# Nixos-vex automates configuration checks for vulnerability triage

_Published Sunday, October 11, 2026 at 5:06 PM EDT · Security · Latest · Tier 2 — Notable_

Fabian Kammel has open-sourced nixos-vex, a project that turns vulnerability assessments into checks against NixOS system configurations. His demonstration generates a machine-readable advisory saying an OpenSSH vulnerability does not affect a system only while specified configuration conditions hold.

Passing that advisory to the Grype scanner reduced its vulnerability matches from 272 to 271, with one marked ignored. The approach requires initial manual triage and coding of the conditions, then rechecks them as configurations change. Kammel cautions against using the project as a high-trust data source yet.

## Sources

- [blog.kammel.dev](https://blog.kammel.dev/post/nixos_vex/)

---
Canonical: https://techandbusiness.org/newswire/UZnoNE0rVQA62DUpbCzmhU
Published: 2026-10-11T21:06:46.325Z
Story chronology: 2026-10-11T19:23:07.000Z
Retrieved: 2026-10-11T23:49:07.086Z
Publisher: Tech & Business (techandbusiness.org)
