Updated 22:00
Determinate Secure Packages distribution
secure-packages-rollingSupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.ContinuousCovered continuously, with no end date: as it follows Nixpkgs, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs as it moves. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
210
last 30 days
Fixed within SLA
24
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
237 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Low | Skia uninitialized use in Chrome <151.0.7922.109 leaks cross-origin data after renderer compromise via crafted HTML | Aug 10, 2026 | Nov 8, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Low | Chrome <151.0.7922.109 Skia uninitialized use leaks cross-origin data post-renderer compromise | Aug 10, 2026 | Nov 8, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome Views before 151.0.7922.109 enables remote heap corruption via crafted HTML, UI gestures | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Windows Chrome pre-151.0.7922.109 Views use-after-free allows heap corruption via crafted HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical | Critical ANGLE out-of-bounds write enables sandbox escape via crafted HTML in Chrome Android <151.0.7922.109 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | High-severity Google Chrome Base heap buffer overflow pre-151.0.7922.109 via malicious extension | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome Payments (<151.0.7922.109) enables sandbox escape from compromised renderer | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Critical use-after-free in Skia enables sandbox escape in Chrome Android <151.0.7922.109 via HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Pre-151.0.7922.109 Chrome Workers input validation flaw enabled site isolation bypass via crafted HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Insufficient navigation policy in Chrome <151.0.7922.109 allows renderer sandbox escape via crafted HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome V8 use-after-free enables sandboxed RCE via crafted HTML, high severity (pre-151.0.7922.109) | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | V8 in Chrome <151.0.7922.109 allows sandboxed RCE via crafted HTML page | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical | Critical UAF in Chrome Aura on Linux enables remote sandbox escape via crafted HTML pre-151.0.7922.109 | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome Linux GPU OOB write allows sandbox escape via crafted HTML (pre-151.0.7922.109) | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Medium | Uninitialized GPU use in Chrome Android leaks process memory via crafted HTML (pre-151.0.7922.109) | Aug 10, 2026 | Sep 24, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.109 Translate use-after-free allows sandboxed RCE via crafted HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome Android WebAPK input validation flaw enables local sandbox escape via malicious file | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome Android pre-151.0.7922.109 Resources use-after-free enables sandbox escape from compromised renderer via crafted HTML page | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome GPU use-after-free <151.0.7922.109 allows sandbox escape from compromised renderer via HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Windows Chrome CredentialProvider race allows local privilege escalation via malicious file pre-151.0.7922.109 | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome CrashReporting heap overflow enables sandbox escape with renderer compromise (pre-151.0.7922.109) | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | WebGL use-after-free allows sandbox escape post-renderer-compromise in Chrome Android <151.0.7922.109 | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Medium | Windows Chrome Updater bug allows local UI spoofing via malicious file pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Critical | Tint implementation flaw in Chrome Mac before 151.0.7922.72 allows sandbox escape via crafted HTML | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Google Chrome Linux pre-151.0.7922.72 Views use-after-free enables remote heap corruption via crafted HTML | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Android Chrome <151.0.7922.72 GPU side-channel leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Cast prior to 151.0.7922.72 cross-origin data leak via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome pre-151.0.7922.72 CSS bug allows remote UXSS via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | GetUserMedia cross-origin data leak in Chrome before 151.0.7922.72 via compromised renderer using crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome Credential Management vulnerability enables remote UI spoofing via crafted HTML pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Payments insufficient input validation allows UI spoofing via compromised renderer prior to 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS pre-151.0.7922.72 input validation flaw enables remote navigation restriction bypass | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Blink vulnerability allowed cross-origin data leak via crafted HTML in Chrome <151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Inappropriate DevTools implementation enables same-origin policy bypass before Chrome 151.0.7922.72 via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Insufficient DevTools input validation enables privilege escalation via malicious Chrome extension (pre-151.0.7922.72) | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Uninitialized use in ANGLE allowed cross-origin data leak in Chrome <151.0.7922.72 via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Chrome Mac Audio use-after-free permits sandbox escape after renderer compromise via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Loader bug leaks cross-origin data via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72: Omnibox URL spoofing via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Isolated Web Apps navigation restriction bypass via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome prior to 151.0.7922.72: Remote Site Isolation bypass via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Autofill pre-151.0.7922.72 cross-origin data leak via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 Receiver policy bypass allows sandbox escape via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 PresentationAPI vulnerability allows cross-origin data leak via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Pre-151.0.7922.72 Chrome Variations input validation flaw enables heap corruption via privileged network attacker | Aug 5, 2026 | Aug 20, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Cast insufficient input validation allowed cross-origin data leak via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome WebGL out-of-bounds read pre-151.0.7922.72 enables remote memory disclosure via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Uninitialized Skia use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome macOS Media out-of-bounds read enables sandbox escape after renderer compromise (pre-151.0.7922.72) | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Cast insufficient input validation leaks cross-origin data via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.