Latest posts

Artiflakery, an easy way to distribute static Nix flake artifacts

In this post, I introduce Artiflakery, a tool I created for on the fly delivery of Nix flakes artifacts.

NixFlakesWebserver

How NixOS and reproducible builds could have detected the xz backdoor for the benefit of all

In this article, I showcase a method to leverage reproducible builds to build trust in untrusted release assets. I claim that this method would have detected the 2024 xz backdoor attack.

NixOS Reproducible-Builds Software Supply ChainXZ Backdoor

Is NixOS truly reproducible?

How reproducible is NixOS? In this article I describe the results of a research work studying the evolution of bitwise reproducibility over time in the NixOS distribution, from 2017 to 2023.