Current projects
On this page you find an overview of recent projects which have either been recently completed or are — at this moment — working with NLnet funding. For a complete overview please check the overview of all projects, or use the thematic index to look up projects based on thematic funds and specific themes. Click on the name of the project to find out more about it.
project | description |
---|---|
0KNOW | Group Theoretic Zero-knowledge Proofs (0KNOW) |
AALT (Accelerated Analog Layout Tool) | More efficient analog layout generation for chips) |
AI Horde | Collaborative infrastructure for running generative AI models |
ARMify | Auto-Identification of MCU Models to Simplify ARM Bare-Metal Reverse Engineering |
AVantGaRDe | Reliable Foundations of Local-first Graph Databases |
ActivityPods | Framework for fully-decentralized social apps, combining ActivityPub and Solid Pods |
Aerogramme | Standards-compliant open-source IMAP server with server-side encryption |
Agorakit | Groupware which is a friendly online home to communities |
AlekSIS | All-libre extensible kit for school information systems |
Alive2 | Translation validation for LLVM |
Apicula | Open source tools for working with Gowin FPGAs |
Apicula IO primitives | Add additional IO primitives to libre Gowin FPGA tools |
Automating mobile app interception with Frida | Mobile app network introspection for security research |
Perspectives: Making Models | Generate software from open models for human interaction patterns |
Arcan-A12 | Explorative p2p protocol for fast and secure remote desktops |
Ari | Purely functional programming language designed to "type" binary files |
Armbian | Versatile OS for ARM-based single board computers |
Atomic Data | Typesafe handling of LinkedData |
Atomic Tables | Self-hostable tabular structured data solution |
Authenticated DNSSEC bootstrapping | Secure in-band announcements of DNSSEC parameters |
Heads-OpenPGP | OpenPGP Authenticated Heads and long-time awaited security improvements |
Automated clearing of source code files | More efficient retrieval of security and license compliance contextual information |
Automerge | Add Merkle Search Tree support to Automerge |
binary-analysis-ng improvements | Integrate Kaitai in binary-analysis-ng |
BB3-CM4 | CM4 compatible MCU board |
Back to source: trust but verify all the packages | Analysis pipeline for mapping and cross-referencing binaries with source code |
Balthazar Casing | Open hardware laptop |
Bana | Personal network oriented ActivityPub powered social networking |
Bertie | Formally verified TLS 1.3 implementation |
Blink Qt Messaging | Add modern encryption to SIP softphone |
BlockNote | An modern, open source Block-based editor |
Bonfire federated groups | Create, join and manage federated groups across instances |
Bonfire Framework | Elixir-based ActivityPub implementation and library with groups and RBAC |
Briar Desktop | E2EE online and offline messaging and discussion |
CNSPRCY | E2EE connections between trusted devices |
Converged Security Suite Improvements | Open source tooling for BIOS configuration |
Converged Security Suite +AMD | Add AMD support to Converged Security Suite |
Cable | A new wire protocol for cabal (and beyond) |
Canaille | Zero-knowledge opinionated OpenID Connect (OIDC) server. |
Canarytail | Warrant canary standardization and automation |
Castopod Plugins | Add plugins to the Castopod podcast server |
Libre-SOC Cavatools: Power ISA Simulator | Power ISA Simulator |
CeroWRT II | Make Wi-Fi routers faster and more reliable |
Certbot ECDSA support | |
Charon | Privacy-enabling account management and SSO solution |
LibrEDA | An integrated development environment for chip design |
Choreographic Programming: From Theory To Practice | Generating a standard library of core distributed algorithms with formal proofs |
Anchorboot | Pre-built UEFI replacement firmware for ARM-based ChromeOS devices using coreboot/U-Boot |
Cloud hosting service portability | Service portability for cloud hosting platforms |
Coko Docs | A modern, open source replacement for Google Docs and Drive |
CokoDocs | Add ODF, legacy office and PDF capabilities to CokoDocs |
Coloquinte | High performance placement of cells inside digital electronic circuitry |
Commune | User-friendly persistent chat/voice rooms |
Conversations 3.0 | Secure and standards-compliant XMPP client for Android |
Libre-SOC, Coriolis2 ASIC Layout Collaboration | Open tooling for ASIC Layout |
ArtistHub | Allow creative artists to gain visibility and build reputation on the web |
CryptPad Auth | Implement external identity mechanisms to E2EE collaborative editor |
CryptPad Blueprints | Server-side encrypted collaborative editor |
CryptoLyzer | Cryptographic settings analyzer library |
