linuxboot/heads
A minimal Linux that runs as a coreboot or LinuxBoot ROM payload to provide a secure, flexible boot environment for laptops, workstations and servers. observed · 2026-08-28
Health v2 · maintenance only
67/100
- Activity 99
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3682
- days_rel: n/a
- days_push: 11
- n_releases_24m: 0
Adoption not part of the score
1585 stars · 211 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Heads is an open-source firmware and OS configuration that runs a minimal Linux as a coreboot or LinuxBoot ROM payload, moving the root of trust into write-protected SPI flash. It measures boot steps into the TPM, provides TOTP/HOTP attestation, GPG-signed kernels, and TPM-sealed LUKS disk decryption for laptops, workstations, and servers.
Use cases
- replace proprietary UEFI firmware with an auditable open-source boot path
- verify firmware and boot integrity via TPM measured boot and attestation
- securely unlock LUKS-encrypted disks using TPM-sealed keys
- sign and verify kernels, initrds, and OS ISOs before booting
- build a tamper-resistant boot environment for Qubes OS or other Linux distros
- harden commodity laptops like ThinkPads against physical and evil-maid attacks
When to choose
- you need a hardware-rooted, measured, and attested boot chain on supported hardware
- you want to replace vendor UEFI with coreboot plus a verified Linux payload
- you run Qubes OS or encrypted Linux and want TPM-based disk unlock and signed boot files
- you are comfortable flashing SPI ROMs and doing hardware modifications
When to avoid
- you need a plug-and-play solution without disassembling hardware or using external flash programmers
- your hardware is not on the supported boards list
- you are a non-technical user unwilling to risk bricking your machine
- you need broad UEFI Secure Boot compatibility with vendor firmware
Facets
application · maturity active
security cryptography embedded developer-tools security operating-systems hardware privacy self-hosted embedded cross-platform coreboot firmware tpm verified-boot measured-boot boot-loader linuxboot secure-boot luks attestation linux
5 sources
- readme: https://github.com/linuxboot/heads · fetched 2026-08-28 · de1da67c594b
- homepage: https://osresearch.net/ · fetched 2026-08-29 · 6756d28fd59a
- site_page: https://osresearch.net/Install-and-Configure · fetched 2026-08-29 · 67ea80d60997
- site_page: https://osresearch.net/InstallingOS · fetched 2026-08-29 · 497ab370f969
- site_page: https://osresearch.net/FAQ · fetched 2026-08-29 · c34634165bd0
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| linuxboot/heads | main | 67 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem