From 29ac8b84fb827c39a8a27ff2ff753777910edbae Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Sat, 24 May 2025 15:01:44 +0200 Subject: [PATCH] workflows/nixpkgs-vet: use nixpkgs-vet from pinned nixpkgs We have added nixpkgs-vet as a regular package to nixpkgs a while ago, so we can now use it from pinned nixpkgs. This avoids pulling a platform-specific binary version from upstream. This change also allows to run the tool easily locally, the same way as other tools: nix-build ci -A nixpkgs-vet This will do a full check of the repo with the exception of nixpkgs-vet's "ratchet" checks: Those depend on having two branches to compare, but the default is to only look at the head branch. Those ratchet checks will still be run in CI, though. (cherry picked from commit 942c377476675848155e860b9d41d869589b8a47) (cherry picked from commit 8eef7754077b467e2b17d6fdd14387c1d73ac4d3) --- .github/workflows/nixpkgs-vet.yml | 18 ++---------------- ci/default.nix | 1 + ci/nixpkgs-vet.nix | 31 +++++++++++++++++++++++++++++++ ci/nixpkgs-vet.sh | 4 +--- 4 files changed, 35 insertions(+), 19 deletions(-) create mode 100644 ci/nixpkgs-vet.nix diff --git a/.github/workflows/nixpkgs-vet.yml b/.github/workflows/nixpkgs-vet.yml index aefed2b267ce..dffa9b63dd89 100644 --- a/.github/workflows/nixpkgs-vet.yml +++ b/.github/workflows/nixpkgs-vet.yml @@ -19,8 +19,7 @@ permissions: {} jobs: check: name: nixpkgs-vet - # This needs to be x86_64-linux, because we depend on the tooling being pre-built in the GitHub releases. - runs-on: ubuntu-24.04 + runs-on: ubuntu-24.04-arm # This should take 1 minute at most, but let's be generous. The default of 6 hours is definitely too long. timeout-minutes: 10 steps: @@ -44,25 +43,12 @@ jobs: - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - - name: Fetching the pinned tool - # Update the pinned version using ci/nixpkgs-vet/update-pinned-tool.sh - run: | - # The pinned version of the tooling to use. - toolVersion=$(