{"id":13575751,"url":"https://github.com/facebook/openbmc","last_synced_at":"2026-05-29T00:01:39.346Z","repository":{"id":28403347,"uuid":"31917712","full_name":"facebook/openbmc","owner":"facebook","description":"OpenBMC is an open software framework to build a complete Linux image for a Board Management Controller (BMC).","archived":false,"fork":false,"pushed_at":"2026-05-23T04:35:09.000Z","size":70755,"stargazers_count":679,"open_issues_count":51,"forks_count":305,"subscribers_count":119,"default_branch":"helium","last_synced_at":"2026-05-24T06:03:03.555Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/facebook.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2015-03-09T19:18:35.000Z","updated_at":"2026-05-23T04:35:13.000Z","dependencies_parsed_at":"2024-05-20T16:59:28.906Z","dependency_job_id":"bc738b9a-9846-422d-91fc-a06d0e176993","html_url":"https://github.com/facebook/openbmc","commit_stats":{"total_commits":15420,"total_committers":216,"mean_commits":71.38888888888889,"dds":0.8356679636835279,"last_synced_commit":"bfd15889f4b91305f584c6b4c1ec0b1b5c4484ad"},"previous_names":[],"tags_count":142,"template":false,"template_full_name":null,"purl":"pkg:github/facebook/openbmc","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fopenbmc","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fopenbmc/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fopenbmc/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fopenbmc/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/facebook","download_url":"https://codeload.github.com/facebook/openbmc/tar.gz/refs/heads/helium","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/facebook%2Fopenbmc/sbom","scorecard":{"id":251124,"data":{"date":"2025-08-11","repo":{"name":"github.com/facebook/openbmc","commit":"e677bf31822e1d537e71b9df75730973b08dc85a"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.9,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":9,"reason":"Found 28/30 approved changesets -- score normalized to 9","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/flashy.yml:1","Warn: no topLevel permission defined: .github/workflows/lint_pr.yml:1","Warn: no topLevel permission defined: .github/workflows/qemu.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Security-Policy","score":9,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/facebook/.github/SECURITY.md:1","Info: Found linked content: github.com/facebook/.github/SECURITY.md:1","Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy","Info: Found text in security policy: github.com/facebook/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Branch-Protection","score":3,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'helium'","Info: 'force pushes' disabled on branch 'helium'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'helium'","Warn: branch 'helium' does not require approvers","Warn: codeowners review is not required on branch 'helium'","Warn: 'up-to-date branches' is disabled on branch 'helium'","Info: status check found to merge onto on branch 'helium'","Warn: PRs are not required to make changes on branch 'helium'; or we don't have data to detect it.If you think it might be the latter, make sure to run Scorecard with a PAT or use Repo Rules (that are always public) instead of Branch Protection settings"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"License","score":0,"reason":"license file not detected","details":["Warn: project does not have a license file"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Vulnerabilities","score":1,"reason":"9 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: PYSEC-2019-217 / GHSA-462w-v97r-4m45","Warn: Project is vulnerable to: PYSEC-2014-8 / GHSA-8r7q-cvjq-x353","Warn: Project is vulnerable to: GHSA-cpwx-vrp4-4pq7","Warn: Project is vulnerable to: PYSEC-2014-82 / GHSA-fqh9-2qgg-h84h","Warn: Project is vulnerable to: PYSEC-2021-66 / GHSA-g3rq-g295-4j3m","Warn: Project is vulnerable to: GHSA-h5c8-rqwp-cp95","Warn: Project is vulnerable to: GHSA-h75v-3vvj-5mfj","Warn: Project is vulnerable to: PYSEC-2019-220 / GHSA-hj2j-77xm-mc5v","Warn: Project is vulnerable to: GHSA-q2x7-8rv6-6q7h"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flashy.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/flashy.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint_pr.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/lint_pr.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint_pr.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/lint_pr.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint_pr.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/lint_pr.yml/helium?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint_pr.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/lint_pr.