Updated 14:01
Determinate Secure Packages CVE Remediation Dashboard
Every Common Vulnerabilities and Exposures record (CVE) in Determinate Secure Packages, we patch within our service-level agreement (SLA), rebuild, and ship to you from FlakeHub Cache. This is that work as it lands.
Fixed in the last 30 days
2352
Fixed in the last 7 days
1852
In progress
395
CVE tracker
Every dot is one CVE, in the row for its severity and wearing that severity’s color. A filled dot sits on the day we shipped its fix, over the last 30 days. Hollow dots sit in the band past today’s line: the CVEs we’re working on right now.
236 of 1393 tracked CVEs shown.
- In progress (236)
- Today
About Determinate Secure Packages
Every fix on this page is one you didn’t have to make. Determinate Secure Packages watches the packages you depend on, patches them within the SLA, and ships the builds to you.
Determinate Secure Packages overview
What you get, how it fits your Nix setup, and how to start.
determinate.systems (opens in a new tab)
Documentation
How the SLA works, which packages we cover, and how to use them.
docs.determinate.systems (opens in a new tab)
Supply chain security
Control over the code, dependencies, builds, and environments behind every system you run.
determinate.systems (opens in a new tab)
CVEs at a glance
The CVEs on the timeline, counted by severity, by how much of the work is done, and by how quickly the fixes landed.
Severity
The share of tracked CVEs at each severity level.
- Critical2379%
- High115642%
- Medium115942%
- Low1957%
Status
How much of the work is done and how much is in hand.
- Fixed235286%
- In progress39514%
Time to fix
Of the 2352 CVEs fixed in the last 30 days, the share fixed the same day, the next day, and so on, counting from when work on each began.
- Same day: 1672 of 2352, 71%
- 1 day: 233 of 2352, 10%
- 2 to 3 days: 180 of 2352, 8%
- 4 to 7 days: 187 of 2352, 8%
- 8 to 15 days: 34 of 2352, 1%
- 16 to 30 days: 30 of 2352, 1%
- Over 30 days: 16 of 2352, 1%
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.
Vulnerability databases
The databases the dashboard draws on. Every CVE here is one of theirs.
National Vulnerability Database (opens in a new tab)
The CVE records the dashboard follows and the write-up each one shows.
Open Source Vulnerabilities (opens in a new tab)
A second record of each CVE with the affected versions.