{"id":13642756,"url":"https://github.com/mendersoftware/mender","last_synced_at":"2026-02-03T18:36:37.207Z","repository":{"id":37396777,"uuid":"47542798","full_name":"mendersoftware/mender","owner":"mendersoftware","description":"Mender over-the-air software updater client.","archived":false,"fork":false,"pushed_at":"2026-01-20T08:26:28.000Z","size":13869,"stargazers_count":1139,"open_issues_count":6,"forks_count":224,"subscribers_count":37,"default_branch":"master","last_synced_at":"2026-01-20T18:12:21.375Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://mender.io","language":"C++","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mendersoftware.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"code-of-conduct.md","threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":"support/CMakeLists.txt","governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2015-12-07T09:36:43.000Z","updated_at":"2026-01-19T11:42:21.000Z","dependencies_parsed_at":"2025-11-11T16:02:39.314Z","dependency_job_id":null,"html_url":"https://github.com/mendersoftware/mender","commit_stats":{"total_commits":2689,"total_committers":83,"mean_commits":"32.397590361445786","dds":0.7047229453328374,"last_synced_commit":"11dde3e63431d8866e2d0b0eaf3238dfe2e944a2"},"previous_names":["mendersoftware/client"],"tags_count":87,"template":false,"template_full_name":null,"purl":"pkg:github/mendersoftware/mender","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mendersoftware%2Fmender","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mendersoftware%2Fmender/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mendersoftware%2Fmender/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mendersoftware%2Fmender/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mendersoftware","download_url":"https://codeload.github.com/mendersoftware/mender/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mendersoftware%2Fmender/sbom","scorecard":{"id":636318,"data":{"date":"2025-08-11","repo":{"name":"github.com/mendersoftware/mender","commit":"1f4fa660531038139962503c4bcf17f6cb26494a"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.9,"checks":[{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":10,"reason":"27 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":8,"reason":"Found 8/9 approved changesets -- score normalized to 8","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact 1.6.0 not signed: https://api.github.com/repos/mendersoftware/mender/releases/12855542","Warn: release artifact 1.5.0 not signed: https://api.github.com/repos/mendersoftware/mender/releases/11307667","Warn: release artifact 1.4.1 not signed: https://api.github.com/repos/mendersoftware/mender/releases/11260300","Warn: release artifact 1.4.0 not signed: https://api.github.com/repos/mendersoftware/mender/releases/10098155","Warn: release artifact 1.3.1 not signed: https://api.github.com/repos/mendersoftware/mender/releases/9506399","Warn: release artifact 1.6.0 does not have provenance: https://api.github.com/repos/mendersoftware/mender/releases/12855542","Warn: release artifact 1.5.0 does not have provenance: https://api.github.com/repos/mendersoftware/mender/releases/11307667","Warn: release artifact 1.4.1 does not have provenance: https://api.github.com/repos/mendersoftware/mender/releases/11260300","Warn: release artifact 1.4.0 does not have provenance: https://api.github.com/repos/mendersoftware/mender/releases/10098155","Warn: release artifact 1.3.1 does not have provenance: https://api.github.com/repos/mendersoftware/mender/releases/9506399"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: containerImage not pinned by hash: tests/Dockerfile.daemon:3","Warn: containerImage not pinned by hash: tests/Dockerfile.daemon:36: pin your Docker image by updating ubuntu:24.04 to ubuntu:24.04@sha256:7c06e91f61fa88c08cc74f7e1b7c69ae24910d745357e0dfe1d2c0322aaf20f9","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-21T09:16:06.153Z","repository_id":37396777,"created_at":"2025-08-21T09:16:06.153Z","updated_at":"2025-08-21T09:16:06.153Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29052639,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-03T15:43:47.601Z","status":"ssl_error","status_checked_at":"2026-02-03T15:43:46.709Z","response_time":96,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:01:35.889Z","updated_at":"2026-02-03T18:36:37.202Z","avatar_url":"https://github.com/mendersoftware.png","language":"C++","funding_links":[],"categories":["Misc","Go","C++","Resources"],"sub_categories":["Embedded