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint_pr.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/lint_pr.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qemu.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/qemu.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qemu.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/qemu.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qemu.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/qemu.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qemu.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/qemu.yml/helium?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qemu.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/facebook/openbmc/qemu.yml/helium?enable=pin","Warn: containerImage not pinned by hash: .github/actions/build_qemu/Dockerfile:1: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8feb4d8ca5354def3d8fce243717141ce31e2c428701f6682bd2fafe15388214","Warn: downloadThenRun not pinned by hash: meta-facebook/meta-galaxy100/recipes-utils/openbmc-utils/files/seutil:34","Warn: pipCommand not pinned by hash: tests2/experimental/vboot_tests/run.sh:26","Info:   0 out of  18 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned","Info:   0 out of   1 pipCommand dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}}]},"last_synced_at":"2025-08-17T08:29:27.152Z","repository_id":28403347,"created_at":"2025-08-17T08:29:27.152Z","updated_at":"2025-08-17T08:29:27.152Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33630999,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-28T02:00:06.440Z","response_time":99,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T15:01:03.898Z","updated_at":"2026-05-29T00:01:39.326Z","avatar_url":"https://github.com/facebook.png","language":"C","funding_links":[],"categories":["C","\u003ca id=\"89e277bca2740d737c1aeac3192f374c\"\u003e\u003c/a\u003e工具"],"sub_categories":["\u003ca id=\"203d00ef3396d68f5277c90279f4ebf3\"\u003e\u003c/a\u003e新添加"],"readme":"# OpenBMC\n\nOpenBMC is an open software framework to build a complete Linux image for a Board Management Controller (BMC).\n\nOpenBMC uses the [Yocto Project](https://www.yoctoproject.org) as the underlying building and distro generation framework.\n\n| Board | Description |\n|-------|-------------|\n[**Wedge**](https://code.facebook.com/posts/681382905244727/introducing-wedge-and-fboss-the-next-steps-toward-a-disaggregated-network/) | A 40G OS-agnostic TOR switch\n[**Yosemite**](https://code.facebook.com/posts/1616052405274961/introducing-yosemite-the-first-open-source-modular-chassis-for-high-powered-microservers-) | An open source modular chassis for high-powered microservers\n[**Lightning**](https://code.facebook.com/posts/989638804458007/introducing-lightning-a-flexible-nvme-jbof/) | A flexible NVMe JBOF\n[**Wedge100**](https://code.facebook.com/posts/1802489260027439/wedge-100-more-open-and-versatile-than-ever/) | A 32x100G TOR switch\n[**Backpack LC/FC**](https://code.facebook.com/posts/864213503715814/introducing-backpack-our-second-generation-modular-open-switch/) | Linecard and fabric card in a 128x100G modular open switch\n[**Backpack CMM**](https://code.facebook.com/posts/864213503715814/introducing-backpack-our-second-generation-modular-open-switch/) | Chassis management module in a 128x100G modular open switch\n[**Tioga Pass**](https://code.facebook.com/posts/232534267210735/ocp-summit-2017-facebook-news-recap-/) | A dual-socket compute platform\n[**YosemiteV2**](https://code.facebook.com/posts/232534267210735/ocp-summit-2017-facebook-news-recap-/) | A refresh of Yosemite\n[**Bryce Canyon**](https://code.facebook.com/posts/1869788206569924/introducing-bryce-canyon-our-next-generation-storage-platform/) | Disk Storage platform\n**Grand Canyon** | Disk Storage platform\n\n## Contents\n\nThis repository includes 3 set of layers:\n\n* **OpenBMC Common Layer** - Common packages and recipes can be used in different types of BMC.\n* **BMC System-on-Chip (SoC) Layer** - SoC specific drivers and tools. This layer includes the bootloader (u-boot) and the Linux kernel. Both the bootloader and Linux kernel shall include the hardware drivers specific for the SoC.\n* **Board Specific Layer** - Board specific drivers, configurations, and tools. This layer defines how to configure the image. It also defines what packages to be installed for an OpenBMC image for this board. Any board specific initialization and tools are also included in this layer.\n\n## File structure\n\nThe Yocto naming pattern is used in this repository. A \"`meta-layer`\" is used to name a layer or a category of layers. And `recipe-abc` is used to name a recipe. The project will exist as a meta layer itself! Within the Yocto Project's distribution call this project `meta-openbmc`.\n\nThe recipes for OpenBMC common layer are found in `common`.