FlakeHub now has FedRAMP High Authorization

5 Likes

This is really big news. I don’t think there’s many folks here who can appreciate how time consuming and costly it is to get FedRAMP certified.

  • Private flakes. Share Nix flakes across your team or org without needing to handle SSH keys or static credentials.

  • Trusted publishing and provenance. Semantic versioning for Nix flakes, cryptographic provenance, and publishing restricted to authorized CI/CD systems, so you can answer “what’s running, and where did it come from?” with certainty instead of hope.

Are there any plans to help integrate these features upstream?

The features you’re pointing to here are platform-side features, not really Nix-level features, so it’s not entirely clear what upstreaming would entail in these cases.