DANCE4All | Implement DANCE specification in GnuTLS and MbedTLS |
DAVx⁵ | Share Contacts, Calendars, Tasks, Notes & Journals |
Securing Internet protocols with DIDs | Bridge Decentralized Identifiers with standardised authorisation mechanisms |
DMT | Implementation of MOSFET Parameter Extraction Flow for Sky130 into DMT |
DNSvizor | Privacy-enhanced DNS resolver and DHCP server |
DUT Control | Unified Control Interface for Firmware Security Tests |
DATALISP | Universal data interchange format using canonical S-expressions |
Delta Tauri | DeltaChat implemented in Tauri |
Dolphin authorisation | Avoid privilege escalation in the Dolphin file manager |
dream2nix | Automate reproducible packaging for various language ecosystems |
Python supply-chain with dream2nix | Towards a secure, extensible & reproducible Python supply-chain with dream2nix |
How AdTech works | Improving public awareness of AdTech and privacy |
EDeA | Repeatable, automated measurement data capture |
EEZ Studio | Open source tooling for measurement and test equipment |
EEZ flow for EEZ Studio IV | Open Hardware Test & Measurement equipment |
ELF Linking | Analytic tools for UNIX' Executable and Linkable Format |
Encoding for Robust Immutable Storage (ERIS) | Encrypted and content-addressable data blocks |
Open source ESP32 802.11 MAC | Open source wifi drivers for ESP32 |
Earthstar | P2P protocol and APIs for collaborative and social applications |
Earthstar (Encryption, Safety, and Local Sync) | Improve security, encryption and sync capabilities in Earthstar CRDT |
Elm Matrix SDK | Better moderation for Matrix rooms and servers |
Email <=> XMPP gateway | Bridge instant messaging with email |
Etebase - protocol and encryption enhancements | Redesign EteSync protocol and encryption scheme |
Ethersync | Real-time co-editing of local text files |
EventFahrplan | Conference schedule app with strong offline capabilities |
Exter | Proxy-based external browser extensions |
Friendly Forge Format (F3) | Proposed Standard for secure communication between software forges |
FABulous Demo SoC | SoC with open source FPGA based on FABulous |
FOSS Code Supply Chain Assurance | Mitigate attacks through software dependencies |
FOSS Code Supply Chain Assurance II | Add approximate matching capabilities to software vulnerability discovery |
FastWave | Modern waveform VCD parser |
Feather UI | Declarative cross-platform UI toolkit |
Federated software forges with Forgejo | Add ActivityPub based federation to Forgejo |
Software metadata | Decentralized, federated metadata about software applications |
Federated Task-Tracking with Live Data | Track tasks and issues in a federated way |
Federated Timesheets | Interoperable machine-readable time tracking |
Fediverse Test Framework | Test bench for ActivityPub implementations |
Fediverse Test Suite | Interoperability effort for W3C ActivityPub |
Fidus Writer | Real-time collaborative web-based online editor for academia |
Flarum | Add federation and much more to the extensible forum software Flarum. |
Fleetbase on Solid: A production-ready supply chain solution | Federated open source supply chain solution using Solid |
Fobnail | Remote attestation delivered locally |
ForgeFed | Federating software forges with ActivityPub |
ForgeFlux | Software Forge independent federation with ActivityPub and F3 |
Forgejo | An open source software forge with a focus on federation |
Native IFC for FreeCAD | ISO-compliant Building Information Modeling in FreeCAD |
Fix the Pitch Black Attack in Freenet routing | A decentralized distributed platform for private communication |
Data packages | Specification + improved tooling for external data set descriptions |
Funkwhale | ActivityPub-driven audio streaming and sharing |
Funkwhale | ActivityPub-driven audio streaming and sharing |
GNS Migration and Zone Management | Registrar tools for adoption of GNU Name System |
Full-source GNU Mes on ARM and RISC-V | Expand full-source bootstrap to other CPU platforms |
GNU Mes RISC-V | Bringing the trustworthy bootstrap to RISC-V |
RISC-V bootstrapping effort via GNU Mes | Allow bootstrapping Guix on RISC-V via GNU Mes |
GNU Mes Tower | GNU Mes with alternative scheme implementations and WASM |
GNU Taler KYC | Know-Your-Customer support for GNU Taler |
Taler for local currencies. | Free software banking backend for local currencies |
GNUnet CONG | Modernise the network stack of GNUnet |
Layer-2-Overlay | Generalising the GNUnet Layer-2 Overlay for broader usage |
GNUnet Messenger API | API for decentralized instant messaging using CADET |
Garage | Lightweight geo-distributed data store compatible with Amazon S3 |
Gash | Port Gash to GNU Mes for auditable bootstrap |
Genealogos | Nix to SBOM generator targeting the CycloneDX format |
