CRA Starter File · RMK firmware, RP2040 build
Open-source keyboard firmware · source commit 4cb64c1 (26 Sep 2026) · built 28 Sep 2026
309components in the CycloneDX 1.7 SBOM
0known vulnerabilities (OSV, checked 28 Sep)
5unmaintained crates to note in your support plan
File contents
| Part | What it says | Status |
|---|---|---|
| SBOM | sbom.cdx.json, from Cargo.lock: 303 crates plus 6 other components | Done |
| Vulnerability check | OSV and RustSec advisories: no known vulnerabilities | Done |
| Product class | Keyboard firmware: not in Annex III or IV, so default class, self-assessment (module A) | Done |
| Disclosure policy | SECURITY.md and /.well-known/security.txt, ready to publish | In paid file |
| ENISA runbook | Who does what at hour 0, 24h, 72h and 14 days, with the early-warning form pre-filled | In paid file |
| Annex VII outline | Sections pre-filled from the code, with the gaps marked for you | In paid file |
Unmaintained crates found
| Crate | Advisory |
|---|---|
atomic-polyfill 1.0.3 | RUSTSEC-2023-0089, unmaintained |
bare-metal 0.2.5 | RUSTSEC-2026-0110, deprecated |
json 0.12.4 | RUSTSEC-2022-0081, unmaintained |
paste 1.0.15 | RUSTSEC-2024-0436, no longer maintained |
proc-macro-error2 2.0.1 | RUSTSEC-2026-0173, unmaintained |
Built from the public source of RMK to show the format. RMK's authors did not ask for or review this; it is an example, not an assessment of their project. Not legal advice.