Linux"],"readme":"![Mender logo](mender_logo.png)\n\n[![Build Status](https://gitlab.com/Northern.tech/Mender/mender/badges/master/pipeline.svg)](https://gitlab.com/Northern.tech/Mender/mender/pipelines)\n[![Coverage Status](https://coveralls.io/repos/github/mendersoftware/mender/badge.svg?branch=master)](https://coveralls.io/github/mendersoftware/mender?branch=master)\n\n# Overview\n\nMender is an open-source, over-the-air (OTA) update manager for IoT and embedded Linux devices. Its\nclient-server architecture enables the central management of software deployments, including\nfunctionality such as dynamic grouping, phased deployments, and delta updates. Mender also supports\npowerful extensions to [configure](https://mender.io/product/features/device-configuration),\n[monitor](https://mender.io/product/features/device-monitoring), and\n[troubleshoot](https://mender.io/product/features/device-troubleshooting) devices. Features include\nremote terminal access, port forwarding, file transfer, and device configuration. It integrates with\n[Azure IoT Hub](https://azure.microsoft.com/en-us/products/iot-hub/) and [AWS IoT\ncore](https://aws.amazon.com/iot-core/).\n\n## Table of Contents\n\n* [Why Mender?](#why-mender)\n* [Where to start?](#where-to-start)\n* [Mender documentation](#mender-documentation)\n* [About this repository](#about-this-repository)\n* [Contributing](#contributing)\n* [License](#license)\n* [Security disclosure](#security-disclosure)\n* [Installing from source](#installing-from-source)\n* [Cross-compiling](#cross-compiling)\n* [Community](#community)\n* [Authors](#authors)\n\n## Why Mender?\n\nMender enables secure and robust over-the-air updates for all device software. Some of the core\nfunctionalities include:\n\n* 💻 Flexible management server and client architecture for secure OTA software update deployments\n  and fleet management.\n* 💾 Standalone deployment support, triggered at the device-level (**no server needed**) for\n  unconnected or USB delivered software updates.\n* 🔄 Automatic rollback upon update failure with an A/B partition design.\n* 🔀 Support for a full root file system, application, files, and containerized updates.\n* ✅ Dynamic grouping, phased rollouts to ensure update success.\n* ⚙️ Advanced configuration, monitoring, and troubleshooting for software updates.\n* 🔬 Extensive logging, audits, reporting, and security and regulatory compliance capabilities.\n\n### Our mission and goals\n\nEmbedded product teams often create homegrown updaters at the last minute due to the need to fix\nbugs in field-deployed devices. However, the essential requirement for an embedded update process is\n*robustness*. For example, loss of power at any time should not brick a device. This creates a\nchallenge, given the time constraints to develop and maintain a homegrown updater.\n\n**Mender aims to address this challenge with a *robust* and *easy to use* updater for embedded Linux\ndevices, which is open source and available to anyone.**\n\nRobustness is ensured with *atomic* image-based deployments using a dual A/B rootfs partition\nlayout. This makes it always possible to roll back to a working state, even when losing power at any\ntime during the update process.\n\nEase of use is addressed with an intuitive UI, [comprehensive\ndocumentation](https://docs.mender.io/), a [meta layer for the Yocto\nProject](https://github.com/mendersoftware/meta-mender) for *easy integration into existing\nenvironments*, and high-quality software (see the test coverage badge).\n\n## Where to start?\n\n| **Mender (Commercial)** | **Mender (Open source)** |\n| ------------- | ------------- |\n| Ready to get started immediately? The commercial version of Mender allows you to simply connect your devices to a hosted, enterprise-grade, and multi-region backend. Capabilities include: advanced fleet management, top-tier security, regulatory compliance features, role-based access control (RBAC), dynamic groups, delta updates, and mutual TLS support.\u003cbr\u003e\u003cbr\u003eFree for 12 months, up to 10 devices, [get started with Mender today](https://docs.mender.io/get-started). | Alternatively, the open-source version of Mender allows you to start updating devices in a quick, secure, and robust method. Learn more about how to get started.