Verilog-AMS in Gnucap (cont'd) | Analog/Mixed modelling and simulation in Gnucap |
Verilog-AMS in Gnucap | Mixed-signal modelling and simulation with Verilog-AMS |
GoToSocial | Lightweight ActivityPub social network server |
GoToSocial | Improvements to ActivityPub server written in Go |
Gorgon CI | Continuous integration testing for PRs against software dependencies |
Gosling | Generic Onions Services Library Project |
Guix Peer-to-Peer substitutes | |
Porting Guix to Riscv64 | Port Guix software collection to Riscv64 architecture |
Guix-Daemon | Transition to a Guile implementation of the guix-daemon |
TPM 2.0 for HEADS | TPM 2.0 support for open source BIOS replacement firmware |
Haphaestus | Lightweight JavaScript-free browser engine written in Haskell |
Hardware accelerated 2D graphics | Design hardware accelerated 2D graphics using C to Verilog |
Open Hardware Manuals | Automatically generate user-friendly documentation for open hardware elements |
OCap layer for Haskell actor library | Implement OCapN and Syndicate in Haskell's troupe |
SCE, DelTiC and Antler | High-Fidelity Congestion Control |
Himalaya | End-to-end encryption capable scriptable email |
Holo Routing | A novel routing stack in Rust, including IS-IS routing |
Hyper Hyper Space | Cryptographically secure append-only distributed data layer |
IC workspace | Open Source IC Design Management Tool |
IPDL | Equational Proofs for Distributed Cryptographic Protocols |
IPDL II | A new process logic aimed at formal proofs for cryptographic algorithm |
Telecommunication in HF using the Internet Protocol (IPoHF) | High-throughput software-defined wireless telecommunications |
IPv6-monostack - upstream Linux SIIT/NAT64 | Commoditizing NAT64 and IP/ICMP translation to accelerate IPv6 deployment |
Icestudio | Visual developer tool for development of FPGAs |
Icosa Gallery | Open, decentralised platform for 3D assets |
Inko | Programming language with deterministic automatic memory management |
Interpeer SDKs | Secure and efficient peer-to-peer networking stack |
Inventaire Self-hosted | Self-hosted book inventories that share the wikidata-powered bibliographic database |
IotECC | Lightweight Elliptic Curve Cryptography for small chips |
Irdest - OpenWRT Image and Bluetooth LE | Add Bluetooth LE connections to Irdest |
Irdest spec, db, route scoring | Route scoring and other routing improvements for Irdest meshnets |
Threat intelligence sharing | Privacy-Preserving Sharing of Threat Intelligence in Trusted Adversarial Environments |
json-joy | JSON data structure as a CRDT |
JSON-Joy Peritext | Tich-text CRDT implementations for json-joy CRDT |
JShelter | Cross-browser extension to make javascript less exploitable |
JShelter Manifest V3 | Make JShelter compatible with Manifest V3 |
JellyfishOPP | Open Hardware device for power profiling |
K-Gen | From datasets in DCAT catalogs to knowledge graphs |
KDE Connect | KDE Connect discovery and transport protocol improvements |
KDE Plasma Wayland | Accessibility and advanced graphics input support for KDE Plasma Wayland |
Standardizing KEMTLS | Post-quantum TLS without handshake signatures |
Kaidan Auth + portability | Account portability and Client/Server Authentication for the Kaidan XMPP client |
Kaidan | Encrypted A/V calls, group chat messaging |
Improving and extending Kaitai Struct | Rust parsing for binary analysis tool Kaitai Struct |
Serialization in Kaitai Struct for Java and Python | Declaratively modify and create complex binary file formats |
Kami | Choreography programming language integrated with the Rust ecosystem |
Karrot | Location-aware community self-organisation |
Katzen | Meta-data resistant instant messaging over the Katzenpost mixnet |
Katzen Metadata Minimizing Messsenger | Privacy preserving instant messaging using a modern mixnet |
Kazarma | Bridge ActivityPub and Matrix realms |
Kazarma Release | Bridge between ActivityPub and Matrix protocol |
Kbin | ActivityPub based link sharing and microblogging |
/kbin | Mobile app and feature additions to /kbin |
Keyoxide Mobile | Mobile client for identity magement tool Keyoxide |
Private Key Operations for Keyoxide | Implement Private Key Store design in Keyoxide |
Keyoxide v2 | Add cryptographic signature based to Keyoxide |
KiCad | Professional open source electronics design application |
KiCad | Add RPC API, multichannel designs and schematic variant system to FOSS EDA suite |
KiKit | Tooling for automation of production of PCB designed in KiCAD |
Kintex-nextpnr | Open toolchain for high performance FPGAs |
Klusterlab Wireguard | Implement Wireguard in Verilog on FPGA |
Improve Email Encryption in KMail | Adopt improvements in Email Encryption in KMail |
Improve Krill (RPKI) BGP integration | Real-time routing for Krill RPKI daemon |
