Open source · IoT & Edge

Firmware Manifest Validator

Check firmware manifests for version, target, digest and rollback metadata.

v1.0.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Offline, read-only validation of a firmware manifest against a local target policy. When a local artifact basename is supplied, its byte length and SHA-256 digest are verified. This tool never signs, publishes, or flashes firmware.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/firmware-manifest-validator.mjs --root examples/pass --policy policy.json --manifest manifest.json
node bin/firmware-manifest-validator.mjs --root examples/fail --policy policy.json --manifest manifest.json
npm run check

Read the result

One JSON report goes to stdout: exit 0=pass, 1=fail, 2=incomplete or invalid configuration. Invalid options, root, or policy leave stdout empty. Unreadable or malformed manifest/artifact emits an incomplete report. JSON and firmware file paths are resolved by realpath beneath --root; duplicate decoded JSON keys and invalid UTF-8 JSON are rejected. No files are written.

Where this check stops

Policy and manifest each ≤65,536 bytes; firmware ≤16,777,216 bytes; ≤100 compatible base versions; JSON depth ≤16; evaluation deadline 5,000 ms using an injected monotonic clock. Each declared bound accepts N and rejects N+1.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.