Packages with the hardened use flag

Global definition: Activate default security enhancements for toolchain (gcc, glibc, binutils).

app-admin / clsync : Live sync tool based on inotify, written in GNU C

app-containers / cni-plugins : Standard networking plugins for container networking

app-containers / containerd : A daemon to control runC

app-containers / docker : The core functions you need to create Docker images and run Docker containers

app-containers / docker-cli : the command line binary for docker

app-containers / flannel : An etcd backed network fabric for containers

app-containers / kompose : Tool to move from docker-compose to Kubernetes

app-containers / runc : runc container cli tools

app-crypt / cfssl : Cloudflare's PKI and TLS toolkit

app-emulation / docker-machine : Machine management for a container-centric world

app-misc / jdupes : Identify duplicate files on the filesystem

dev-lang / gnat-gpl : GNAT Ada Compiler - GPL version

dev-lang / python : An interpreted, interactive, object-oriented programming language

dev-libs / mimalloc : A compact general purpose allocator with excellent performance

  • Enable exploit mitigations

dev-ruby / rjb : Rjb is a Ruby-Java software bridge

games-emulation / dosbox : DOS emulator

mail-client / thunderbird : Thunderbird Mail Client

net-analyzer / suricata : High performance Network IDS, IPS and Network Security Monitoring engine

net-im / ricochet : Privacy-focused instant messaging through Tor hidden services

net-misc / bfgminer : Modular Bitcoin ASIC/FPGA/GPU/CPU miner in C

net-misc / cgminer : Bitcoin CPU/GPU/FPGA/ASIC miner in C

net-misc / mosh : Mobile shell that supports roaming and intelligent local echo

net-misc / udpcast : Multicast file transfer tool

sys-cluster / kube-apiserver : Kubernetes API server

sys-cluster / kube-controller-manager : Kubernetes Controller Manager

sys-cluster / kube-proxy : Kubernetes Proxy service

sys-cluster / kube-scheduler : Kubernetes Scheduler

sys-cluster / kubeadm : CLI to Easily bootstrap a secure Kubernetes cluster

sys-cluster / kubectl : CLI to run commands against Kubernetes clusters

sys-cluster / kubelet : Kubernetes Node Agent

sys-cluster / minikube : Single Node Kubernetes Cluster

sys-devel / distcc : Distribute compilation of C code across several machines on a network

sys-devel / gcc : The GNU Compiler Collection

sys-kernel / gentoo-kernel : Linux kernel built with Gentoo patches

  • Use selection of hardening options recommended by Kernel Self Protection Project

sys-kernel / vanilla-kernel : Linux kernel built from vanilla upstream sources

sys-process / ctop : Top-like interface for container-metrics

www-client / firefox : Firefox Web Browser