Collabora Online/LibreOffice Accessibility | Private and accessible collaborative editing with Collabora Online/LibreOffice |
LibreOffice/Collabora Online typography | Add interoperability and state-of-the-art web typography to LibreOffice/Collabora Online line break |
Lemmy private communities | Add private communities to Lemmy federated link aggregator |
Lemmy Scale | ActivityPub-powered social link aggregation and discussion |
Lemmy Federation | Lemmy Federation and ActivityPub compliance |
Let's Connect! Client-Server to P2P | Add P2P features to Let's Connect! |
Letswifi/Geteduroam | Make federated wifi access provisioning safer and more convenient |
LiberaForms | End tot End Encrypted Forms |
Audio/Video Calls in Libervia | Encrypted Audio/Video Calls in multi-frontend XMPP client |
Libre-SOC | A fully open hardware System-on-a-Chip |
Libre-SOC HPC | Work on High Performance Compute capabilities for Libre-SOC |
Libre-SOC OpenPOWER ISA WG | Steward ISA extension proposals through OpenPOWER External RFC Process |
IndieHosters | System for Cross-domain Identity Management (SCIM) |
Libre Car Control | Automotive development platform, protocol analyzer and hacking multi-tool |
Librecast | E2E encrypted multicast |
LibreCellular | FOSS technology stack for 4G networks |
LibreOffice CRDT | Real-time collaboration between several, distributed LibreOffice instances |
LibrePCB | EDA software suite to develop printed circuit boards |
LibreQoS | Improve congestion control for wifi networks |
The Libre-SOC Gigabit Router | Native Open Hardware chip implementation of crypto primitives |
Port of AMDVLK/RADV 3D Driver to the Libre-SOC | Adapt Vulkan Drivers to the Libre-SoC |
Libre-SOC Formal Correctness Proofs | Mathematical unit tests for open hardware System-on-Chip |
Libre-SOC Formal Standards Development | Formal Standards for OpenPower extensions from Libre-SoC |
Libre-SOC Video Acceleration | Optimised video acceleration instructions for Libre RISC-V SoC |
Liminix | Nix-based OS for domestic WiFi routers, access points etc |
Usability of Linux firewall userspace tools | Userspace tooling for Linux kernel Netfilter |
LiteX | Developer framework for FPGA and ASIC designs |
Local Production of Antennas for LibreRouter (LoPaLiR) | Reliable open hardware Antennas for LibreRouter |
LumoSQL at-rest data security | Modern embedded database with encryption and signed data |
Luna PnR | A versatile and fast new open-source place and route tool |
LunaPnR Phase 2 | A versatile and fast new open-source place and route tool |
Mainstreaming Anonymity for Developers (MAD) | Add Onion Services to interactive internet applications |
MNT Reform Next | New iteration of the MNT open hardware laptop |
Improving the deployability of Multipath TCP | Improve MPTCP support in the Linux kernel |
Machdyne | Modular open compute hardware |
Maemo Leste | An independent mobile operating system focused on trustworthiness |
Maemo Leste Telepathy | Modernise open source real-time communications stack |
Mailpile 2 (moggie) | Building a secure, modern e-mail client for self-hosting |
Makatea | An x86, 64-bit Virtual Machine Monitor for the seL4, verified microkernel |
Manas | Rust modules for Solid clients and servers |
Manyverse Private Groups | Implement SSB Private Groups in Manyverse |
MapComplete | Thematics OpenStreetMap-viewer and editor. |
Marginalia Search | A fresh take on search |
Catalogs in MariaDB | Enable true multi-tenacy in the MariaDB database |
Mastodon - groups, filtering, moderation | Group support with ActivityPub |
Improving Matrix E2E encryption UX | Better usability of Matrix.org E2E encryption |
Mellium | Add OMEMO support to XMPP library |
Practical Decentralised Search and Discovery | Search and discovery inside mesh/adhoc networks |
Modular Meta-Press.es | Reusable decentralised meta-search engine |
MirageVPN | Robust OpenVPN client and server, and QubesOS client |
Misskey | Misskey federation and ActivityPub compliance |
MobileAtlas | A distributed open hardware test infrastructure to analyse mobile networks |
MobileAtlas | Taking roaming measurements to the next levelMobileAtlas |
postmarketOS/phosh-mobile-settings integration | Consolidate functionality of FOSS mobile settings applications |
Mobilizon UX | Share events on the fediverse |
Mobroute | A minimalist FOSS public-transportation router/tool suite |
Caster | Open-hardware high-refresh-rate electrophoretic display controller |
Monal IM | Free Jabber/XMPP client for iOS and macOS |
Monal IM UI | Modern UI for XMPP on iOS and macOS |
Mox | Modern full-featured open source secure mail server |
SecSync | Efficiently combine end-to-end encryption with CRDTs |
Naja | EDA tool focused on post logic synthesis |
Naja | Add Dissolved and Batch Netlists to Naja EDA |
Namecoin: Electrum-NMC | Security hardening and futureproofing Namecoin and Electrum-NMC |
