Skip to Content
Determinate Secure Packages

Determinate Secure Packages

Determinate Secure Packages provides secure, signed, auditable Nix packages that you can trust. It’s built on Nixpkgs, the world’s largest package repository, and adds the enterprise-grade security, compliance controls, and managed vulnerability remediation demanded by production systems in critical industries, including support for Federal Information Processing Standards (FIPS).

Determinate Secure Packages is available through FlakeHub to organizations that have been provided access. Contact us to discuss terms of access or schedule a demo.

Live dashboardSee how we stay ahead of CVEs
Every CVE in Determinate Secure Packages has a fix deadline set by our SLA. The dashboard follows each one from disclosure to remediation, so you can see what we've fixed recently and what we're fixing right now.

Distributions

VersionStatusFIPSSupport timeline
secure-packages-rollingSupportedFIPS supportedContinuous
secure-packages-26.05SupportedFIPS supportedUntil May 2031 (LTS)
secure-packages-25.11SupportedUntil November 2026
secure-packages-26.11PlannedUntil November 2027
secure-packages-27.05PlannedUntil May 2028
secure-packages-27.11PlannedUntil November 2028
secure-packages-28.05PlannedFIPS plannedUntil May 2033 (LTS)

Key:

  • Supported: Available for use in production environments and covered by our standard SLA.
  • Pre-release: Not yet available for use in production environments but available for testing and feedback. Pre-release distributions are not covered by our standard SLA.
  • Pending: Integration is in progress, and will soon be available as pre-release.
  • Planned: Not yet available.
  • LTS: A long-term support distribution, with 60 months of support. See support timelines.
  • FIPS supported: A distribution with Federal Information Processing Standards (FIPS) mode enabled is available for government and other regulated workloads.
  • FIPS planned: A distribution with FIPS mode enabled isn’t available yet, but we plan to release one. Contact us to help us prioritize its release.

Support timelines

We support every versioned distribution for at least 12 months from its Nixpkgs release. The distribution built on the May Nixpkgs release of every even-numbered year, such as secure-packages-26.05 and secure-packages-28.05, is a long-term support (LTS) distribution with 60 months of support. That makes one in every four distributions an LTS distribution, and at least one LTS distribution is always available. The secure-packages-rolling distribution has no end date.

If you need support beyond 60 months, we offer optional extended support for any LTS distribution. Contact us and we’ll work out the terms together.

The support calendar shows the timeline for every current and planned distribution.

System support

These systems are fully supported, with covered packages pre-built and cached in FlakeHub Cache:

  • x86_64-linux (64-bit x86 Intel/AMD Linux)
  • aarch64-linux (64-bit ARM Linux)
  • aarch64-darwin (64-bit ARM macOS)

These systems are partially supported, which means that covered packages are not pre-built/cached:

  • x86_64-darwin (64-bit Intel/AMD macOS) is available as a legacy target
  • riscv64-linux (64-bit RISC-V) is available as an upcoming target

Variants

There are two variants of Determinate Secure Packages via FlakeHub (accessible only if you have access and are logged in):

  1. The standard variant at DeterminateSystems/secure-packages-rolling. You should use this unless you’re sure that you need FIPS mode enabled.
  2. The FIPS variant at DeterminateSystems/secure-packages-rolling-fips.

Requirements

If you’d like to use Determinate Secure Packages, you need to ensure that:

  • Your organization has access.
  • You’ve installed Determinate Nix. In CI environments, use the Determinate Nix Action to install it (authentication with FlakeHub is automatic).
  • You’ve authenticated with FlakeHub and thereby with FlakeHub Cache. Authentication happens automatically in cloud environments like Amazon Web Services and CI/CD environments like GitHub Actions.

Usage

Once you’ve checked those boxes, you can add Determinate Secure Packages to an existing flake using fh, the CLI for FlakeHub:

fh add DeterminateSystems/secure-packages-rolling

Or you can add it manually:

flake.nix
{ inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0"; }

Using the FIPS variant

Determinate Secure Packages also has a variant with FIPS mode enabled for widely used packages like OpenSSL, Network Security Services (NSS), GnuTLS, and Cryptsetup, as well as any packages that depend on them.

The instructions for this variant are analogous to those above, except that:

  1. You can run fh add DeterminateSystems/secure-packages-rolling-fips to add it to a flake
  2. You need to use the flake input https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0 in your flakes

Another way to use the package set with FIPS mode enabled is to set config.enableFIPS = true when importing the secure-packages-rolling variant:

flake.nix
{ inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0"; # In your outputs block pkgs = import inputs.nixpkgs { # Other attributes config.enableFIPS = true; }; }

In general, though, we recommend using the DeterminateSystems/secure-packages-rolling-fips flake instead of this approach.

