Updated 14:01
Determinate Secure Packages distributions
Determinate Secure Packages ships both as a rolling distribution that follows Nixpkgs as it moves, and as versioned distributions built on one Nixpkgs release each and supported for years. We track every Common Vulnerabilities and Exposures record (CVE) separately in every distribution it affects, so the same CVE appears once per distribution, and we fix it in each one.
3 supported distributions
secure-packages-rolling
SupportedFIPS supportedBuilt on Nixpkgs as it moves
- Fixed (30d)
- 807
- Fixed (7d)
- 603
- In progress
- 83
See 890 tracked CVEs
secure-packages-26.05
SupportedFIPS supportedBuilt on Nixpkgs 26.05
- Fixed (30d)
- 751
- Fixed (7d)
- 575
- In progress
- 189
See 940 tracked CVEs
secure-packages-25.11
SupportedFIPS plannedBuilt on Nixpkgs 25.11
- Fixed (30d)
- 794
- Fixed (7d)
- 674
- In progress
- 123
See 917 tracked CVEs
secure-packages-25.05
PlannedWill be built on Nixpkgs 25.05
secure-packages-24.11
PlannedWill be built on Nixpkgs 24.11
Glossary
| Term | Meaning |
|---|---|
| Supported | Available for use in production environments and covered by our standard service-level agreement (SLA) |
| Planned | Not yet available |
| FIPS supported | A variant is available for environments that require cryptography compliant with Federal Information Processing Standards (FIPS) |
| FIPS planned | No FIPS variant yet but we plan to release one |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.
Learn more
Distributions
The table these distributions come from: standing and FIPS.
docs.determinate.systems (opens in a new tab)
Package update policy
How we handle packages we can't patch in place, like browser engines and kernels.
docs.determinate.systems (opens in a new tab)
Determinate Secure Packages overview
What you get, how it fits your Nix setup, and how to start.
determinate.systems (opens in a new tab)
Supply chain security
Control over the code, dependencies, builds, and environments behind every system you run.
determinate.systems (opens in a new tab)