Securing Nix Builds using microVMs
2026-08-08 , Nix Vegas Main Stage

Recent vulnerabilities like Copy Fail and DirtyFrag have made abundantly clear just how risky it is to run untrusted Nix builds inside your core infrastructure. In response, we at Determinate Systems have begun building every Nix package inside of ephemeral microVMs. This talk covers what microVMs are, how they limit kernel-level vulnerabilities, and how we hope to substantially improve our security posture using this technology.

I work on supply chain security at Determinate Systems.

This speaker also appears in: