and parsed by u-boot\n  * Three environment files are stored and loaded by u-boot from the BalenaOS boot partition. [resinOS_uEnv.txt](https://github.com/balena-os/meta-balena/blob/master/meta-balena-common/classes/resin-u-boot.bbclass#L58) is used for storing the active root partition index, [extra_uEnv.txt](https://github.com/balena-os/meta-balena/blob/master/meta-balena-common/classes/resin-u-boot.bbclass#L59) stores device-specific configuration elements like optional kernel command-line parameters as well as any custom selected device-tree while [bootcount.env](https://github.com/balena-os/meta-balena/blob/master/meta-balena-common/classes/resin-u-boot.bbclass#L66) stores the number of failed attempted boot retries during an OS update. NOTE: Custom device-tree selection is supported only on [specific devices](https://docs.balena.io/learn/develop/hardware/i2c-and-spi/#custom-device-trees)\n  * Applies the kernel device-tree overlays specified in [uEnv.txt_internal/uEnv.txt](https://github.com/balena-os/balena-beaglebone/blob/master/layers/meta-balena-beaglebone/recipes-core/images/balena-image-flasher.bbappend) on Beaglebone devices\n* Grub\n  * Is used for the legacy supported x86 device-types\n  * Common functionality is implemented by the OS layer in the [grub configuration template](https://github.com/balena-os/meta-balena/blob/master/meta-balena-common/recipes-bsp/grub/grub-conf/grub.cfg_internal_template)\n* Cboot\n  * Is used on Jetson Xavier devices running L4T 32.X\n  * Loads device-trees from device-specific A/B partitions\n  * Unlike the rest of the bootloaders, it does not support FAT filesystems\n  * The current active root filesystem label is defined in the kernel command line provided by the kernel device-tree. The active rootfs is selected at boot time based on the active device-tree\n* UEFI L4Tlauncher\n  * Is used on the Jetson Orin platforms\n  * Obtains the kernel image path and kernel cmdline arguments from extlinux.conf files\n  * Rollbacks and active root filesystem selection are implemented in [bootloader patches](https://github.com/balena-os/balena-jetson-orin/blob/master/layers/meta-balena-jetson/recipes-bsp/uefi/edk2-firmware-tegra/0005-L4TLauncher-hup-rollback-support-orin-nx.patch) provided bythe balena-jetson-orin [device repository](https://github.com/balena-os/balena-jetson-orin)\n  * Employs the same rollback mechanisms used by balenaOS in u-boot by storing and reading environment variables from the resinOS_uEnv.txt, extra_uEnv.txt and bootcount.env files\n\n### Rollback framework\n\nCheck [docs/rollbacks.md](docs/rollbacks.md) for the rollback documentation\n\n### OS update locks\n\nHost OS update scripts (`safe_reboot` in `hostapp-update`) check for an exclusive `flock()` on `/tmp/balena/updates.lock` in any of the container before rebooting the device. If a process holds an exclusive flock on this file, these scripts will wait until the lock is released before proceeding with the reboot.\n\nThis is independent from the application update lock mechanism managed by the Supervisor. The Supervisor uses a lockfile (file existence) to prevent application updates, while the host OS uses `flock()` to prevent reboots during OS updates.\n\nDuring critical operations, both mechanisms should be used together for full protection. For details on the application update lock and how to combine both, see the [Supervisor update locking documentation](https://github.com/balena-os/balena-supervisor/blob/master/docs/update-locking.md).\n\n#### Creating the flock\n\n##### Shell\n\nUsing [flock](https://linux.die.net/man/1/flock) (Debian: `util-linux` package):\n\n```shell\nflock /tmp/balena/updates.lock -c '... (command to run while locked)'\n```\n\nTo hold the lock across a long-running process:\n\n```shell\nexec {FD}\u003e/tmp/balena/updates.lock\nflock -x $FD || exit 1\n# ... critical section; safe_reboot will wait ...