Skip to content
Foxx Cyberfoxxcyber/docs

Bedrock RMF

Release notes for Bedrock RMF, the open-source, self-hosted RMF / NIST SP 800-53 compliance manager.

Bedrock RMF ships as semantic-versioned container images in a public registry: registry.gitlab.com/foxxcyber-oss/bedrock-rmf:X.Y.Z (the runtime) and …/bedrock-rmf/bootstrap:X.Y.Z (migrations and seeds). Every tag is applied only to an image that passed the Trivy and SAST gates. The full changelog lives in the repository at CHANGELOG.md.

1.0.2 — August 2026 — A much smaller bootstrap image

  • The one-shot bootstrap image (migrations + seeds) is now built from self-contained bundles and ships no node_modules — 187 MB instead of 899 MB, faster to pull, and nothing inside it for an image scanner to flag. Its Trivy scan is now a hard release gate, the same as the runtime image (#7).
  • No configuration changes; docker compose pull && docker compose up -d upgrades an existing install.

1.0.1 — August 2026 — Fixes from the documentation pass

Defects found while capturing the walkthrough screenshots, fixed the same day. Upgrade with docker compose pull && docker compose up -d.

  • Milestone status sticks — setting a POA&M milestone to Completed was silently reverted; it now saves with its completion date (#1).
  • Dates show the day you entered — POA&M scheduled completion, milestone due dates and software end-of-life rendered one day early in US time zones (#3).
  • POA&M lists wrap long weakness text instead of stretching the table (#4); the hardware type list labels Network Device (firewall, router, switch) (#5).
  • Bootstrap image — docker compose run --rm bootstrap cat /secrets/initial_admin_password now does what the guide says (it used to re-run the bootstrap); the image no longer ships npm, which clears its advisory scan findings (#6).

1.0.0 — August 2026 — First public release

Bedrock RMF is now open source under the GNU AGPL v3, at https://gitlab.com/foxxcyber-oss/bedrock-rmf. This is the same version Foxx Cyber runs for its own ATO packages.

  • Self-hosted in one command — docker compose up -d pulls the published images and a bootstrap job applies the schema, seeds the NIST SP 800-53 Rev 5 catalog (with CCI mappings), generates the auth secret and creates the first admin. No source checkout, no .env. See the Deployment Quickstart.
  • Code Security module — track GitLab projects, import SAST, Trivy filesystem and Trivy image reports (including from failed pipelines), triage findings with permanent dispositions, and report per project.
  • Baseline and overlay template library for the SCTM, with C/I/A-driven selection of the applicable baseline.
  • /api/v1 agent API — API keys can list and start control implementations.
  • Hardening — encrypted-at-rest fields enforce a 16-byte GCM authentication tag; the bootstrap stage runs unprivileged; all Trivy findings cleared; migrations are asserted newer than the whole journal so an upgrade can never silently skip one.
  • A self-contained CI pipeline — every gate is defined in the repository so forks and contributor merge requests run the identical pipeline.

0.3.x — August 2026 — STIG depth

  • Package-level STIG posture with a host compliance grid, STIG evidence in the NIST catalog down to the CCI, and a derived STIG column in the SCTM.
  • SQL-aggregated STIG summaries; imports bind only to live hardware.
  • Software asset identity index with duplicate collapse.

0.1 – 0.2 — August 2026

  • Zero-config Compose stack with the bootstrap service.
  • STIG Center metrics and workspace polish.

Last updated August 27, 2026