[Funding] Hosting expenses for the Nixpkgs vulnerability tracker
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 141
- Forks
- 17
- PR merge metrics
- No merged PRs in 30d
Description
The Nixpkgs vulnerability tracker was developed with financial support by the Sovereign Tech Fund. It demoed to the security team in December 2024 and is now deployed on official infra under https://tracker.security.nixos.org for testing purposes. Thanks to the @nixos/infra team for your support!
It's likely there will be means available to continue development in 2025 to roll it out for day-to-day operations, which will result in growing resource consumption.
In order to cover hosting expenses, I request to reserve a slice of 100€/month from the infrastructure budget.
Currently we're spending <35€/month. The server runs nightly CVE ingestions and Nixpkgs evaluations and stores a couple GB of data. The goal is to keep expenses at the low end, ideally by taking evals directly from Hydra, and pruning old data.
@nixos/steering approves according to @tomberek.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the deployed tracker at https://tracker.security.nixos.org and the stated hosting costs, nightly CVE ingestions, Nixpkgs evaluations, and data storage needs. Done means reaching a decision on reserving up to 100€/month from the infrastructure budget; the issue does not name code files or tests.
Written by the indexing model from the issue text.
Assessment
- Domain
- infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100