\u003cbr\u003e\u003cbr\u003e*For rollback functionality, the Mender client requires an integration with the boot loader and a partition layout. Support for rollback functionality is most easily built as part of your Yocto Project image by using the [meta layer for the Yocto Project](https://github.com/mendersoftware/meta-mender).* |\n\nCompare the complete list of features and functionality available at the\n[features](https://mender.io/product/features) page.\n\n### Mender documentation\n\nThe [documentation](https://docs.mender.io) is a great place to learn more, especially:\n\n* [Overview](https://docs.mender.io/overview/introduction) — learn more about Mender, it's design,\n  and capabilities.\n* [Debian](https://docs.mender.io/system-updates-debian-family) — get started with updating your\n  Debian devices.\n* [Yocto](https://docs.mender.io/system-updates-yocto-project) — take a look at our support for\n  Yocto.\n\nWould you rather dive into the code? Then you are already in the right place!\n\n---\n\n# High-level architecture overview\n\n![Mender architecture](mender_architecture.png)\n\u003c!-- https://drive.google.com/file/d/1pKfJ-eRHYrDYZW7jCTHI7_D9tEF-rKDz --\u003e\n\nThe chart above depicts a typical Mender architecture with the following elements:\n\n* Back End \u0026 User Interface: The shaded sky blue area is the Mender product which comprises the back end and the user interface (UI).\n* Clients: The Mender client runs on the devices represented by the devices icon.\n* Gateway: All communications between devices, users, and the back end occur through an API gateway. [Traefik](https://traefik.io) is used for the API gateway. The gateway routes the requests coming from the clients to the right micro-service(s) in the Mender back end.\n* NATS message broker: some of the micro-services use NATS as a message broker to support the Mender device update troubleshooting and the orchestration within the system.\n* Mongo DB: persistent database for the Mender back end micro-services.\n* Storage layer: in both hosted and on-premise Mender, an AWS S3 Bucket (or S3 API-compatible) or an Azure Storage Account storage layer is used to store the artifacts.\n* Redis: in-memory cache to enable device management at scale.\n\nYou can find more detailed information in our [documentation](https://docs.mender.io/3.5/server-installation/overview).\n\n---\n\n# About this repository\n\nThis repository contains the Mender client updater, which can be run in standalone mode (manually\ntriggered through its command line interface) or managed mode (connected to the Mender server).\n\nMender provides both the client-side updater and the backend and UI for managing deployments as open\nsource. The Mender server is designed as a microservices architecture and comprises several\nrepositories.\n\n## Contributing\n\nWe welcome and ask for your contribution. If you would like to contribute to Mender, please read our guide on how to best get started [contributing code or\ndocumentation](https://github.com/mendersoftware/mender/blob/master/CONTRIBUTING.md).\n\n## License\n\nMender is licensed under the Apache License, Version 2.0. See\n[LICENSE](https://github.com/mendersoftware/mender/blob/master/LICENSE) for the full license text.\n\n## Security disclosure\n\nWe take security very seriously. If you come across any issue regarding\nsecurity, please disclose the information by sending an email to\n[security@mender.io](security@mender.io). Please do not create a new public\nissue. We thank you in advance for your cooperation.\n\n## Installing from source\n\n### Requirements\n\n* C++ compiler\n* cmake\n* libarchive-dev, libboost-all-dev, liblmdb-dev, libdbus-1-dev, libssl-dev and libsystemd-dev packages\n\nFor Debian/Ubuntu, the prerequisites can be installed by\n```\nsudo apt install git build-essential cmake libarchive-dev liblmdb-dev libboost-all-dev libssl-dev libdbus-1-dev libsystemd-dev\n```\nAdjust as needed for other distributions.\n\n\n### Steps\n\nTo install Mender C++ client on a device from source, first clone the repository:\n\n```\ngit clone https://github.com/mendersoftware/mender.git\n```\n\nChange into the cloned repository:\n```\ncd mender\n```\n\nUse `git submodule` to fetch additional dependencies:\n```\ngit submodule update --init --recursive\n```\n\nCreate a build directory and enter it:\n```\nmkdir build\ncd build\n```\n\nConfigure and start the build:\n\n```\ncmake -DCMAKE_INSTALL_PREFIX:PATH=/usr ..