Hacker News new | ask | show | jobs
by niz4ts 932 days ago
How do you folks manage NixOS from a security/compliance perspective? I'm currently considering NixOS for a few test services in my company, and security/compliance is the biggest obstacle. Have you had to develop your own tooling for this?

To expand on it further: NixOS has modules and packages that come straight from Nixpkgs, and there are concerns with supply chain attacks because of that. How does your company solve this?