View organization page for WorkOS

16,598 followers

In a Nix-based architecture, every dependency is pinned to a file path. So a known CVE already has a known address. You look it up, see exactly where it lives, and remediate by bumping the version up or down to the last one that worked. Ron Efroni, CEO of Flox and President of the NixOS Foundation, calls this the "cryptographic layer" of software: deterministic, reproducible, and hardened by construction. We covered this and how Flox runs agents and 100+ sandbox platforms inside portable, hermetic environments.

Hi Ron Efroni the 'known CVE has a known address' framing is excellent. This solves trust for the environment layer, deterministic, verifiable by construction. I'm working on the same problem one layer up with ModGate (modgate.io): when agents inside those hermetic sandboxes start calling MCP servers or spawning sub-agents, 'who authorized this action' needs the same by-construction verifiability, signed agent identity, scoped permissions, cryptographic delegation chains. A hermetic sandbox running an unidentified agent is a very secure room with an unlocked door. Environment integrity + agent identity feels like the full trust stack for the agentic era.

Like
Reply

Flox very interesting 🤔

Like
Reply
See more comments

To view or add a comment, sign in

Explore content categories