\nmake\n```\nMake sure you configure installation to the `/usr` path prefix, as the executables required by systemd units and\nD-Bus policy file must be placed in the canonical paths.\n\nInstall the client:\n```\nsudo make install\n```\n\n### Client setup\n\nThe required configuration files for client operation can be created in several ways.\n\n- for an interactive setup process, use the [`mender-setup`](https://github.com/mendersoftware/mender-setup) tool.\n- in a Yocto-based set up, those are generated as part of the build process\n\n### Installation notes\n\nInstalling this way does not offer a complete system updater.  For this, you need additional\nintegration steps. Depending on which OS you are using, consult one of the following:\n\n* [System updates: Debian family](https://docs.mender.io/system-updates-debian-family)\n* [System updates: Yocto Project](https://docs.mender.io/system-updates-yocto-project)\n\nHowever, it is possible to use [Update Modules](https://docs.mender.io/artifacts/update-modules)\nand update other parts of the system.\n\nIn order to connect to a Mender server, you either need to get a [Mender\nProfessional](https://hosted.mender.io/) account, or [set up a server\nenvironment](https://docs.mender.io/getting-started/create-a-test-environment). If\nyou are setting up a demo environment, you will need to put the\n`support/demo.crt` file into `/etc/mender/server.crt` on the device and add the\nconfiguration line below to `/etc/mender/mender.conf` after the installation\nsteps above:\n\n```\n  \"ServerCertificate\": \"/etc/mender/server.crt\"\n```\n\n**Important:** `demo.crt` is not a secure certificate and should only be used for demo purposes,\nnever in production.\n\n## Cross-compiling\n\nGeneric cross-compilation procedures using `cmake` apply.\n\nDuring the current, early stage of development using a higher, cross-compilation aware build\nsystem such as Yocto is advisable. Once things are sufficiently stabilized, a set of steps for\nmanual cross-compilation will be added here.\n\n### Aarch64\n\nInstall the requirements for aarch64, e.g. for a Debian-based system:\n```\nsudo dpkg --add-architecture arm64\nsudo apt update \u0026\u0026 sudo apt install git crossbuild-essential-arm64 cmake libarchive-dev:arm64 liblmdb++-dev:arm64 libboost-log-dev:arm64 libssl-dev:arm64 libdbus-1-dev:arm64 libsystemd-dev:arm64\n```\n\nConfigure and build:\n```\ncmake -DCMAKE_TOOLCHAIN_FILE=cmake/aarch64.cmake -B build .\ncmake --build build\n```\n### QNX\n\n**Note that QNX support is still experimental, and not supported.**\n\n```\nmkdir build \u0026\u0026 cd build\nQNX_TARGET_ARCH=aarch64le cmake .. -DCMAKE_TOOLCHAIN_FILE=../cmake/qnx.cmake\nmake\n```\n\n\n## Running\n\nOnce installed, Mender can be enabled by executing:\n\n```\nsystemctl enable mender-authd mender-updated \u0026\u0026 systemctl start mender-authd mender-updated\n```\n\n## D-Bus API\n\nThe introspection files for Mender D-Bus API can be found at\n[documentation](https://docs.mender.io/device-side-api)\n\n## Community\n\n* Join the [Mender Hub discussion forum](https://hub.mender.io)\n* Follow us on [Twitter](https://twitter.com/mender_io). Please\n  feel free to tweet us questions.\n* Fork us on [GitHub](https://github.com/mendersoftware)\n* Create an issue in the [bugtracker](https://tracker.mender.io/projects/MEN)\n* Email us at [contact@mender.io](mailto:contact@mender.io)\n* Connect to the [#mender IRC channel on Libera](https://web.libera.chat/?#mender)\n\n## Authors\n\nMender was created by the team at [Northern.tech AS](https://northern.tech), with many contributions\nfrom the community. Thanks [everyone](https://github.com/mendersoftware/mender/graphs/contributors)!\n\n### About Northern.tech\n\n[Northern.tech](https://northern.tech) is the leader in device lifecycle management with a mission to secure the world's\nconnected devices. Established in 2008, Northern.tech showcases a long history of enterprise\ntechnology management before IIoT and IoT became buzzwords. Northern.tech is the company behind\n[CFEngine](https://cfengine.com), a standard in server configuration management, to automate\nlarge-scale IT operations and compliance.\n\nLearn more about [device lifecycle management](https://northern.tech/what-we-do) for industrial IoT devices.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmendersoftware%2Fmender","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmendersoftware%2Fmender","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmendersoftware%2Fmender/lists"}