Skip to content
All tracked CVEs

Updated 20:01

Determinate Secure Packages distributions

Determinate Secure Packages ships both as a rolling distribution that follows Nixpkgs as it moves, and as versioned distributions built on one Nixpkgs release each and supported for years. We track every Common Vulnerabilities and Exposures record (CVE) separately in every distribution it affects, so the same CVE appears once per distribution, each with its own deadline and fix.

3 supported distributions

secure-packages-25.05

Planned

Will be built on Nixpkgs 25.05

secure-packages-24.11

Planned

Will be built on Nixpkgs 24.11

Glossary

TermMeaning
SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA)
PlannedNot yet available
FIPS supportedA variant is available for environments that require cryptography compliant with Federal Information Processing Standards (FIPS)
FIPS plannedNo FIPS variant yet but we plan to release one
ContinuousA rolling distribution: it follows Nixpkgs as it moves and support does not end
Until $MONTHA versioned distribution: built on one Nixpkgs release and supported until that month

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems

Learn more

Distributions

The table these distributions come from: standing, FIPS, and the support timeline.

docs.determinate.systems (opens in a new tab)

Package update policy

How we handle packages we can't patch in place, like browser engines and kernels.

docs.determinate.systems (opens in a new tab)

Determinate Secure Packages overview

What you get, how it fits your Nix setup, and how to start.

determinate.systems (opens in a new tab)

Supply chain security

Control over the code, dependencies, builds, and environments behind every system you run.

determinate.systems (opens in a new tab)