Frigate is a network video recorder for IP cameras that understands what it sees. Instead of alerting on every leaf that moves, it runs a cheap motion check first and then real object detection only where something changed, so it can tell a person from a car, a dog or a parcel and record or alert on just those. It records 24/7 or by event with retention rules per object, re-streams camera feeds over RTSP to cut connections to the camera, and gives you a live view over WebRTC, a review timeline and a zone and mask editor.
It earns its place because all of that runs on your own hardware, with no cloud subscription and no footage leaving the house. It is built around Home Assistant through a custom integration and talks MQTT to anything else. A Google Coral, Hailo, OpenVINO-capable Intel chip, NVIDIA or AMD GPU, or one of several NPUs handles detection with little load; the README recommends an accelerator over even a fast CPU.
Frigate was created by Blake Blackshear and is now developed under Frigate, Inc. It has about 36,000 stars and the code is MIT-licensed, while the Frigate name and logo are trademarks. Version 0.18.0 was released in September 2026.
- Repository: github.com/blakeblackshear/frigate
- Licence: MIT (MIT License)
- Language: Python. Stars: 36.3K. Forks: 3,661. Last push: Oct 2, 2026.
- Scan: safe, Oct 2, 2026, commit 9b2839f
Who it is for
Home Assistant users and homelab owners with IP cameras who want smart alerts and recordings without a cloud subscription, and anyone who wants footage of their home to stay at home.
Getting started
1. Write a docker-compose.yml from the docs (the online generator fills in devices for your hardware)
open https://docs.frigate.video/frigate/installation2. Start the container from the folder holding the file
docker compose up -d3. Read the generated admin password from the logs
docker logs frigate4. Log in as admin; the setup wizard walks you through adding cameras
open https://localhost:8971Frigate needs Docker on Linux for hardware access, and an AI accelerator or supported GPU is highly recommended. Port 5000 is an unauthenticated internal interface: the example Compose file leaves it commented out, and you should only expose it with care.
Safety scan
We cloned blakeblackshear/frigate at commit 9b2839f on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no bare-IP URLs and no committed binaries across 3,195 files (about 155,000 lines of TypeScript and 137,000 of Python). The one pattern hit, docker/deepx/user_installation.sh line 116, runs sudo systemctl enable dxrt.service: the host driver installer for DEEPX NPU owners, which you run by hand following the docs.
- The installer scripts are Docker build steps: install_deps.sh fetches packages from Debian, Intel and GitHub while the image is built. The web UI's one npm hook runs patch-package. Hosts in the code are GitHub (including the version check), the docs, vendor repositories, Hugging Face for models and fcm.googleapis.com for push notifications; we found no analytics.
- 45 known advisories, none critical (21 high). 34 are in JavaScript build tooling: the documentation site's package-lock.json (28) and the web UI's (6, such as braces, picomatch and webpack-dev-middleware), none of which runs in the server. The main image's Python requirements use version ranges such as tensorflow == 2.19.*, which the scanner skips as non-exact pins, so they are not counted.
- The Python advisories sit in the TensorRT image requirements: protobuf 3.20.3 (two high, denial of service) in requirements-amd64.txt, and onnx 1.14.0 (seven high, mostly path traversal when loading or saving models from untrusted sources) in requirements-models-arm64.txt, used for the ARM64 TensorRT build. They matter only for those image variants and only with model files you do not trust.
- 5 workflows. pr_template_check uses pull_request_target with a third-party action pinned to a commit and no checkout of pull request code; 2 of 13 third-party actions are pinned overall. Dependabot, licence and contributing guide present; no security policy or CodeQL. OpenSSF Scorecard 6.3.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | 1 pattern hit found and read; every one is listed under the raw findings. |
| Install-time code | 1 npm lifecycle script. 6 installer scripts |
| Committed binaries | None. |
| CI workflows | 5 workflows. 1 uses pull_request_target, none check out the pull request head. 11 of 13 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, docs.frigate.video, developer.memryx.com, fcm.googleapis.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 45 advisories across 1,899 pinned packages: 0 critical, 21 high, 20 moderate, 4 low. docker/main/requirements-dev.txt: 1 packages, 0 advisories; docker/main/requirements-wheels.txt: 4 packages, 0 advisories; docker/rockchip/requirements-wheels-rk.txt: 2 packages, 0 advisories; docker/tensorrt/requirements-amd64.txt: 13 packages, 2 advisories; docker/tensorrt/requirements-models-arm64.txt: 2 packages, 14 advisories; docs/package-lock.json: 1,561 packages, 28 advisories; web/package-lock.json: 725 packages, 6 advisories. |
