Skip to content

Get Nix Stats ​

Retrieve counts of open nixpkgs security issues: the same figures /api/v1/stats publishes under nix, on their own.

Data Source

This endpoint returns statistics only for nixpkgs security issues. For combined stats across all ecosystems, use the /api/v1/stats endpoint.

Endpoint ​

GET /api/v1/nix/stats

The path is under /nix/. An earlier edition of this page named /api/v1/nix-stats, which has never answered.

Response ​

json
{
  "success": true,
  "data": {
    "total": 681,
    "closed": 5179,
    "totalTracked": 5860,
    "bySeverity": {
      "critical": 49,
      "high": 260,
      "medium": 241,
      "low": 51,
      "unknown": 80
    },
    "withFix": 129,
    "assigned": 0
  },
  "timestamp": "2026-09-28T01:02:23.793Z"
}

Response Fields ​

FieldTypeDescription
totalnumberOpen nixpkgs security issues. This once counted the whole corpus including closed issues and said 2779 where 607 were open.
closednumberClosed issues
totalTrackednumberOpen and closed together
bySeverityobjectOpen issues by severity, enriched from NVD where a CVSS score exists
bySeverity.critical, high, medium, low, unknownnumberCount per severity
withFixnumberOpen issues with a known fixed version
assignednumberOpen issues assigned to a contributor on GitHub

A GitHub failure answers 502 with data: null rather than zeros: a list that could not be read is not one with nothing open.

Example ​

bash
curl https://api.vulnpatch.dev/api/v1/nix/stats

Code Examples ​

javascript
async function displayNixStats() {
  const response = await fetch('https://api.vulnpatch.dev/api/v1/nix/stats');
  const { data } = await response.json();

  console.log(`Open: ${data.total} of ${data.totalTracked} tracked`);
  console.log(`With fix: ${data.withFix}`);
  console.log(`Assigned: ${data.assigned}`);
}
python
import requests

response = requests.get('https://api.vulnpatch.dev/api/v1/nix/stats')
stats = response.json()['data']

print(f"Open: {stats['total']} of {stats['totalTracked']} tracked")
print(f"With fix: {stats['withFix']}")
print(f"Assigned: {stats['assigned']}")
  • Nix CVEs - the issues themselves as CVE records
  • Aggregate Stats - these figures alongside OSV and recent-advisory counts