Offline, read-only validation of a firmware manifest against a local target policy. When a local artifact basename is supplied, its byte length and SHA-256 digest are verified. This tool never signs, publishes, or flashes firmware.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
node bin/firmware-manifest-validator.mjs --root examples/pass --policy policy.json --manifest manifest.json
node bin/firmware-manifest-validator.mjs --root examples/fail --policy policy.json --manifest manifest.json
npm run checkRead the result
One JSON report goes to stdout: exit 0=pass, 1=fail, 2=incomplete or invalid configuration. Invalid options, root, or policy leave stdout empty. Unreadable or malformed manifest/artifact emits an incomplete report. JSON and firmware file paths are resolved by realpath beneath --root; duplicate decoded JSON keys and invalid UTF-8 JSON are rejected. No files are written.
Where this check stops
Policy and manifest each ≤65,536 bytes; firmware ≤16,777,216 bytes; ≤100 compatible base versions; JSON depth ≤16; evaluation deadline 5,000 ms using an injected monotonic clock. Each declared bound accepts N and rejects N+1.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.