Hardening packages on NixOS: https://github.com/NixOS/nixpkgs/issues/7220 (building on the ideas of Hardened Gentoo and equivalents)