Demonstrably Secure Software Supply Chains with Nix