paper

An Empirical Study of the TianoCore Community

arXiv:2608.23280

Abstract

We investigate the software security and maintenance practices adopted by stakeholders in the TianoCore community and identify opportunities to improve firmware development workflows. We conduct a survey and a limited interview study with participants representing independent firmware vendors, original equipment manufacturers, security experts, firmware developers, and academic researchers. This open-source development community maintains a reference implementation for the core of the UEFI firmware. We highlight important gaps in the current state of firmware development within the TianoCore ecosystem and identify key areas in which improved security practices, greater adoption of memory-safe technologies, and increased automation of manual processes could strengthen the maintenance and security of the UEFI firmware.

This work is accepted to be presented in the FTA 2026 workshop but is not published in the proceedings, according to the ACM SIGSOFT policy (https://www2.sigsoft.org/policies/pcpolicy/) that does not allow the work of organizers to be published in the workshop proceedings