Bedrock RMF
Release notes for Bedrock RMF, the open-source, self-hosted RMF / NIST SP 800-53 compliance manager.
Bedrock RMF ships as semantic-versioned container images in a public
registry: registry.gitlab.com/foxxcyber-oss/bedrock-rmf:X.Y.Z (the
runtime) and …/bedrock-rmf/bootstrap:X.Y.Z (migrations and seeds). Every
tag is applied only to an image that passed the Trivy and SAST gates. The
full changelog lives in the repository at
CHANGELOG.md.
1.0.2 — August 2026 — A much smaller bootstrap image
- The one-shot bootstrap image (migrations + seeds) is now built from
self-contained bundles and ships no
node_modules— 187 MB instead of 899 MB, faster to pull, and nothing inside it for an image scanner to flag. Its Trivy scan is now a hard release gate, the same as the runtime image (#7). - No configuration changes;
docker compose pull && docker compose up -dupgrades an existing install.
1.0.1 — August 2026 — Fixes from the documentation pass
Defects found while capturing the walkthrough screenshots, fixed the same
day. Upgrade with docker compose pull && docker compose up -d.
- Milestone status sticks — setting a POA&M milestone to Completed was silently reverted; it now saves with its completion date (#1).
- Dates show the day you entered — POA&M scheduled completion, milestone due dates and software end-of-life rendered one day early in US time zones (#3).
- POA&M lists wrap long weakness text instead of stretching the table (#4); the hardware type list labels Network Device (firewall, router, switch) (#5).
- Bootstrap image —
docker compose run --rm bootstrap cat /secrets/initial_admin_passwordnow does what the guide says (it used to re-run the bootstrap); the image no longer ships npm, which clears its advisory scan findings (#6).
1.0.0 — August 2026 — First public release
Bedrock RMF is now open source under the GNU AGPL v3, at https://gitlab.com/foxxcyber-oss/bedrock-rmf. This is the same version Foxx Cyber runs for its own ATO packages.
- Self-hosted in one command —
docker compose up -dpulls the published images and a bootstrap job applies the schema, seeds the NIST SP 800-53 Rev 5 catalog (with CCI mappings), generates the auth secret and creates the first admin. No source checkout, no.env. See the Deployment Quickstart. - Code Security module — track GitLab projects, import SAST, Trivy filesystem and Trivy image reports (including from failed pipelines), triage findings with permanent dispositions, and report per project.
- Baseline and overlay template library for the SCTM, with C/I/A-driven selection of the applicable baseline.
/api/v1agent API — API keys can list and start control implementations.- Hardening — encrypted-at-rest fields enforce a 16-byte GCM authentication tag; the bootstrap stage runs unprivileged; all Trivy findings cleared; migrations are asserted newer than the whole journal so an upgrade can never silently skip one.
- A self-contained CI pipeline — every gate is defined in the repository so forks and contributor merge requests run the identical pipeline.
0.3.x — August 2026 — STIG depth
- Package-level STIG posture with a host compliance grid, STIG evidence in the NIST catalog down to the CCI, and a derived STIG column in the SCTM.
- SQL-aggregated STIG summaries; imports bind only to live hardware.
- Software asset identity index with duplicate collapse.
0.1 – 0.2 — August 2026
- Zero-config Compose stack with the bootstrap service.
- STIG Center metrics and workspace polish.