{"id":13575304,"url":"https://github.com/openbmc/openbmc","last_synced_at":"2026-01-28T10:31:46.316Z","repository":{"id":38023326,"uuid":"42542702","full_name":"openbmc/openbmc","owner":"openbmc","description":"OpenBMC Distribution","archived":false,"fork":false,"pushed_at":"2026-01-20T18:00:04.000Z","size":194319,"stargazers_count":2341,"open_issues_count":38,"forks_count":1065,"subscribers_count":241,"default_branch":"master","last_synced_at":"2026-01-21T01:13:55.925Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"BitBake","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/openbmc.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2015-09-15T19:51:42.000Z","updated_at":"2026-01-20T21:44:57.000Z","dependencies_parsed_at":"2025-09-07T10:02:13.086Z","dependency_job_id":null,"html_url":"https://github.com/openbmc/openbmc","commit_stats":null,"previous_names":[],"tags_count":62,"template":false,"template_full_name":null,"purl":"pkg:github/openbmc/openbmc","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openbmc%2Fopenbmc","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openbmc%2Fopenbmc/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openbmc%2Fopenbmc/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openbmc%2Fopenbmc/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/openbmc","download_url":"https://codeload.github.com/openbmc/openbmc/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openbmc%2Fopenbmc/sbom","scorecard":{"id":110336,"data":{"date":"2025-08-04","repo":{"name":"github.com/openbmc/openbmc","commit":"7824d13b13d619ae0ddf2618655e1715880d46d9"},"scorecard":{"version":"v5.2.1-28-gc1d103a9","commit":"c1d103a9bb9f635ec7260bf9aa0699466fa4be0e"},"score":2.8,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#cii-best-practices"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#packaging"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#license"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#dangerous-workflow"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#fuzzing"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#sast"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#binary-artifacts"}},{"name":"Vulnerabilities","score":0,"reason":"21 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-cpwx-vrp4-4pq7","Warn: Project is vulnerable to: GHSA-gmj6-6f8f-6699","Warn: Project is vulnerable to: GHSA-h5c8-rqwp-cp95","Warn: Project is vulnerable to: GHSA-h75v-3vvj-5mfj","Warn: Project is vulnerable to: GHSA-q2x7-8rv6-6q7h","Warn: Project is vulnerable to: PYSEC-2014-14 / GHSA-652x-xj99-gmcc","Warn: Project is vulnerable to: GHSA-9hjg-9r4m-mvj7","Warn: Project is vulnerable to: GHSA-9wx4-h78v-vm56","Warn: Project is vulnerable to: PYSEC-2014-13 / GHSA-cfj3-7x9c-4p3h","Warn: Project is vulnerable to: PYSEC-2018-28 / GHSA-x84v-xcm2-53pg","Warn: Project is vulnerable to: PYSEC-2023-206","Warn: Project is vulnerable to: PYSEC-2024-4 / GHSA-2mqj-m65w-jghx","Warn: Project is vulnerable to: PYSEC-2023-165 / GHSA-cwvm-v4w8-q58c","Warn: Project is vulnerable to: PYSEC-2022-42992 / GHSA-hcpj-qp55-gfph","Warn: Project is vulnerable to: PYSEC-2023-137 / GHSA-pr76-5cm5-w9cj","Warn: Project is vulnerable to: PYSEC-2023-161 / GHSA-wfm5-v35h-vwf4","Warn: Project is vulnerable to: PYSEC-2019-217 / GHSA-462w-v97r-4m45","Warn: Project is vulnerable to: PYSEC-2014-8 / GHSA-8r7q-cvjq-x353","Warn: Project is vulnerable to: PYSEC-2014-82 / GHSA-fqh9-2qgg-h84h","Warn: Project is vulnerable to: PYSEC-2021-66 / GHSA-g3rq-g295-4j3m","Warn: Project is vulnerable to: PYSEC-2019-220 / GHSA-hj2j-77xm-mc5v"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#vulnerabilities"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Info: Possibly incomplete results: error parsing shell code: not a valid arithmetic operator: 0: meta-openembedded/meta-networking/recipes-filter/ebtables/ebtables-2.0.11/ebtables.common:0","Warn: containerImage not pinned by hash: meta-raspberrypi/.github/workflows/docker-images/dco-check/Dockerfile:5: pin your Docker image by updating christophebedard/dco-check:latest to christophebedard/dco-check:latest@sha256:248aff3b7959253ad9d0dd7248b56ddd0654a3b1522686d073d5f143dcd81865","Warn: containerImage not pinned by hash: meta-raspberrypi/.github/workflows/docker-images/yocto-builder/Dockerfile:5: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:1ec65b2719518e27d4d25f104d93f9fac60dc437f81452302406825c46fcc9cb","Warn: containerImage not pinned by hash: poky/bitbake/contrib/hashserv/Dockerfile:12: pin your Docker image by updating alpine:3.13.1 to alpine:3.13.1@sha256:08d6ca16c60fe7490c03d10dc339d9fd8ea67c6466dea8d558526b1330a85930","Warn: containerImage not pinned by hash: poky/bitbake/contrib/prserv/Dockerfile:31: pin your Docker image by updating alpine:3.14.4 to alpine:3.14.4@sha256:cf5b2ed6e37873edf0733ad18ca3ccc414a60ba260be611459c245508a19b652","Warn: pipCommand not pinned by hash: poky/documentation/tools/host_packages_scripts/opensuse_essential.sh:2","Warn: pipCommand not pinned by hash: poky/documentation/tools/host_packages_scripts/pip3_docs.sh:1","Warn: pipCommand not pinned by hash: poky/scripts/contrib/patchtest.sh:82","Warn: pipCommand not pinned by hash: poky/scripts/contrib/patchtest.sh:83","Info:   0 out of   4 containerImage dependencies pinned","Info:   0 out of   4 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#pinned-dependencies"}}]},"last_synced_at":"2025-08-15T12:04:38.642Z","repository_id":38023326,"created_at":"2025-08-15T12:04:38.646Z","updated_at":"2025-08-15T12:04:38.646Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28844014,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-28T07:39:25.367Z","status":"ssl_error","status_checked_at":"2026-01-28T07:39:24.487Z","response_time":57,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T15:00:59.831Z","updated_at":"2026-01-28T10:31:46.296Z","avatar_url":"https://github.com/openbmc.png","language":"BitBake","funding_links":[],"categories":["BitBake","Python","Technologies and Terminology"],"sub_categories":[],"readme":"# OpenBMC\n\n[![Build Status](https://jenkins.openbmc.org/buildStatus/icon?job=latest-master)](https://jenkins.openbmc.org/job/latest-master/)\n\nOpenBMC is a Linux distribution for management controllers used in devices such\nas servers, top of rack switches or RAID appliances. It uses\n[Yocto](https://www.yoctoproject.org/),\n[OpenEmbedded](https://www.openembedded.org/wiki/Main_Page),\n[systemd](https://www.freedesktop.org/wiki/Software/systemd/), and\n[D-Bus](https://www.freedesktop.org/wiki/Software/dbus/) to allow easy\ncustomization for your platform.\n\n## Setting up your OpenBMC project\n\n### 1) Prerequisite\n\nSee the\n[Yocto documentation](https://docs.yoctoproject.org/ref-manual/system-requirements.html#required-packages-for-the-build-host)\nfor the latest requirements\n\n#### Ubuntu\n\n```sh\nsudo apt install git python3-distutils gcc g++ make file wget \\\n    gawk diffstat bzip2 cpio chrpath zstd lz4 bzip2\n```\n\n#### Fedora\n\n```sh\nsudo dnf install git python3 gcc g++ gawk which bzip2 chrpath cpio \\\n    hostname file diffutils diffstat lz4 wget zstd rpcgen patch\n```\n\n### 2) Download the source\n\n```sh\ngit clone https://github.com/openbmc/openbmc\ncd openbmc\n```\n\n### 3) Target your hardware\n\nAny build requires an environment set up according to your hardware target.\nThere is a special script in the root of this repository that can be used to\nconfigure the environment as needed. The script is called `setup` and takes the\nname of your hardware target as an argument.\n\nThe script needs to be sourced while in the top directory of the OpenBMC\nrepository clone, and, if run without arguments, will display the list of\nsupported hardware targets, see the following example:\n\n```text\n$ . setup \u003cmachine\u003e [build_dir]\nTarget machine must be specified. Use one of:\n...\n```\n\nA more complete list of supported machines can be found under\n[meta-phosphor/docs](https://github.com/openbmc/openbmc/blob/master/meta-phosphor/docs/supported-machines.md).\n\nOnce you know the target (e.g. romulus), source the `setup` script as follows:\n\n```sh\n. setup romulus\n```\n\n### 4) Build\n\n```sh\nbitbake obmc-phosphor-image\n```\n\nAdditional details can be found in the [docs](https://github.com/openbmc/docs)\nrepository.\n\n## OpenBMC Development\n\nThe OpenBMC community maintains a set of tutorials new users can go through to\nget up to speed on OpenBMC development out\n[here](https://github.com/openbmc/docs/blob/master/development/README.md)\n\n## Build Validation and Testing\n\nCommits submitted by members of the OpenBMC GitHub community are compiled and\ntested via our [Jenkins](https://jenkins.openbmc.org/) server. Commits are run\nthrough two levels of testing. At the repository level the makefile `make check`\ndirective is run. At the system level, the commit is built into a firmware image\nand run with an arm-softmmu QEMU model against a barrage of\n[CI tests](https://jenkins.openbmc.org/job/CI-MISC/job/run-ci-in-qemu/).\n\nCommits submitted by non-members do not automatically proceed through CI\ntesting. After visual inspection of the commit, a CI run can be manually\nperformed by the reviewer.