mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-03 21:40:12 +00:00
Changelog: https://github.com/cachix/secretspec/blob/v0.21.1/CHANGELOG.md Release: https://github.com/cachix/secretspec/releases/tag/v0.21.1 The published crate now ships every test fixture, so drop the sparse checkout of the release tag. The external provider ancestor walk tests no longer depend on host ownership, so stop skipping them. Assisted-by: Claude Code (Claude Opus 5.5)
55 lines
1.1 KiB
Nix
55 lines
1.1 KiB
Nix
{
|
|
lib,
|
|
rustPlatform,
|
|
fetchCrate,
|
|
cacert,
|
|
gitMinimal,
|
|
jq,
|
|
sops,
|
|
nix-update-script,
|
|
}:
|
|
|
|
rustPlatform.buildRustPackage (finalAttrs: {
|
|
pname = "secretspec";
|
|
version = "0.21.1";
|
|
|
|
src = fetchCrate {
|
|
inherit (finalAttrs) pname version;
|
|
hash = "sha256-VCvo+O3IHVUeZG6cxBmWy8/CEDZOwVr8IVcWxroUd00=";
|
|
};
|
|
|
|
cargoHash = "sha256-cA7HmOxCrfPiBKI8xxxpRBvGLUgyl4Ts1uhoCt0bBuk=";
|
|
|
|
postPatch = ''
|
|
patchShebangs tests/fixtures/bw-shim.sh
|
|
'';
|
|
|
|
nativeCheckInputs = [
|
|
gitMinimal
|
|
jq
|
|
sops
|
|
];
|
|
|
|
preCheck = ''
|
|
export HOME="$TMPDIR"
|
|
export NO_COLOR=1
|
|
export SSL_CERT_FILE="${cacert}/etc/ssl/certs/ca-bundle.crt"
|
|
'';
|
|
|
|
# A test binds to localhost, which requires an explicit Darwin sandbox exception.
|
|
__darwinAllowLocalNetworking = true;
|
|
|
|
passthru.updateScript = nix-update-script { };
|
|
|
|
meta = {
|
|
description = "Declarative secrets, every environment, any provider";
|
|
homepage = "https://secretspec.dev";
|
|
license = lib.licenses.asl20;
|
|
maintainers = with lib.maintainers; [
|
|
domenkozar
|
|
sandydoo
|
|
];
|
|
mainProgram = "secretspec";
|
|
};
|
|
})
|