Namecoin: TLS | Various TLS integrations for Namecoin |
Namecoin: ZeroNet and Packaging | Make ZeroNet work with Namecoin |
NaxRiscv core improvements | Open hardware out-order Risc-V CPU |
NeoChat | Native Matrix encrypted instant messaging client |
Packet classification extensions for Netfilter | High throughput packet classification of tunneled traffic |
neuropil | DHT based overlay network |
NextGraph | Interlinked data graphs, with privacy, security, data locality, and interoperability in mind |
Nitrokey 3 | PIV/FIPS 201-3 and extended hardware support for Trussed/Nitrokey |
Nitter | Alternative privacy-preserving FOSS UI for Twitter |
Type Inference for Nix | Adding static typing and type inference to Nix |
Debug Adapter with Nix | Implement the Debug Adaptor Protocol for Nix |
NixOS/Clevis | Unattented disk decryption with Clevis on NixOS |
Securing NixOS services with systemd | |
UEFI Secure Boot support for NixOS | Add a self-sovereign root of trust as part of supply chain security |
NoScript Contextual Policies & LAN protection | Application Boundaries Enforcer (ABE) for new generation of browsers |
NodeBB | ActivityPub support and accessibility improvements for forum software |
Adopting the Noise Key Exchange in Tox | Improved security of Tox instant messaging with NoiseIK |
Nominatim as a library | Self-hostable address/location retrieval for OpenStreetMap |
Nyxt Webextensions | Independent implementation of WebExtensions |
OCaml-QUIC | Implement QUIC/QUIC-TLS/QPACK and HTTP/3 in OCAML |
OVT 13 | Open Hardware laptop |
owi | Symbolic evaluator and fuzzing of WASM software |
Oil Shell | A new dialect of shell that is less error-prone |
Oil Shell | Modern shell language and runtime |
Oils for Unix | Bringing shell environments into the 21st century |
Oku | A browser and encrypted data vault based on IPFS |
Improve Okular digital signature support | Improve open source tooling for digital signatures |
Open Cloud Mesh | Improved specs and test suite for Open Cloud Mesh protocol |
OpenCryptoHW | CGRA- based reconfigurable open-source cryptographic IP cores |
OpenCryptoLinux | Make Linux run on OpenCryptoHW |
OpenCryptoTester | System-on-Chip for hardware/software testing |
DRTM implementation for AMD processors | Unified framework for dynamic RTM |
Open Energy Profiler Toolset | Modular open hardware Energy Profiling |
Openki.net | Make local events and meetups discoverable |
Open MLS Infrastructure | End-to-end encrypted group messaging |
Improving OpenSSH's Authentication and PKI | Improving SSH Authentication with OpenPGP transitive trust |
Hardening OpenPGP CA deployments | HSM support for OpenPGP key infrastructure |
OpenQRNG | Open source, certified Quantum Random Number Generator |
Open Web Calendar Stack | Aggregate public and private web calendars |
Ordie | Designing a SoC for Betrusted |
Organic Maps | Privacy-focused Android & iOS offline maps application |
LTE support in OsmoCBC (Cell Broadcast Centre) | Open source Cell Broadcast Centre for mobile networks |
GPRS/EGPRS support in Osmocom CNI for Ericsson RBS | |
Open source ePDG for VoWiFi | Enhanced Packet Data Gateway for mobile infrastructure |
Overte | Virtual reality based social platform |
p2panda | p2p protocol and event-driven data store |
p2panda: group encryption and capabilities | Add group encryption and capabilities to peer-to-peer SDK |
PGP4civiCRM | Add email encryption to CRM |
Adding Web-of-Trust Support to PGPainless | Web-of-Trust specification support for Java |
Securing PLCs via embedded protocol adapters | Open hardware protocol adapters for industrial automation |
Post-Quantum Crypto in DNSSEC | Experimental platform for DNSSEC with post-quantum cryptography |
Statime | Memory-safe high-precision clock synchronization |
PTP gateware with openXC7 | PTP on FPGA timing cards and SDR cards with openXC7 |
Passthrough Authentication | Authentication proxy using Kerberos and SPNEGO |
PeerDB Search | Search for semantic and full-text data |
Popularizing PeerTube | Decentralised video platform powered by ActivityPub |
Peertube plugin livechat | Integrated chat for Peertube live streams |
PeerTube - Remote Transcoding | Remote Transcoding for distributed video sharing network |
Peppol for the masses | Hybrid self-hosted e-invoicing with decentralized identities |
Manyfold | Manage private collections of 3D models |
Pimalaya | Open source personal information management |
Pion | Network congestion measurement for adaptive real-time applications |
PixelDroid/Media editor | Native PixelFed/ActivityPub image sharing app |
Pixelfed | Open source, federated photo sharing platform using ActivityPub |
Pleroma | Scalable ActivityPub server written in Elixir |
Poliscoops | Make political news and online debate accessible |
