Introducing Determinate Secure Packages LTS

We’re excited to announce the availability of Determinate Secure Packages LTS (long-term support) to all Determinate Secure Packages customers. With LTS, which replaces our originally offered Determinate Secure Packages product as of today, there will always be at least one secure packages distribution available with 60 months of support, starting with 26.05, while every other distribution will get 12 months of support.
For each distribution, “support” means:
- CVE remediation backed by our SLA
- Full cache coverage in FlakeHub Cache
- An optional Federal Information Processing Standards (FIPS) variant
- Cryptographically signed packages (including Commercial National Security Algorithm (CNSA) 2.0 post-quantum signatures)
But there are two important things haven’t changed:
- All distributions are available to our customers at all times, so your org is free to mix and match them in the way that best suits your needs.
- All customers get access to both FlakeBOM, our lightning-fast CLI for generating SBOMs in CycloneDX format, and FlakeAudit, our tool for evaluating those SBOMs against your org’s security policies.
How support works
Under Determinate Secure Packages LTS, every May release of Nixpkgs in an even-numbered year gets 60 months of support. The already-released 26.05 is the first, supported until May 2031, and 28.05 will be the next, starting in May 2028. Because a new 60-month distribution arrives every two years, you’ll never have to wait for one to become available. If you need support beyond five years, you can purchase for any 60-month distribution.
Every other bi-yearly release gets 12 months of support. That applies to the already-available 25.11 and will apply to 26.11, 27.05, and others in the future. It’s important to note that twelve months is six months longer than upstream Nixpkgs supports each release, and for that entire window you get our full support, with SLA-backed CVE remediation, cache coverage, signed packages, and the rest.
Beyond that, we also offer a rolling release that tracks Nixpkgs master and will continue to do so indefinitely.
This means that there will be at least three distributions available at all times.
This diagram provides a succinct illustration of the LTS system:
For more information, see the support calendar at security.determinate.systems.
Why we made the change
When we launched Determinate Secure Packages, we initially committed to supporting every distribution for 12 months. But since then, customer feedback has made it clear that many orgs need coverage for significantly longer periods than that. Two key considerations convinced us that we needed to update the terms of our secure packages offering:
- Many orgs that use Nix ship devices and systems with long field lifetimes, and those orgs need predictable coverage throughout.
- Article 13(8) of the EU Cyber Resilience Act requires a support period of at least five years, and we wanted to provide concrete assurances to orgs operating within that regime.
Our SLA
Whichever distribution you’re on, CVE remediation is backed by the same SLA throughout its support window, be it 12 months or 60:
- CriticalFixed within 7 days
- HighFixed within 15 days
- MediumFixed within 45 days
- LowFixed within 90 days
To get a detailed view of our remediation work across all available distributions, check out our dedicated dashboard at security.determinate.systems.
FIPS
To best serve U.S. federal government and other regulated workloads, every 60-month distribution provides optional variants with Federal Information Processing Standards (FIPS) mode enabled for tools like OpenSSL, GnuTLS, and others, as well as tools that depend on them, like compilers and runtimes.
See our documentation for more info on FIPS enablement.
Getting started
First, to establish a customer relationship. Once you’ve done that, using Determinate Secure Packages LTS instead of standard Nixpkgs generally involves little more than swapping a flakeref, like this:
{ inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";}Written by
Jeff has been building developer tools for the last 15 years in both product management and startup founder roles. He is the Chief Executive Officer of Determinate Systems.
