BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.nix.vegas//2026//speaker//39GR3G
BEGIN:VTIMEZONE
TZID:PST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T100000Z
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T110000Z
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-2026-AA9JET@cfp.nix.vegas
DTSTART;TZID=PST:20260808T140000
DTEND;TZID=PST:20260808T143000
DESCRIPTION:I built a tool to help maintainers patch nixpkgs CVEs faster. B
 ut I optimized the wrong thing.\n\nThe tool - Vulnpatch\, is a dashboard. 
 It pulls together CVE intelligence\, triages by what is actually being exp
 loited\, gives the maintainer the context they need and gets out of the wa
 y. The assumption underneath it was that the maintainer is the bottleneck:
  speed up the workflow and packages get patched faster.\n\nI no longer bel
 ieve that assumption. I was already building Vulnpatch to automate the rem
 ediation work when Mythos was announced\, and it undercut the premise. Bui
 lding a product to do what a frontier model could now do on its own was th
 e wrong problem to be solving.\n\nThe difficult part was never automating 
 the work. It is making an agent's output something a volunteer on the secu
 rity team can actually trust. The work is the evidence: which package is a
 ctually affected\, which upstream commit fixes it\, what the new hash is\,
  whether it still builds\, whether the tests still pass and whether a main
 tainer has any reason to trust it. And that is before the non-trivial case
 s: the patches that are not simple version bumps or hash updates.\n\nThis 
 is a talk about that shift. I will discuss Vulnpatch and Trace\, an agent-
 owned nixpkgs fork that produces signed\, reproducible CVE evidence bundle
 s instead of drive-by pull requests. And I want to make one argument I thi
 nk is worth taking seriously: Nix is unusually well-suited to AI agents be
 cause it provides strong automated feedback. Reproducible builds and passt
 hru.tests give agents an objective verifier for many changes\, whereas mos
 t repositories offer much weaker validation.\n\nPatches are cheap. Proof i
 s not. I will show what it takes to make an agent's work auditable enough 
 to be worth a maintainer's time and I hope\, to persuade maintainers that 
 agents belong in their workflow. The workflows we built for human-only con
 tribution will not survive contact with agents unchanged.
DTSTAMP:20260725T040022Z
LOCATION:Nix Vegas Main Stage
SUMMARY:Nix Knows When the Agent Is Wrong - Jason Odoom
URL:https://cfp.nix.vegas/2026/talk/AA9JET/
END:VEVENT
END:VCALENDAR