pretalx | Open source tooling for events and conferences |
Probabilistic NAT Traversal | Last resort ad hoc connections for GNUnet |
Prosody IM | Implement SASL authentication mechanism for XMPP |
Protomaps | Self-hostable maps based on OpenStreetMap data |
ProveThis | Prove statements about authenticated API resources |
Py2HWSW | A tool to manage embedded HW/SW project |
PyCM | Evaluate the performance of ML algorithms |
Pythonic Slint | Add a full-blown Python API to Slint |
Proper Webcam support in Qemu | Better virtualisation of camera interfaces |
R5N-DHT | Formalisation within IETF of R5N Distributed Hash Table design |
RA-Sentinel | FPGA-based Radio Receiver for securing Wifi against hacking attacks |
RADIUSdesk Multi WAN | Add Multiwan to RADIUSdesk |
RAIJIN | Open Hardware brain meeasurements with near-infrared spectroscopy |
rasn | Safe ASN.1 codec framework for Rust |
Fast RSA + PQ Blind Signatures | Fast multiprecision integers for blind RSA and Post-Quantum signatures |
RADIUSdesk | Open wifi mesh deployment application |
Raptor Lake Desktop | Implement open-source firmware for modern mainboards and chipsets |
Python bindings to the rattler library | |
ReOxide | Improving Rust Decompilation |
Replicant on Pinephone 1.2 | Add basic support for the Pinephone 1.2 to Replicant |
Finish porting Replicant to newer Android version | Alternative, free software version of Android |
Reproducible F-Droid | Building a trusted app ecosystem with F-Droid |
Ricochet Refresh | Anonymous, meta-data free secure messaging |
pcb-rnd, sch-rnd | Open source EDA suite |
Rosenpass | Post Quantum Security Add-On for WireGuard |
Rotonda Secure Extensions | Implement BGPSec in Rust and integrate into Rotonda |
SCION-enabled IPFS and libp2p | Enhancing IPFS Performance and Resilience through SCION's Path-Aware Networking |
Geographic tagging of Routing and Forwarding | Geographic tagging and discovery of Internet Routing and Forwarding |
SDCC | Small Device C Compiler compiler for 8-bit microcontrollers |
SES - SimplyEdit Spaces | SimplyEdit Spaces - collaborative presentations |
SIP RELOAD | REsource LOcation And Discovery, a peer-to-peer (P2P) signaling protocol |
Software Heritage listers + tooling | Performance improvements and new listers/tooling for Software Heritage |
Subliminal Messaging | Embedded secure channels within traditional and internet telephony |
SeedVault Integrity | Add integrity checking and WebDAV support to SeedVault Android backups |
SelfPrivacy | Reproducible self-hosting stack based on NixOS |
SensifAI | AI driven image tagging |
#Seppo! | Portable ActivityPub implementation |
A Secret Key Store for Sequoia PGP | Standards-compliant private key store for OpenPGP |
Adding TPM Support to Sequoia PGP | Implement use of TPM 2.0 crypto hardware for OpenPGP |
Sequoia PGP | Improve interface of Sequoia PGP commandline |
Sequoia GPG Chameleon | Implement well-known API's for using OpenPGP |
Servo | Independent Rust-based browser engine |
SiCl4 | Tool for interactive reverse engineering of digital logic. |
Signature PDF | Self-hosted tool to add signature to PDFs |
SignRoom | Zenroom based signature and credential platform |
Silicon verification | Non-destructive, in-situ inspection of physical chips |
Slint port for Android | Port the Rust-based Slint UI toolkit to Android |
smoltcp RPL | Implement Routing Protocol for Low-Power and Lossy networks |
Peer-to-Peer Access to Our Software Heritage | Access Software Heritage data via IPFS DHT |
Solid Compound | A software library/framework to simplify designing for W3C Solid |
Solid Data Modules | Improve data accessibility and prevent data corruption in Solid Pods |
Solid Application Interoperability | Interoperable Data sharing flows and discovery for Solid |
Solid Usable App Tools Project | Improve developer experience for W3C Solid |
Solid Wallet | Authorization reasoning, rule-based controls and fluid integration for Solid |
Sonar: a modular peer-to-peer search engine | Modular peer-to-peer search engine |
Space Tube | Group-to-group instant messaging |
Dual-level Specification Inference | Make formal verification more practical with dual-level Specification Inference |
Spectrum Applications | Add running graphical applications to the compartmentalized desktop OS Spectrum |
Secure User Interfaces (Spritely) | Usability of decentralised social media |
Spritely (and OCapN) | Enable secure P2P applications with Object Capabilities |
Stalwart Mail Server | Robust full featured mail infrastructure in Rust |
Standards Grammar Catalog/Toolchain | Open Standards Grammar Catalog/Toolchain |
Statime PTP Master | Statime - Zero-allocation cross-platform Precision Time Protocol |
Stencila v2 for ERA and EPP | Add editable, runnable code to scientific publications |
