Tech article
The Unreasonable Effectiveness of Vex in NixOS
No preview is available. Read the original article for the full story.
Hacker News | Oct 11, 2026 | datosh
Automated excerpt
VEX stands for Vulnerability Exploitability eXchange: a machine-readable security advisory that tells you whether a specific software product is actually exposed to a known vulnerability. Using v0. 38. 0 of the golang. org/x/text library: golang. org/x/text v0. 38. 0 0. 39. 0 go-module GO-2026-5970 High 0. 5% (39th) 0. 4 golang. org/x/text v0. 38. 0 0. 41. 0 go-module GO-2026-6629 High 0. 3% (24th) 0. 3 If we do the legwork though, we can see that neither vulnerability actually affects our program. GO-2026-5970 only exists in the golang. org/x/text/unicode/norm package, and GO-2026-6629 only exists in the golang. org/x/text/secure/precis package.
Selected automatically from source text; not independently written or fact-checked. Read the original for full context.