Skip to content

Releases: Ahmadsi70/DFIM

DFIM v0.1.0 — Initial Release

Choose a tag to compare

@Ahmadsi70 Ahmadsi70 released this 08 Sep 19:42

DFIM v0.1.0 — Initial Release

Deterministic Firmware Integrity Matrix — IEC 62443 firmware integrity enforcement.

Core Modules

  • dfim_core_engine: Block-stream parser, Merkle verification, UEFI state parsing
  • dfim_host_init: Host-side firmware integrity daemon (Linux + Windows)
  • dfim_management_api: REST API + PostgreSQL backend for fleet management
  • dfim_cli_provisioner: CLI toolchain for provisioning and key management
  • dfim_ebpf: eBPF-based runtime integrity probes
  • dfim_kani_proofs: 4 Kani formal verification proofs (all green)
  • dfim_plugin_sdk: WASM sandbox plugin runtime (wasmtime 36)

CI/CD Status

Workflow Status
CI/CD Pipeline (build, test, fuzz, lint, benchmark) ✅ 16/16 green
Kani Proofs (formal verification) ✅ 4/4 green
CodeQL (security analysis) ✅ green
Bounded Fuzzing ✅ green

Security

  • IEC 62443 CR 1.8: compile-time string encryption via litcrypt
  • RUSTSEC advisories addressed (wasmtime 30→36)
  • cargo-audit clean with audit.toml

Downloads

  • dfim-linux-x86_64.tar.gz — Static Linux x86_64 binary
  • dfim-windows-x86_64.zip — Windows x86_64 binary + UEFI guard
  • dfim-uefi-x86_64.tar.gz — UEFI firmware image