Updated 22:01
Determinate Secure Packages CVE Remediation Dashboard
Every Common Vulnerabilities and Exposures record (CVE) in Determinate Secure Packages, we patch within our service-level agreement (SLA), rebuild, and ship to you from FlakeHub Cache. This is that work as it lands.
Fixed in the last 30 days
3326
Fixed in the last 7 days
257
In progress
336
CVE tracker
Every dot is one CVE, in the row for its severity and wearing that severity’s color. A filled dot sits on the day we shipped its fix, over the last 30 days. Hollow dots sit in the band past today’s line: the CVEs we’re working on right now.
3662 of 3662 tracked CVEs shown.
- Fixed (3326)
- In progress (336)
- Today
About Determinate Secure Packages
Every fix on this page is one you didn’t have to make. Determinate Secure Packages watches the packages you depend on, patches them within the SLA, and ships the builds to you.
Determinate Secure Packages overview (opens in a new tab)
What you get, how it fits your Nix setup, and how to start.
determinate.systems
Documentation (opens in a new tab)
How the SLA works, which packages we cover, and how to use them.
docs.determinate.systems
Supply chain security (opens in a new tab)
Control over the code, dependencies, builds, and environments behind every system you run.
determinate.systems
CVEs at a glance
The CVEs on the timeline, counted by severity, by how much of the work is done, and by how quickly the fixes landed.
Severity
The share of tracked CVEs at each severity level.
- Critical35610%
- High139538%
- Medium162944%
- Low2828%
Status
How much of the work is done and how much is in hand.
- Fixed332691%
- In progress3369%
Time to fix
Of the 3326 CVEs fixed in the last 30 days, the share fixed the same day, the next day, and so on, counting from when work on each began.
- Same day: 2100 of 3326, 63%
- 1 day: 560 of 3326, 17%
- 2 to 3 days: 342 of 3326, 10%
- 4 to 7 days: 220 of 3326, 7%
- 8 to 15 days: 101 of 3326, 3%
- 16 to 30 days: 3 of 3326, <1%
- Over 30 days: 0 of 3326, 0%
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.
Vulnerability databases
The databases the dashboard draws on. Every CVE here is one of theirs.
National Vulnerability Database (opens in a new tab)
The CVE records the dashboard follows and the write-up each one shows.
Open Source Vulnerabilities (opens in a new tab)
A second record of each CVE with the affected versions.