Ross ROSS = Recommend OSS · open-source software intelligence for agents

nix-community/lanzaboote

Secure Boot & Measured Boot for NixOS [maintainers=@blitz @raitobezarius @nikstur] observed · 2026-08-28

github.com/nix-community/lanzaboote · homepage · Rust · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 99
  • Release rhythm 57
  • Longevity 98
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 193
  • age_days: 1381
  • days_rel: 72
  • days_push: 8
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

1818 stars · 117 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Lanzaboote is Rust tooling that brings UEFI Secure Boot and Measured Boot support to NixOS. Its lzbt tool signs boot components, builds Unified Kernel Images, and installs them to the EFI System Partition, with TPM-based measurement for binding secrets.

Use cases

  • enable secure boot on nixos
  • sign nixos kernel and initrd for uefi secure boot
  • set up measured boot with tpm2 on nixos
  • create unified kernel images for nixos
  • protect luks encryption keys with tpm measurements
  • replace systemd-boot with a secure boot bootloader on nixos

When to choose

  • you run NixOS with systemd-boot and want UEFI Secure Boot with your own keychain
  • you want TPM2 Measured Boot to bind disk encryption secrets to boot state
  • you need a reproducible, Nix-integrated signing and UKI installation flow

When to avoid

  • you are not comfortable with recovery tools or lack a backup, since misconfiguration can leave the system unbootable
  • your system is not installed in UEFI mode or does not use systemd-boot
  • you need guaranteed support across arbitrary hardware, as firmware behavior is inconsistent

Facets

cli-tool · maturity active

security cryptography cli developer-tools security operating-systems developer-tools rust cli secure-boot uefi nixos measured-boot tpm2 unified-kernel-image systemd-boot bootloader linux

2 sources

Member repositories

RepositoryRoleHealth v2
nix-community/lanzabootemain84

For agents

markdown · JSON · MCP: product_card(name="nix-community/lanzaboote")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem