OpenMV OTA
Secure over-the-air updates for OpenMV cameras: build your application into a signed ROMFS image, publish it, and a camera downloads, verifies, and installs it — falling back to the last release that worked if anything goes wrong.
What a camera downloads is encrypted, under a key minted with the project and baked into your own firmware, so a published release is ciphertext to the update server, to the store it sits in, and to anyone who gets hold of it.
Start with the tutorial — the complete, navigable reference for every command and the update server's HTTP API, in the order you use them: install → project → build → flash → device runtime → update server. The command documentation lives there and only there, so it has one place to be right.
Shipping in the EU? The compliance mapping
lays out how this stack lines up with the Cyber Resilience Act and RED 3.3 —
what's covered, and the residual threats
that aren't — and project new --ota scaffolds the fill-in templates
(conformity checklist, EU DoC, disclosure policy, security.txt) into your
project's compliance/. Found a vulnerability in this stack itself? See
the security policy.
Installation
Not yet published. Once the package lands on PyPI, all tools install together:
pip install openmv-ota
For development, install from a checkout:
pip install -e .
Contributing to the project
Contributions are most welcome. If you are interested in contributing to the project, start by creating a fork of the repository:
Clone the forked repository, and add a remote to the main openmv-ota repository:
git clone https://github.com/<username>/openmv-ota.git
git -C openmv-ota remote add upstream https://github.com/openmv/openmv-ota.git
Now the repository is ready for pull requests. To send a pull request, create a new feature branch and push it to origin, and use Github to create the pull request from the forked repository to the upstream openmv/openmv-ota repository. For example:
git checkout -b <some_branch_name>
<commit changes>
git push origin -u <some_branch_name>
Contribution guidelines
Please follow the best practices when sending pull requests upstream. In general, the pull request should:
- Fix one problem. Don't try to tackle multiple issues at once.
- Split the changes into logical groups using git commits.
- Pull request title should be less than 78 characters, and match this pattern:
<scope>:<1 space><description><.>
- Commit subject line should be less than 78 characters, and match this pattern:
<scope>:<1 space><description><.>
Metadata
Release files for openmv-ota 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| openmv_ota-1.0.0.tar.gz | 1.1 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| openmv_ota-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 2.2 MB
Release files / openmv_ota-1.0.0.tar.gz
| Download URL | openmv_ota-1.0.0.tar.gz |
|---|---|
| Size | 1.1 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
85782eb8925d9885a231f44e17897a6b4284c1bd5d29b192c6e6aaf4a3a266d1
|
|
BLAKE2b-256 checksum How to use checksums |
0782dc0af391f03f54af51b68817ddcd9af42f3f15779b35554a933c3627f1bd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / openmv_ota-1.0.0-py3-none-any.whl
| Download URL | openmv_ota-1.0.0-py3-none-any.whl |
|---|---|
| Size | 1.1 MB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cc4c0b1b71fedf49ca50e84264e237712e073b722bb8dc73dfe921d011a2afad
|
|
BLAKE2b-256 checksum How to use checksums |
02b2eb4f7216e811dabdd7a8e46c71028a6eca9ecf7e30a238a6ae8766aefe36
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency log