feat(dev): add a pinned nix development shell - #413
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add a pinned Nix development shell with Git, Task, and git-of-theseus. Package the Python CLI through Nix, with supporting files under
tools/nix, so the environment needs onlyflake.nixandflake.lockat the repository root.Add history-analysis tasks and
nix fmt. Keep package smoke tests, Task integration checks, and formatting checks separate; declare test sources with Nix file sets and use standard build phases. Other repository tools can be added to the shell incrementally.Enable weekend Renovate maintenance for
flake.lockand require review for Nix workflow dependency updates. The custom git-of-theseus release still needs its version and wheel hash updated together manually.Validation:
nix flake checkpasses natively on Apple Silicon macOS and ARM/x86 Linux, and Kubeconform passes. Dependency checks confirm that task-script changes affect only the task check and shell-tool additions do not affect package or task checks. Renovate's strict config validation, dependency extraction, and effective update-policy checks pass.