Finds the build-config lines that ship an ESP-IDF or Zephyr device with secure boot off, a debug por
185
Finds the build-config lines that ship an ESP-IDF or Zephyr device with secure boot off, a debug port open, unsigned images or plaintext OTA.
docker run --rm -v "$PWD":/work getreadystack/firmware-release-gate /work/file
The same 18 rules as the VS Code extension, in a container. Mount a folder on /work.
--rules lists every ruledocker run --rm -e READYSTACK_LICENSE=<key> -v "$PWD":/work getreadystack/firmware-release-gate --dir /work --ci
An outside firmware-only security review starts around $6,000 and a full IoT device assessment runs $10,000 to $50,000; this is the config pass you run before you pay for one.
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "firmware-release-gate": { "command": "npx", "args": ["-y", "@readystack/firmware-release-gate", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence; the full sweep is free for 7 days). The agent gets every finding with the line number.
- name: Firmware Release Gate for sdkconfig and prj.conf
run: npx -y @readystack/firmware-release-gate --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/firmware-release-gate --dir /work --ci)
Try the full run free for 7 days — no key needed. Then one licence, 7-day refund, no questions. Set READYSTACK_LICENSE=<key> or run --license <key> once.
Content type
Image
Digest
sha256:8e4a4c2e6…
Size
46.1 MB
Last updated
3 days ago
docker pull getreadystack/firmware-release-gate