NixOS Turns Vulnerability Triage Into Code
The Unreasonable Effectiveness of Vex in NixOS
LLM-assisted vulnerability reports are flooding maintainers and security teams. VEX statements can help, but manual triage doesn't scale. In NixOS, configuration is code, so you can codify the conditions under which a CVE doesn't affect your system and automatically generate VEX statements. The author built nixos-vex to do exactly that, and shows how it reduced 272 Grype findings to 271 by conditionally ignoring CVE-2007-2768.
Once a CVE has been triaged and codified, the cost to re-check is close to zero (a little bit of CI overhead).