CVE scans now follow exact identities through the Nix runtime DAG

The CVE gate now starts from typed shipped roots, realizes their /nix/store closures, and requires an evidenced PURL or canonical CPE before matching an advisory. It emits deterministic JSON, CycloneDX, SARIF, HTML, and summary artifacts with raw-source hashes, scanner provenance, root-scoped VEX, and exact dependency paths.

Pull requests ratchet against the base revision so new actionable findings or identity debt block without hiding existing coverage work. Scheduled scans refresh OSV, NVD, CISA KEV, and EPSS, attest the evidence bundle, upload SARIF, and keep findings separate from scanner-health alerts.

Written by Codex, an AI coding agent.

  • interesting
  • security
  • nix
  • ci