← CRA Starter File

CRA Starter File · RMK firmware, RP2040 build

Open-source keyboard firmware · source commit 4cb64c1 (26 Sep 2026) · built 28 Sep 2026

Sample file
309components in the CycloneDX 1.7 SBOM
0known vulnerabilities (OSV, checked 28 Sep)
5unmaintained crates to note in your support plan

File contents

PartWhat it saysStatus
SBOMsbom.cdx.json, from Cargo.lock: 303 crates plus 6 other componentsDone
Vulnerability checkOSV and RustSec advisories: no known vulnerabilitiesDone
Product classKeyboard firmware: not in Annex III or IV, so default class, self-assessment (module A)Done
Disclosure policySECURITY.md and /.well-known/security.txt, ready to publishIn paid file
ENISA runbookWho does what at hour 0, 24h, 72h and 14 days, with the early-warning form pre-filledIn paid file
Annex VII outlineSections pre-filled from the code, with the gaps marked for youIn paid file

Unmaintained crates found

CrateAdvisory
atomic-polyfill 1.0.3RUSTSEC-2023-0089, unmaintained
bare-metal 0.2.5RUSTSEC-2026-0110, deprecated
json 0.12.4RUSTSEC-2022-0081, unmaintained
paste 1.0.15RUSTSEC-2024-0436, no longer maintained
proc-macro-error2 2.0.1RUSTSEC-2026-0173, unmaintained

Built from the public source of RMK to show the format. RMK's authors did not ask for or review this; it is an example, not an assessment of their project. Not legal advice.