Finally, a secure Nixpkgs for the enterprise: an update on Determinate Secure

It would be interesting to hear your thoughts on Security fixes should bypass staging — unbound CVE batch as a case study and how you think nixpkgs itself could improve with lessons you’ve pulled from your product.

I assume your suggestion would be having smaller channels for more focused usecases to ship updates faster?

1 Like