Example flake

The flake below uses Determinate Secure Packages with FIPS mode enabled to output a dev shell with OpenSSL available:

flake.nix
{ inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0"; outputs = { self, ... }@inputs: let supportedSystems = [ "x86_64-linux" # 64-bit x86 Intel/AMD Linux "aarch64-linux" # 64-bit ARM Linux "aarch64-darwin" # 64-bit ARM macOS ]; forEachSupportedSystem = f: inputs.nixpkgs.lib.genAttrs supportedSystems ( system: f { pkgs = import inputs.nixpkgs { inherit system; }; } ); in { devShells = forEachSupportedSystem ( { pkgs }: { default = pkgs.mkShell { packages = with pkgs; [ openssl ]; }; } ); }; }

Package inclusion

You can use any package available in the revision of Nixpkgs from which a specific release of Determinate Nix Packages was built (evaluate it, build it, run it, and so on). Determinate Systems actively monitors, patches (if necessary), builds, and caches a carefully chosen of subset of all available packages. That includes packages for which FIPS mode is relevant as well as:

  • A variety of packages deemed of critical importance, such as widely used shells and shell utilities, systemd, various language compilers, and more
  • All of the packages necessary to build Determinate Nix, FlakeHub, and other Determinate Systems software
  • All of the packages necessary to build a baseline NixOS system

This curated package set will grow over time in response to customer and community needs (with customer needs having higher priority).

Provided tools

Determinate Secure Packages also includes two CLI tools that turn the metadata carried by the package set into something you can act on:

  • FlakeBOM generates a CycloneDX Software Bill of Materials (SBOM) from a flake, covering everything your flake’s outputs depend on. On a flake that uses Determinate Secure Packages, it also picks up the package identifiers, provenance, and curated vulnerability exploitability exchange (VEX) metadata that upstream Nixpkgs doesn’t carry.
  • FlakeAudit evaluates an SBOM against a policy that you write, covering licenses, banned components, permitted package sources, and vulnerabilities. A failing check exits non-zero, so you can gate a build or a release on the result.

The two work together: run flakebom against a flake that uses Determinate Secure Packages, then run flakeaudit check on the SBOM it produces. FlakeAudit accepts SBOMs from any source, but our curated VEX metadata is what takes a vulnerability out of its default untriaged state, and FlakeBOM is what carries that metadata into the SBOM.

Package update policy for long term support releases

We update Determinate Secure Packages regularly to ensure that the package set remains secured against known vulnerabilities. We prioritize package updates based on the severity of the vulnerabilities identified and the importance of specific packages to our customers.

Our workflow:

  • We typically incorporate changes from the corresponding upstream Nixpkgs release branch within two weeks, with a target minimum cadence of once every three weeks.
  • We will resolve vulnerabilities without breaking compatibility when possible, generally by applying minor or patch version bumps.
  • If we can’t update the vulnerable package, we will backport security patches to the current major version.

Some packages are not amenable to that approach, and for those we have a different policy:

Package typeUpdate policy
Browser enginesWe will not attempt to backport patches and will instead seek to ship the latest stable release of that software.
Closed source softwareWe will not attempt to backport patches and will instead seek to ship the latest stable release of that software.
Linux kernelsWe provide and maintain the latest kernel LTS branches on every distribution and recommend following the Linux team’s recommendation to run the latest stable release.

Exceptions to the above, although rare, will be documented as errata.

Service-level agreement (SLA)

In supported distributions of Determinate Secure Packages, CVE mitigation is covered by this SLA:

Vulnerability levelInitial responseMitigation SLA
CriticalAim to mitigate within 24 hours of embargo lifting7 days
High severityAim to mitigate within 72 hours of embargo lifting15 days
Medium severity45 days
Low severity90 days

We hold ourselves to this SLA in public. The CVE remediation dashboard tracks every CVE in Determinate Secure Packages against its deadline and shows how many we’ve fixed within the SLA, how many are open, and whether any are overdue.

We publish our triage of individual advisories as VEX metadata inside the package set itself. FlakeBOM carries that metadata into the SBOMs it generates, and FlakeAudit evaluates it against your own policy, so you can see how we analyzed each advisory that affects your build.

We continuously improve our detection of vulnerabilities and expand the coverage of the package set. In both cases we may occasionally identify vulnerabilities that are already breaching our SLA. When that happens, we treat those vulnerabilities as if they were newly disclosed and apply the SLA above starting from the date of discovery. After the initial intake, the SLA is applied based on when the vulnerability is first published.

This policy exception exists to support the improvement of our software identification and vulnerability detection capabilities, which in turn improves the security of our customers’ systems.

Errata

PackageDistributionDateReason
miniosecure-packages-25.112026-04-10Upstream project abandoned
N/Asecure-packages-rolling, secure-packages-25.11, secure-packages-26.05, and all future distributions2026-06-26nixos/lib/make-disk-image.nix, nixos/lib/make-multi-disk-zfs-image.nix, nixos/lib/make-single-disk-zfs-image.nix, and nixos/modules/installer/cd-dvd/channel.nix no longer include channels by default.
N/Asecure-packages-rolling, secure-packages-25.11, secure-packages-26.05, and all future distributions2026-06-26The HTML NixOS manual no longer includes the exact revision it was built from.
Last updated on