| Project hygiene | Has automated dependency updates, licence file, contributing guide. Missing security policy, CodeQL. |
| OpenSSF Scorecard | 6.3 out of 10, as of Sep 28, 2026. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Pattern hits (1)
| Where | Rule | Match |
|---|---|---|
| docker/deepx/user_installation.sh:116 | persistence | sudo systemctl enable dxrt.service |
npm lifecycle scripts (1)
web/package.jsonpostinstall:patch-package
Installer scripts (6)
- .devcontainer/features/onnxruntime-gpu/install.sh, 15 lines
- docker/main/install_deps.sh, 213 lines; talks to deb.debian.org, github.com, repositories.intel.com
- docker/main/install_go2rtc.sh, 20 lines; talks to github.com
- docker/main/install_s6_overlay.sh, 36 lines; talks to github.com
- docker/main/install_tempio.sh, 26 lines; talks to github.com
- docker/rpi/install_deps.sh, 35 lines; talks to archive.raspberrypi.org, deb.debian.org
Worst known vulnerabilities (24 of 45)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-7gcm-g887-7qv7 | high | protobuf@3.20.3 | protobuf affected by a JSON recursion depth bypass |
| GHSA-8qvm-5x2c-j2w7 | high | protobuf@3.20.3 | protobuf-python has a potential Denial of Service issue |
| GHSA-3r9x-f23j-gc73 | high | onnx@1.14.0 | onnx Vulnerable to Path Traversal via Symlink |
| GHSA-538c-55jv-c5g9 | high | onnx@1.14.0 | ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. |
| GHSA-6rq9-53c3-f7vj | high | onnx@1.14.0 | onnx allows Arbitrary File Overwrite in download_model_with_test_data |
| GHSA-h36j-8vv3-cj52 | high | onnx@1.14.0 | Open Neural Network Exchange (ONNX) Path Traversal Vulnerability |
| GHSA-hqmj-h5c6-369m | high | onnx@1.14.0 | ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() - Silent Supply-Chain Attack |
| GHSA-q56x-g2fj-4rj6 | high | onnx@1.14.0 | ONNX: TOCTOU arbitrary file read/write in save_external_dat |
| GHSA-whh8-fjgc-qp73 | high | onnx@1.14.0 | Onnx Directory Traversal vulnerability |
| GHSA-qxc2-j82w-r537 | high | @faker-js/faker@5.5.3 | Faker: helpers.fake exploitable into arbritary code execution |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@1.1.18 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@1.1.18 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-ch52-4w7c-c8xp | high | http-cache-semantics@4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses |
| GHSA-2883-xcg3-v3hh | high | js-yaml@4.3.0 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| GHSA-5p4m-2wfm-xmqj | high | js-yaml@4.3.0 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) - CVE-2026-59870 fix not backported |
| GHSA-c2c7-rcm5-vvqj | high | picomatch@2.3.1 | Picomatch has a ReDoS vulnerability via extglob quantifiers |
| GHSA-5c6j-r48x-rmvq | high | serialize-javascript@6.0.2 | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() |
| GHSA-c2c7-rcm5-vvqj | high | picomatch@4.0.3 | Picomatch has a ReDoS vulnerability via extglob quantifiers |
| GHSA-g84c-rxfj-3j2c | high | webpack-dev-middleware@7.4.5 | webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath |
| GHSA-5j98-mcp5-4vw2 | high | glob@11.0.3 | glob CLI: Command injection via -c/--cmd executes matches with shell:true |
| GHSA-cmw6-hcpp-c6jp | moderate | onnx@1.14.0 | ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load |
| GHSA-h8wv-9h96-m4hr | moderate | onnx@1.14.0 | Onnx Out-of-bounds Read vulnerability |
| GHSA-hwpq-hmq9-wj77 | moderate | onnx@1.14.0 | ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs) |
Workflows worth a look
- .github/workflows/pr_template_check.yml: pull_request_target
By the numbers
| Stars | 36.3K |
|---|---|
| Forks | 3,661 |
| Contributors | 411 |
| Commits | 6,377 |
| Open issues | 74 |
| Open pull requests | 37 |
| Releases | 79 |
| Latest release | v0.18.0 |
| Licence | MIT |
| Main language | Python |
| Project age | 7 years |
| Last push | Oct 2, 2026 |
| Tracked files | 3,195 |
| Lines of code | 561.9K |
| Checkout size | 65 MB |
Lines by language: JSON 230.8K, TypeScript 155.1K, Python 137K, Markdown 20.9K, YAML 13.3K, CSS 2,311.
Questions
Is Frigate free?
Yes. Frigate's code is MIT-licensed and free, with no subscription needed to record or detect. Frigate+ is an optional paid service from the same team that trains detection models on your own camera images for better accuracy; everything else works without it.
What hardware does Frigate need?
Any Linux machine that runs Docker, plus ideally an AI accelerator. Supported detectors include Google Coral, Hailo, Intel GPUs and NPUs through OpenVINO, NVIDIA GPUs through TensorRT, AMD GPUs through ROCm, Rockchip NPUs and several M.2 accelerators. A CPU works for testing but struggles with several cameras.
Does Frigate need Home Assistant?
No. It runs on its own with a web interface for live view, review and recordings, and sends events over MQTT. Home Assistant is the integration it is designed around, adding notifications, automations and camera entities through a custom component.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
