Files
nixpkgs/pkgs/by-name/se/secretspec/package.nix
Domen Kožar a690c58565 secretspec: 0.21.0 -> 0.21.1
Changelog: https://github.com/cachix/secretspec/blob/v0.21.1/CHANGELOG.md
Release: https://github.com/cachix/secretspec/releases/tag/v0.21.1

The published crate now ships every test fixture, so drop the sparse
checkout of the release tag. The external provider ancestor walk tests
no longer depend on host ownership, so stop skipping them.

Assisted-by: Claude Code (Claude Opus 5.5)
2026-09-27 02:45:30 +02:00

55 lines
1.1 KiB
Nix

{
lib,
rustPlatform,
fetchCrate,
cacert,
gitMinimal,
jq,
sops,
nix-update-script,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "secretspec";
version = "0.21.1";
src = fetchCrate {
inherit (finalAttrs) pname version;
hash = "sha256-VCvo+O3IHVUeZG6cxBmWy8/CEDZOwVr8IVcWxroUd00=";
};
cargoHash = "sha256-cA7HmOxCrfPiBKI8xxxpRBvGLUgyl4Ts1uhoCt0bBuk=";
postPatch = ''
patchShebangs tests/fixtures/bw-shim.sh
'';
nativeCheckInputs = [
gitMinimal
jq
sops
];
preCheck = ''
export HOME="$TMPDIR"
export NO_COLOR=1
export SSL_CERT_FILE="${cacert}/etc/ssl/certs/ca-bundle.crt"
'';
# A test binds to localhost, which requires an explicit Darwin sandbox exception.
__darwinAllowLocalNetworking = true;
passthru.updateScript = nix-update-script { };
meta = {
description = "Declarative secrets, every environment, any provider";
homepage = "https://secretspec.dev";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [
domenkozar
sandydoo
];
mainProgram = "secretspec";
};
})