forked from nikstur/bombon
-
Notifications
You must be signed in to change notification settings - Fork 0
/
flake.nix
121 lines (101 loc) · 3.17 KB
/
flake.nix
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
{
description = "Nix CycloneDX Software Bills of Materials (SBOMs)";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
systems.url = "github:nix-systems/default";
flake-utils = {
url = "github:numtide/flake-utils";
inputs.systems.follows = "systems";
};
flake-parts = {
url = "github:hercules-ci/flake-parts";
inputs.nixpkgs-lib.follows = "nixpkgs";
};
pre-commit-hooks-nix = {
url = "github:cachix/pre-commit-hooks.nix";
inputs = {
nixpkgs.follows = "nixpkgs";
};
};
};
outputs = inputs@{ self, flake-parts, systems, ... }: flake-parts.lib.mkFlake { inherit inputs; } {
systems = import systems;
imports =
let
# This is effectively just boilerplate to allow us to keep the `lib`
# output.
libOutputModule = { lib, ... }: flake-parts.lib.mkTransposedPerSystemModule {
name = "lib";
option = lib.mkOption {
type = lib.types.lazyAttrsOf lib.types.anything;
default = { };
};
file = "";
};
in
[
inputs.pre-commit-hooks-nix.flakeModule
libOutputModule
];
flake = {
templates.default = {
path = builtins.filterSource (path: type: baseNameOf path == "flake.nix")
./examples/flakes;
description = "Build a Bom for GNU hello";
};
};
perSystem = { config, system, pkgs, lib, ... }:
let
bombon = import ./. { inherit pkgs; };
inherit (bombon) transformer buildBom passthruVendoredSbom;
in
{
lib = { inherit buildBom passthruVendoredSbom; };
packages = {
# This is mostly here for development
inherit transformer;
default = transformer;
sbom = buildBom transformer { };
};
checks = {
clippy = transformer.overrideAttrs (_: previousAttrs: {
nativeCheckInputs = (previousAttrs.nativeCheckInputs or [ ]) ++ [ pkgs.clippy ];
checkPhase = "cargo clippy";
});
rustfmt = transformer.overrideAttrs (_: previousAttrs: {
nativeCheckInputs = (previousAttrs.nativeCheckInputs or [ ]) ++ [ pkgs.rustfmt ];
checkPhase = "cargo fmt --check";
});
} // import ./nix/tests { inherit pkgs buildBom; };
pre-commit = {
check.enable = true;
settings = {
hooks = {
nixpkgs-fmt.enable = true;
typos.enable = true;
statix = {
enable = true;
settings.ignore = [ "sources.nix" ];
};
};
};
};
devShells.default = pkgs.mkShell {
shellHook = ''
${config.pre-commit.installationScript}
'';
packages = [
pkgs.clippy
pkgs.rustfmt
pkgs.cargo-machete
pkgs.cargo-edit
pkgs.cargo-bloat
pkgs.cargo-deny
pkgs.cargo-cyclonedx
];
inputsFrom = [ transformer ];
RUST_SRC_PATH = "${pkgs.rust.packages.stable.rustPlatform.rustLibSrc}";
};
};
};
}