Determinate Secure Packages: Nixpkgs with SBOMs, FIPS, and SLA'd CVE Patching
determinate.systems
determinate.systems
In pretty much every Nix consulting gig I’ve ever had, I’ve been asked something like "well, what about security patching?" This has been a high priority goal since I started Determinate Systems. We just had to build a lot of infrastructure and maturity as a company to make it feasible :).
Anyway, if you have any questions I'd be glad to answer. Thanks!