\nexec {FD}\u003e\u0026-\n```\n\n##### Python\n\nUsing `fcntl.flock` (standard library):\n\n```python\nimport fcntl\nimport os\nimport time\n\nLOCK_PATH = '/tmp/balena/updates.lock'\n\ndef with_update_lock(fn):\n    fd = os.open(LOCK_PATH, os.O_CREAT | os.O_EXCL | os.O_RDWR)\n    try:\n        fcntl.flock(fd, fcntl.LOCK_EX)\n        fn()\n    finally:\n        fcntl.flock(fd, fcntl.LOCK_UN)\n        os.close(fd)\n        try:\n            os.unlink(LOCK_PATH)\n        except OSError:\n            pass\n\nwith_update_lock(critical_function)\n```\n\n## Devices support\n\n### WiFi Adapters\n\nWe currently tested and provide explicit support for the following WiFi adapters:\n\n* bcm43143 based adapters\n\n### Modems\n\nWe currently test as part of our release process and provide explicit support for the following modems:\n\n* USB modems (tested on Raspberry Pi 3, Balena Fin, Intel NUC and Nvidia TX2)\n  * Huawei MS2131i-8\n  * Huawei MS2372\n* mPCI modems (tested on Balena Fin and Nvidia TX2 Spacely carrier)\n  * Huawei ME909s-120\n  * Quectel EC20\n  * SIM7600E\n\n### Recommended WiFi USB dongle\n\n* Panda N600 Dual-Band (2.4 GHz + 5 GHz) Wireless-N USB Adapter\nThis USB dongle is based on the Ralink RT5572 chipset and is supported by the generic rt2800usb driver.\nTests have been done on the PAU09 model of the Panda N600 Dual-Band USB Adapter and having the\nfirmware version 0.36 from firmware file rt2870.bin\n\n## How to fix various build errors\n\n* Supervisor fails with a log similar to:\n```\nStep 3 : RUN chmod 700 /entry.sh\n---\u003e Running in 445fe69866f9\noperation not supported\n```\nThis is probably because of a docker bug where, if you update kernel and don't reboot, docker gets confused. The fix is to reboot your system.\nMore info: http://stackoverflow.com/questions/29546388/getting-an-operation-not-supported-error-when-trying-to-run-something-while-bu\n\n## config.json\n\nThe behavior of balenaOS can be configured by setting the following keys in the config.json file in the boot partition. This configuration file is also used by the supervisor.\n\n### hostname\n\n(string) The configured hostname of the device, otherwise the device UUID is used.\n\n### persistentLogging\n\n(boolean) Enable or disable persistent logging on the device - defaults to false. Once persistent journals are enabled, they end up stored as part of the data partition on the device (either on SD card, eMMC, harddisk, etc.). This is located on-device at `/var/log/journal/\u003cuuid\u003e` where the UUID is variable.\n\n### country\n\n(string) [Two-letter country code](https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2) for the country in which the device is operating. This is used for setting the WiFi regulatory domain, and you should check the WiFi device driver for a list of supported country codes.\n\n### ntpServers\n\n(string) A space-separated list of NTP servers to use for time synchronization. Defaults to `resinio.pool.ntp.org` servers:\n\n- `0.resinio.pool.ntp.org`\n- `1.resinio.pool.ntp.org`\n- `2.resinio.pool.ntp.org`\n- `3.resinio.pool.ntp.org`\n\n### dnsServers\n\n(string) A space-separated list of preferred DNS servers to use for name resolution.\n\n- When `dnsServers` is not defined, or empty, Google's DNS server (8.8.8.8) is added to the list of DNS servers obtained via DHCP or statically configured in a NetworkManager connection profile.\n- When `dnsServers` is \"null\" (a string), Google's DNS server (8.8.8.8) will NOT be added as described above.\n- When `dnsServers` is defined and not \"null\", the listed servers will be added to the list of servers obtained via DHCP or statically configured via a NetworkManager connection profile.\n\n### balenaRootCA\n\n(string) A base64-encoded PEM CA certificate that will be installed into the root trust store. This makes the device trust TLS/SSL certificates from this authority. \nThis is useful when the device is running behind a re-encrypting network device, like a transparent proxy or some deep packet inspection devices.\n\n```json\n\"balenaRootCA\": \"4oCU4oCTQkVHSU4gQ0VSVElGSUNBVEXigJTi...\"\n```\n\n### developmentMode\n\nTo enable development mode at runtime:\n\n```json\n\"developmentMode\": true\n```\n\nBy default development mode enables unauthenticated SSH logins unless custom SSH keys are present, in which case SSH key access is enforced.\n\nAlso, development mode provides serial console passwordless login as well as an exposed balena engine socket to use in local mode development.\n\n### os\n\nAn object containing settings that customize the host OS at runtime.\n\n#### network\n\n##### wifi\n\nAn object that defines the configuration related to Wi-Fi.\n\n- \"randomMacAddressScan\" (boolean) Configures MAC address randomization of a Wi-Fi device during scanning\n\nThe following example disables MAC address randomization of Wi-Fi device during scanning:\n\n```json\n\"os\": {\n \"network\" : {\n  \"wifi\": {\n    \"randomMacAddressScan\": false\n  }\n }\n}\n```\n\n##### connectivity\n\nAn object that defines configuration related to networking connectivity checks. This feature builds on NetworkManager's connectivity check, which is further documented in the connectivity section [here](https://developer.gnome.org/NetworkManager/stable/NetworkManager.conf.html).\n\n- \"uri\" (string) Value of the url to query for connectivity checks. Defaults to `$API_ENDPOINT/connectivity-check`.\n- \"interval\" (string) Interval between connectivity checks in seconds. Defaults to 3600. To disable the connectivity checks set the interval to \"0\".\n- \"response\" (string). If set controls what body content is checked for when requesting the URI. If it is an empty value, the HTTP server is expected to answer with status code 204 or send no data.\n\nThe following example configures the connectivity check by passing the balenaCloud connectivity endpoint with a 5-minute interval.\n\n```json\n\"os\": {\n \"network\" : {\n  \"connectivity\": {\n    \"uri\" : \"https://api.balena-cloud.com/connectivity-check\",\n    \"interval\" : \"300\"\n  }\n }\n}\n```\n\n#### udevRules\n\nAn object containing one or more custom udev rules as `key:value` pairs.\n\nTo turn a rule into a format that can be easily added to `config.json`, use the following command:\n\n```shell\ncat rulefilename | jq -sR .\n```\n\nFor example:\n\n```shell\nroot@resin:/etc/udev/rules.d# cat 64.rules | jq -sR .\n\"ACTION!=\\\"add|change\\\", GOTO=\\\"modeswitch_rules_end\\\"\\nKERNEL==\\\"ttyACM*\\\", ATTRS{idVendor}==\\\"1546\\\", ATTRS{idProduct}==\\\"1146\\\", TAG+=\\\"systemd\\\", ENV{SYSTEMD_WANTS}=\\\"u-blox-switch@'%E{DEVNAME}'.service\\\"\\nLBEL=\\\"modeswitch_rules_end\\\"\\n\"\n```\n\nThe following example contains two custom udev rules that will create `/etc/udev/rules.d/56.rules` and `/etc/udev/rules.d/64.rules`. The first time rules are added, or when they are modified, udevd will reload the rules and re-trigger.\n\n```json\n\"os\": {\n \"udevRules\": {\n  \"56\": \"ENV{ID_FS_LABEL_ENC}==\\\"resin-root*\\\", IMPORT{program}=\\\"resin_update_state_probe $devnode\\\", SYMLINK+=\\\"disk/by-state/$env{BALENA_UPDATE_STATE}\\\"\",\n  \"64\" : \"ACTION!