Reflecting on it, I guess my OS config has turned into a codebase. I have a single Nix closure that includes all my OS config, all the services running on it, and all the small utilities that need to be compiled from source (either because they are something I wrote, or something that isn't packaged in Nixpgs). I'm not sure whether this is considered best practice or not. To your point though, I would be unaware if an upstream maintainer released a security patch for something that I'm compiling from source, because I am pinned to a specific Git commit. On the other hand, I can just point an LLM at my Nix source, and ask it to scan it for security issues periodically. I do this from time to time with one of the smart models, but it might be an interesting experiment to set up a daily scan with an inexpensive or even a local model.