Updated 06:00
Determinate Secure Packages CVE Remediation Dashboard
Every Common Vulnerabilities and Exposures record (CVE) in Determinate Secure Packages, we patch within our service-level agreement (SLA), rebuild, and ship to you from FlakeHub Cache. This is that work as it lands.
Fixed in the last 30 days
1986
Fixed in the last 7 days
175
In progress
194
CVE tracker
Every dot is one CVE, in the row for its severity and wearing that severity’s color. A filled dot sits on the day we shipped its fix, over the last 30 days. Hollow dots sit in the band past today’s line: the CVEs we’re working on right now.
2180 of 2180 tracked CVEs shown.
- Fixed (1986)
- In progress (194)
- Today
About Determinate Secure Packages
Every fix on this page is one you didn’t have to make. Determinate Secure Packages watches the packages you depend on, patches them within the SLA, and ships the builds to you.
Determinate Secure Packages overview (opens in a new tab)
What you get, how it fits your Nix setup, and how to start.
determinate.systems
Documentation (opens in a new tab)
How the SLA works, which packages we cover, and how to use them.
docs.determinate.systems
Supply chain security (opens in a new tab)
Control over the code, dependencies, builds, and environments behind every system you run.
determinate.systems
CVEs at a glance
The CVEs on the timeline, counted by severity, by how much of the work is done, and by how quickly the fixes landed.
Severity
The share of tracked CVEs at each severity level.
- Critical21110%
- High87340%
- Medium92042%
- Low1768%
Status
How much of the work is done and how much is in hand.
- Fixed198691%
- In progress1949%
Time to fix
Of the 1986 CVEs fixed in the last 30 days, the share fixed the same day, the next day, and so on, counting from when work on each began.
- Same day: 912 of 1986, 46%
- 1 day: 451 of 1986, 23%
- 2 to 3 days: 187 of 1986, 9%
- 4 to 7 days: 268 of 1986, 13%
- 8 to 15 days: 149 of 1986, 8%
- 16 to 30 days: 18 of 1986, 1%
- Over 30 days: 1 of 1986, <1%
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.
Vulnerability databases
The databases the dashboard draws on. Every CVE here is one of theirs.
National Vulnerability Database (opens in a new tab)
The CVE records the dashboard follows and the write-up each one shows.
Open Source Vulnerabilities (opens in a new tab)
A second record of each CVE with the affected versions.