\n\nAutomated testing against the QEMU model along with supported systems are\nperformed. The OpenBMC project uses the\n[Robot Framework](http://robotframework.org/) for all automation. Our complete\ntest repository can be found\n[here](https://github.com/openbmc/openbmc-test-automation).\n\n## Submitting Patches\n\nSupport of additional hardware and software packages is always welcome. Please\nfollow the\n[contributing guidelines](https://github.com/openbmc/docs/blob/master/CONTRIBUTING.md)\nwhen making a submission. It is expected that contributions contain test cases.\n\n## Bug Reporting\n\n[Issues](https://github.com/openbmc/openbmc/issues) are managed on GitHub. It is\nrecommended you search through the issues before opening a new one.\n\n## Questions\n\nFirst, please do a search on the internet. There's a good chance your question\nhas already been asked.\n\nFor general questions, please use the openbmc tag on\n[Stack Overflow](https://stackoverflow.com/questions/tagged/openbmc). Please\nreview the\n[discussion](https://meta.stackexchange.com/questions/272956/a-new-code-license-the-mit-this-time-with-attribution-required?cb=1)\non Stack Overflow licensing before posting any code.\n\nFor technical discussions, please see [contact info](#contact) below for Discord\nand mailing list information. Please don't file an issue to ask a question.\nYou'll get faster results by using the mailing list or Discord.\n\n### Will OpenBMC run on my Acme Server Corp. XYZ5000 motherboard?\n\nThis is a common question, particularly regarding boards from popular COTS\n(commercial off-the-shelf) vendors such as Supermicro and ASRock. You can see\nthe list of supported boards by running `. setup` (with no further arguments) in\nthe root of the OpenBMC source tree. Most of the platforms supported by OpenBMC\nare specialized servers operated by companies running large datacenters, but\nsome more generic COTS servers are supported to varying degrees.\n\nIf your motherboard is not listed in the output of `. setup` it is not currently\nsupported. Porting OpenBMC to a new platform is a non-trivial undertaking,\nideally done with the assistance of schematics and other documentation from the\nmanufacturer (it is not completely infeasible to take on a porting effort\nwithout documentation via reverse engineering, but it is considerably more\ndifficult, and probably involves a greater risk of hardware damage).\n\n**However**, even if your motherboard is among those listed in the output of\n`. setup`, there are two significant caveats to bear in mind. First, not all\nports are equally mature -- some platforms are better supported than others, and\nfunctionality on some \"supported\" boards may be fairly limited. Second, support\nfor a motherboard is not the same as support for a complete system -- in\nparticular, fan control is critically dependent on not just the motherboard but\nalso the fans connected to it and the chassis that the board and fans are housed\nin, both of which can vary dramatically between systems using the same board\nmodel. So while you may be able to compile and install an OpenBMC build on your\nsystem and get some basic functionality, rough edges (such as your cooling fans\nrunning continuously at full throttle) are likely.\n\nSee also\n[\"Supported Machines\"](https://github.com/openbmc/openbmc/blob/master/meta-phosphor/docs/supported-machines.md).\n\n## Features of OpenBMC\n\n### Feature List\n\n- Host management: Power, Cooling, LEDs, Inventory, Events, Watchdog\n- Full IPMI 2.0 Compliance with DCMI\n- Code Update Support for multiple BMC/BIOS images\n- Web-based user interface\n- REST interfaces\n- D-Bus based interfaces\n- SSH based SOL\n- Remote KVM\n- Hardware Simulation\n- Automated Testing\n- User management\n- Virtual media\n\n### Features In Progress\n\n- OpenCompute Redfish Compliance\n- Verified Boot\n\n### Features Requested but need help\n\n- OpenBMC performance monitoring\n\n## Finding out more\n\nDive deeper into OpenBMC by opening the [docs](https://github.com/openbmc/docs)\nrepository.\n\n## Technical Steering Committee\n\nThe Technical Steering Committee (TSC) guides the project. Members are:\n\n- Benjamin Fair, Google\n- Patrick Williams, Meta\n- Roxanne Clarke, IBM\n- Sagar Dharia, Microsoft\n- Samer El-Haj-Mahmoud, Arm\n- Terry Duncan, Intel\n\n## Contact\n\n- Mail: openbmc@lists.ozlabs.org\n  [https://lists.ozlabs.org/listinfo/openbmc](https://lists.ozlabs.org/listinfo/openbmc)\n- Discord: [https://discord.gg/69Km47zH98](https://discord.gg/69Km47zH98)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fopenbmc%2Fopenbmc","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fopenbmc%2Fopenbmc","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fopenbmc%2Fopenbmc/lists"}