NixOS / NixOS/foundation

[Funding] Hosting expenses for the Nixpkgs vulnerability tracker

Open
#185 5 comments 7 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
141
Forks
17
PR merge metrics
No merged PRs in 30d

Description

The Nixpkgs vulnerability tracker was developed with financial support by the Sovereign Tech Fund. It demoed to the security team in December 2024 and is now deployed on official infra under https://tracker.security.nixos.org for testing purposes. Thanks to the @nixos/infra team for your support!

It's likely there will be means available to continue development in 2025 to roll it out for day-to-day operations, which will result in growing resource consumption.

In order to cover hosting expenses, I request to reserve a slice of 100€/month from the infrastructure budget.

Currently we're spending <35€/month. The server runs nightly CVE ingestions and Nixpkgs evaluations and stores a couple GB of data. The goal is to keep expenses at the low end, ideally by taking evals directly from Hydra, and pruning old data.

@nixos/steering approves according to @tomberek.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the deployed tracker at https://tracker.security.nixos.org and the stated hosting costs, nightly CVE ingestions, Nixpkgs evaluations, and data storage needs. Done means reaching a decision on reserving up to 100€/month from the infrastructure budget; the issue does not name code files or tests.

Written by the indexing model from the issue text.

Assessment

Domain
infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.