An Empirical Study of the TianoCore Community

2026-08-24Software Engineering

Software Engineering
AI summary

The authors studied how people involved in the TianoCore community build and secure firmware, which is the low-level software that helps computers start up. They surveyed and interviewed different experts, including firmware developers and security specialists. They found that there are gaps in how firmware is currently developed and maintained, especially around security and safety. The authors suggest that using safer programming tools and more automation could help make firmware better and more secure.

TianoCoreUEFI firmwarefirmware developmentsoftware securitymemory-safe technologiesautomationoriginal equipment manufacturersopen-source community
Authors
Nazanin Siavash, Connor Glosner, Ayushi Sharma, Bianca Trinkenreich, Terrance E. Boult, Aravind Machiry, Armin Moin
Abstract
We investigate the software security and maintenance practices adopted by stakeholders in the TianoCore community and identify opportunities to improve firmware development workflows. We conduct a survey and a limited interview study with participants representing independent firmware vendors, original equipment manufacturers, security experts, firmware developers, and academic researchers. This open-source development community maintains a reference implementation for the core of the UEFI firmware. We highlight important gaps in the current state of firmware development within the TianoCore ecosystem and identify key areas in which improved security practices, greater adoption of memory-safe technologies, and increased automation of manual processes could strengthen the maintenance and security of the UEFI firmware.