Updated 20:01
Determinate Secure Packages distributions
Determinate Secure Packages ships both as a rolling distribution that follows Nixpkgs as it moves, and as versioned distributions built on one Nixpkgs release each and supported for years. We track every Common Vulnerabilities and Exposures record (CVE) separately in every distribution it affects, so the same CVE appears once per distribution, each with its own deadline and fix.
3 supported distributions
secure-packages-rolling
SupportedFIPS supportedContinuousBuilt on Nixpkgs as it moves
- Fixed (30d)
- 235
- Fixed (7d)
- 24
- Open
- 27
- Overdue
- 0
- Missed SLA
- 0
See 262 tracked CVEs
secure-packages-26.05
SupportedFIPS supportedUntil November 2029Built on Nixpkgs 26.05
- Fixed (30d)
- 503
- Fixed (7d)
- 18
- Open
- 27
- Overdue
- 0
- Missed SLA
- 0
See 530 tracked CVEs
secure-packages-25.11
SupportedFIPS plannedUntil May 2028Built on Nixpkgs 25.11
- Fixed (30d)
- 172
- Fixed (7d)
- 2
- Open
- 28
- Overdue
- 0
- Missed SLA
- 0
See 200 tracked CVEs
secure-packages-25.05
PlannedWill be built on Nixpkgs 25.05
secure-packages-24.11
PlannedWill be built on Nixpkgs 24.11
Glossary
| Term | Meaning |
|---|---|
| Supported | Available for use in production environments and covered by our standard service-level agreement (SLA) |
| Planned | Not yet available |
| FIPS supported | A variant is available for environments that require cryptography compliant with Federal Information Processing Standards (FIPS) |
| FIPS planned | No FIPS variant yet but we plan to release one |
| Continuous | A rolling distribution: it follows Nixpkgs as it moves and support does not end |
| Until $MONTH | A versioned distribution: built on one Nixpkgs release and supported until that month |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.
Learn more
Distributions
The table these distributions come from: standing, FIPS, and the support timeline.
docs.determinate.systems (opens in a new tab)
Package update policy
How we handle packages we can't patch in place, like browser engines and kernels.
docs.determinate.systems (opens in a new tab)
Determinate Secure Packages overview
What you get, how it fits your Nix setup, and how to start.
determinate.systems (opens in a new tab)
Supply chain security
Control over the code, dependencies, builds, and environments behind every system you run.
determinate.systems (opens in a new tab)