\n\nThe BMC SoC layer and board specific layer are grouped together based on the vendor/manufacturer name. For example, all Facebook boards specific code should be in `meta-facebook`. Likewise, `meta-aspeed` includes source code for Aspeed SoCs.\n\n## How to build\n\nNote: In the instruction set below, references to \u003cplatform\u003e for some of the steps is an example only and need to be replaced with the respective platform when setting up for a different platform.\n\n1. Set up the build environment based on the Yocto Project's [Quick Start Guide](https://www.yoctoproject.org/docs/2.5/brief-yoctoprojectqs/brief-yoctoprojectqs.html).\n\n2. Clone the OpenBMC repository and other open source repositories:\n ```bash\n $ git clone -b helium https://github.com/facebook/openbmc.git\n $ cd openbmc\n $ ./sync_yocto.sh\n ```\n\n3. Initialize a build directory for the platform to build. In the `openbmc` directory:\n ```bash\n $ source openbmc-init-build-env wedge\n ```\n Choose between `wedge`, `wedge100`, `yosemite`, or any of the other platforms listed in the meta-facebook directory.\n After this step, you will be dropped into a build directory, `openbmc/build`.\n\n4. Start the build within the build directory:\n In general to build for the platform:\n ```bash\n $ bitbake \u003cplatform\u003e-image\n ```\n The build process automatically fetches all necessary packages and builds the complete image. The final build results are in `openbmc/build/tmp/deploy/images/\u003cplatform\u003e`. The root password will be `0penBmc`, you may change this in the local configuration.\n\n## Build Artifacts\n\n* **u-boot.bin** - This is the u-boot image for the board.\n* **uImage** - This the Linux kernel for the board.\n* **\u003cplatform\u003e-image-\u003cplatform\u003e.cpio.lzma.u-boot** - This is the rootfs for the board.\n* **flash-\u003cplatform\u003e** - This is the complete flash image including u-boot, kernel, and the rootfs.\n\n## Kernel \u0026 U-Boot Development\nBy default, OpenBMC build process fetches and build Linux kernel and U-boot directly from GitHub repository.\n- To make local kernel changes and build with the modified kernel:\n\nIn the build directory, run\n```\n$ devtool modify linux-aspeed\n```\nor\n```\n$ devtool modify u-boot\n```\nThis will create local Linux package under \u003cbuildir\u003e/workspace/sources/linux-aspeed  for development\n\n- To go back to default recipes, run\n```\n$ devtool reset linux-aspeed\n```\n\n## FAQ\n1-  BMC will take care of the controlling the system / fan based on the sensor/device status (I assume it may even shutdown in case of multiple failures or high temperature). How can we debug such issues? Is there any event/critical logs maintained in the the BMC? Can we have list of files which we can be looked into in case of such issues?\n\nAnswer: To debug those issues, you will have to refer to the logs.\nA: For Rest api related issues, please look at the rest logs under /tmp/ (example: /tmp/rest.log).\nB: For FSCD related issues, please look at the fscd logs for /var/log/ (example: /var/log/fscd.log).\nC: For mTerm log (data from the X86 CPU side), please look at /var/log/mTerm\u003csomething\u003e.log (it's usually /var/log/mTerm_wedge.log on most platform).\nD: Some persistent log also go to /mnt/data/ partition.\nE: For everything else, look at /var/log/messages.\n\n2) How do we configure the BMC sensor thresholds for fan / temp / others ? Do we have any command which can be used from the OpenBmc shell?\n\nA- For fan RPM, you can run set_fan_speed.sh to change it (use get_fan_speed.sh to read the value back) from the OpenBMC shell. Some platforms, especially storage/compute ones, use fan-util.  Those scripts are under /usr/local/bin on the BMC. Please keep in mind that fscd process will change the fan speed RPM based so your changed values won't stay for long unless you turn off the watchdog and kill fscd. if you want to change the temperature threshold, you will have to modify the codes and build a new BMC image.\n\n## How can I contribute?\n\nIf you have an application that can be used by different BMCs, you can contribute your application to the OpenBMC common layer.\n\nIf you are a BMC SoC vendor, you can contribute your SoC specific drivers to the BMC SoC layer.\n\nIf you are a board vendor, you can contribute your board specific configurations and tools to the Board specific layer. If the board uses a new BMC SoC that is not part of the BMC SoC layer, the SoC specific driver contribution to the BMC SoC layer is also required.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffacebook%2Fopenbmc","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffacebook%2Fopenbmc","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffacebook%2Fopenbmc/lists"}