=\\\"add|change\\\", GOTO=\\\"modeswitch_rules_end\\\"\\nKERNEL==\\\"ttyACM*\\\", ATTRS{idVendor}==\\\"1546\\\", ATTRS{idProduct}==\\\"1146\\\", TAG+=\\\"systemd\\\", ENV{SYSTEMD_WANTS}=\\\"u-blox-switch@'%E{DEVNAME}'.service\\\"\\nLBEL=\\\"modeswitch_rules_end\\\"\\n\"\n }\n}\n```\n\n#### sshKeys\n\n(Array) An array of strings containing a list of public SSH keys that will be used by the SSH server for authentication.\n\n```json\n\"os\": {\n \"sshKeys\": [\n  \"ssh-rsa AAAAB3Nza...M2JB balena@macbook-pro\",\n  \"ssh-rsa AAAAB3Nza...nFTQ balena@zenbook\"\n ]\n}\n```\n\n#### fan\n\nAn object that defines thermal related configuration. Available for Jetson Orin devices running Jetpack 6 or newer, balenaOS v6.1.24 or newer and Supervisor v16.10.0 or newer.\n\n##### fan.profile\n\n(string) A string which will be used to select the desired cooling profile. Supported values are \"quiet\" and \"cool\". At runtime, this\nconfiguration option should be set through the API or from your balenaCloud dashboard.\n\n```json\n\"os\": {\n \"fan\": {\n  \"profile\":\"cool\"\n }\n}\n```\n\n#### power\n\nAn object that defines power consumption related configuration. Available for Jetson Orin devices running Jetpack 6 or newer, balenaOS v6.1.24 or newer and Supervisor v16.10.0 or newer.\n\n##### power.mode\n\n(string) A string which will be used to select the desired power mode. Supported values for Jetpack 6 and newer are \"low\", \"mid\" and \"high\", where \"low\"\nis the lowest power consumption mode while \"high\" corresponds to MAXN or the highest available power mode for your device type. At runtime, this\nconfiguration option should be set through the API or from your balenaCloud dashboard, and it will cause a device reboot.\n\n```json\n\"os\": {\n \"power\": {\n  \"mode\":\"high\"\n }\n}\n```\n\n#### kernel\n\nAn object that allows configuring kernel settings, which are applied during boot or at runtime.\n\n##### kernel.extraFirmwareVol\n\n(string) A string used for specifying the name of the volume used for storing additional firmware. This volume is used as an additional search path for Linux firmware.\nAt runtime this setting is managed by the Supervisor and the default volume name is \"extra-firmware\".\n\n```json\n\"os\": {\n \"kernel\": {\n  \"extraFirmwareVol\":\"extra-firmware\"\n }\n}\n```\n\n\n### installer\n\nAn object that configures the behaviour of the balenaOS installer image.\n\n#### secureboot\n\n(boolean) Opt-in to installing a secure boot and encrypted disk system for\nsupported device types.\n\n```json\n\"installer\": {\n  \"secureboot\": true\n}\n```\n\n#### migrate\n\nAn object that configures the behaviour of the balenaOS installer migration\nmodule.\n\n##### migrate.force\n\n(boolean) Forces the migration to run. By default the migration only runs if\nthe installer is booting in a single disk system or the `migrate` argument\nis passed in the kernel command line.\n\n```json\n\"installer\": {\n  \"migrate\": {\n    \"force\": true\n  }\n}\n```\n\n#### target_devices\n\n(string) Overrides the default list of provisioning target mediums. May contain one or more\ndevices, separated by spaces. The first one found will be used.\n\n```json\n\"installer\": {\n  \"target_devices\":\"nvme0n1 sda\"\n}\n```\n\n## Yocto version support\n\nThe following Yocto versions are supported:\n * Kirkstone (4.0): **Long Term Support**\n * Honister (3.4): **EOL**\n * Dunfell (3.1): **Long Term Support**\n * Warrior (2.7): **EOL**\n * Thud (2.6): **EOL**\n * Sumo (2.5): **EOL**\n * Rocko (2.4): **EOL**\n * Pyro (2.3): **EOL**\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbalena-os%2Fmeta-balena","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbalena-os%2Fmeta-balena","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbalena-os%2Fmeta-balena/lists"}