Stract | Explorative search engine |
StreetComplete/AllThePlaces | Ingest data from AllThePlaces into StreetComplete |
Structured Email for Roundcube | Add schema.org metadata awareness to open source email |
Sustainable web apps with m-ld | Empower users and developers with distributed interlinked data using local-first principles |
TISG trustable image sensor gateware | FPGA based camera providing encrypted video streams |
TOS;DR OTA backend | Integrate Terms of Service;Didn't Read with Open Terms Archive |
TSCH-rs | Time Slotted Channel Hopping implement in Rust |
Great Black Swamp | Decentralized cloud storage with provider-independent security |
GNU Taler wallet app for iOS | Mobile GNU Taler payments for portable Apple devices |
Tasteweb | Develop new web of trust mechanisms |
Tau | Remote sharing of terminal sessions |
Tauri Apps | A safer run-time for web technology based apps |
Servo Webview for Tauri | Integrated portable webview based on Servo engine into Tauri |
TerosHDL | Assisting hardware developers to deliver safer designs |
TerosHDL: OSS, GHDL, NVC | IDE with support for Open SYthesis Suite and GHDL/NVC simulators |
Threshold OPRFs | Bringing the power of Threshold OPRFs to the people |
Topola | Topological (rubberband) router for printed circuit boards |
Tracking weasel | Detect privacy violations in mobile apps |
TrenchBoot for AMD platform in Linux kernel | Upstream TrenchBoot AMD support to the Linux kernel |
Trenchboot as Anti Evil Maid | Integrate Trenchboot into Qubes OS as defense mechanism against physical compromise |
FIDO 2.2 | Open hardware implementation of FIDO CTAP 2.2 |
TrustING | Ultrafast AS-level Public-Key Infrastructure |
Trust semantic learning and monitoring | Measure on-going trust between interacting agents |
Trustix | Make build logs available as publicly verifiable, tamper-proof Merkle trees |
Tvix | Alternative Rust-based software build transparency |
Tvix-{Store/Build} | Improve store and builder component of Tvix |
TwPM | Open hardware implementation of Trusted Platform Module |
TypeCell | CRDT-based collaborative block-based editor |
UEFI isolation in VM from non UEFI firmware | Safer booting into UEFI-compliant operating system |
UEFI Capsule Update for coreboot with EDK II | Implement more robust firmware updates in coreboot |
ULX3M | A modular open hardware FPGA platform |
UberDDR3 | Open Hardware DDR3 memory controller |
Reverse Engineering Toolkit | Reducing e-waste through Reverse Engineering |
LIP6 VLSI Tools | Logical validation of ASIC layouts |
Verified Reowolf | Formal protocol verification with Reowolf |
Vouivre | A dependent type system for machine learning in Lisp |
Vula | Encrypted ad hoc local-area networking |
Free Software Vulnerability Database | A resource to aggregate software updates |
WPE Android | Embedded-friendly Webview based on WebKit |
DeltaChat/WebXDC | Portable private apps that can be shared in e.g. chat |
webxdc PUSH | Towards an usable, interoperable and trustworthy web app ecosystem |
Whippet | A new local maximum in safe, managed memory |
Whisperfish | Cross-platform mobile client for Signal and derivatives |
WikiRate: More Sites, More Cites | Persistent citation for Dekko-based open source data collections |
Willow Sync | General Sync Protocol for Willow written in Rust |
Winden/Magic Wormhole dilation | Improving Magic-Wormhole by implementing dilation and multiple file support for the web |
WireGuard on FPGA | FPGA implementation of Wireguard protocol written in SpinalHDL |
Wispwot | Implement generalized scalable protection against disruptive behavior in content discovery |
Wolvic | Web browser designed for use in XR devices |
Event Federation Plugin for WordPress | Add ActivityPub to events created with most common WordPress event plugins |
MLS for XMPP | Add Message Layer Security to XMPP |
XMPP Interoperability and Protocol Standard Conformance Testing | Development of an XMPP Test Suite |
XR Fragments | Discover, reference, navigate and query 3D online content |
Yrs | Collaborative editing with CRDT written in Rust |
Yrs Undo | Rust-based CRDT framework for real-time multi-user applications |
Yrs weak links | More efficient CRDT by interconnecting and synchronising data structures inside documents |
ZIP file format description | Documenting the ZIP file format for reverse engineers and developers |
Quantum-Proof Zenroom | Implementation of Quantum-Proof Cryptography in Zenroom |
Zero-allocation web servers in roc | Web server framework with constant memory usage |
Zilch | Tools for efficient granular builds and introspection |
ARPA2 | Working towards a decentralised global internet that offers security and privacy by design. |
bcachefs | Next generation file system |
Reinstatement of crypto.signText() | Cryptographic signatures brought back to the browser |
Democratic SendComm | Easy to use connected open hardware device |
Distributed Mechanism Learning | Privacy preserving ways of distributed data usage |
django-allauth | Versatile authentication for Django |
Donations | smaller contributions to various activities |
dweb-search | Index DHT based distributed webs |
eduVPN app | Add Wireguard protocol to federated VPN suite |
eduVPN on Apple | eduVPN for Apple devices |
eduVPN on Apple part II | Improved version of eduVPN for Apple devices |
eduVPN multi-protocol | Review of the eduVPN multi-protocol project. |
eduVPN | Making secure VPN network technology available to everyone |
elRepo.io - Resilient, distributed content sharing | Resilient, human-centered, distributed content sharing and discovery. |
Explain Direct | Providing effective and efficient access paradigms for open educational material |
f8 | Modern 8-bit instruction set |
Fashion Freedom | Supporting research, development, and education to bring the fashion industry into the 21st century |
FileSender | FileSender is a secure and private way to share large files with anyone. |
Global Directories | Distributed contact information discovery mechanism |
Hackathons | contributions to various hackathons |
imap-codec library | Release version 1.0 of the imap-codec library |
Internet of Coins | Create a decentralized, self-sustaining economy by implementing inter-blockchain connectivity |
it | Radically decentralised version control with CRDTs |
iuh-openbsc | An open source implementation of 3G |
jaq | Implementation of jq in Rust with formal semantics |
lib25519: Secure and efficient computation of X25519 and Ed25519 | |
lib25519 for ARM | Add 64bit ARM optimisations to lib25519 |
libnix | Native Nix on MS Windows |
libresilient | Create robust web presence with service workers and DHT |
libspng | A fast and safe implementation of Portable Network Graphics |
libspng APNG | Add Animated PNG (APNG) image read- and write support to libspng |
lpnTPM | TPM 2.0 compliant open hardware Trusted Platform Module |
Securing Decentralised Live Information with m-ld | Collaborative editing of LInked Data based on CRDT |
mCaptcha | Privacy-friendly Proof of Work (PoW) based CAPTCHA system |
mikroPhone | Open Hardware feature phone |
mitmproxy | HTTP/3 Support and OS Proxy Mode for intercepting local proxy |
nextpnr_large | New place and route algorithms for large FPGAs |
Improvements for the next generation firewalling tool in Linux | Netfilter kernel improvements, user space tools and testing |
Nixcloud Mail | Declarative mail server based on NixOS |
Nixcloud Webservices | Declarative web services based on NixOS |
Strengthening NTP and NTS in ntpd-rs | Memory-safe implementation of IETF time standards including NTPv5 and NTS |
openXC7 | Improve hardware support for open source FPGA tooling |
oqsprovider | Post-quantum/quantum-safe cryptographic algorithms for OpenSSL |
p3pch4t | Decentralized chat platform built on i2p |
p4-nix | Combine Programming Protocol-independent Packet Processors language with declarative Nix packaging |
PKCS#11 v3 | Contribute to standardisation of PKCS#11 for cryptographic tokens |
postmarketOS: v23.12 and v24.06 Releases | New versions of the mobile operating system postmarketOS |
purl2all | Discover metadata for software packages |
purl2sym | FOSS code symbols indexing system |
RaptorJIT | RaptorJIT is a high-performance Lua virtual machine for network dataplanes. |
SDR PHY | Create a GSM mobile phone consisting of completely open source software and SDR radio |
x86-64 VM Monitor for seL4 verified microkernel | Very restricted virtualized environment for higher security |
SecuShare | A framework for sufficiently safe social interaction |
Serval-LR | SERVAL Long-range WiFi Add-on |
Σ-protocols | Formalise and implement zero-knowledge proof Σ-protocol |
Magic Wormhole/SPAKE2 | Securely send files between two computers with minimum fuss |
TOS;DR | A user rights initiative to rate and label website terms & privacy policies |
Tracking Exposed | Increase transparency behind personalization algorithms |
Trusted Boot Module | An open hardware trusted boot manager |
uFork | A memory-safe pure-actor virtual machine |
uFork/FPGA | A memory-safe pure-actor processor soft-core |
uMap | Collaborative custom mapping with OpenStreetMap data |
vdirsyncer | Synchronise calendars and contacts |
vm-builder | Virtual Machine Build, Life Cycle and Integration in monolithic and microkernel platforms |
xrsh | Interactive text/OS terminal inside WebXR |
NLnet Foundation currently supports the following projects with in-kind contributions: |
|
The Commons Conservancy | Legal infrastructure for public benefit efforts |
NLnet Labs | Independent lab for Internet infrastructure development |