The pinned nixpkgs cannot evaluate prettier: its closure carries
pnpm-9.15.9, which is marked insecure for seven CVEs, and the refusal
happens at evaluation. That breaks nix fmt and the formatting flake check
for every language at once, not just prettier's, which is what blocks
wiring prettier into treefmt.
Measured against both pins, prettier.outPath only:
569d5785 refused, suggesting permittedInsecurePackages
5dfba623 /nix/store/7ryzvaaks7m71lilhzalcbay57nqqm78-prettier-3.8.3
Prettier is 3.8.3 on both. What moved is the pnpm in its closure, not the
version.
Landed on its own so a two-month pin bump gets its own CI run and its own
bisect point, separate from the treefmt change that needs it.
Drops the hardcoded `nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"`
from the meta flake renderer. meta now declares:
nixpkgs.follows = "hyperhive/nixpkgs";
nixpkgs-unstable.follows = "hyperhive/nixpkgs-unstable";
so every agent-level `inputs.<X>.inputs.nixpkgs.follows = "nixpkgs"`
resolves transitively to hyperhive's own pin. One channel decision
in the whole tree (hyperhive/flake.nix line 5), no second source
to drift.
`closes #317` invariant still holds: `nixpkgs` is a single canonical
name in the meta tree, it just resolves through hyperhive instead
of being its own root input.
Also:
- bump hyperhive/flake.nix line 5: `nixos-25.11` → `nixos-26.05`,
flake.lock relocked
- flake_check.rs fixtures bumped cosmetically (synthetic data, not
shape-affecting)
- rename + rewrite `render_flake_declares_canonical_nixpkgs` →
`render_flake_aliases_nixpkgs_to_hyperhive`; asserts the new
follows-form AND the absence of any literal `nixpkgs.url`
- drop the now-redundant `render_flake_collapses_hyperhive_nixpkgs_via_follows`
test (the old indirection it covered no longer exists)
Closes#526.
Framework swap, no public API change.
- naersk input → crane (`github:ipetkov/crane`); crane is stateless, no
nixpkgs.follows needed.
- `forAllSystems` exposes `craneLib = crane.mkLib pkgs`,
`cargoArtifacts = craneLib.buildDepsOnly` (built once, reused), and
a shared `nativeBuildInputs = [ pkgs.librsvg pkgs.git ]` consumed by
buildDepsOnly + buildPackage + cargoClippy so the three derivations
see the same toolchain shape.
- `packages.default = craneLib.buildPackage` (was naersk-lib.buildPackage)
with explicit `pname = "hyperhive-workspace"; version = "0.1.0";` —
the virtual workspace Cargo.toml has no [package].name so crane
needs the hint.
- `checks.clippy = craneLib.cargoClippy` (was naersk + overrideAttrs
hack). Crane parses `cargoClippyExtraArgs = "--workspace --all-targets
-- -D warnings"` correctly; naersk's `mode = "clippy"` used to mangle
the `--` separator which is why the old wiring went through
overrideAttrs. The whole hack — including `doCheck = false`,
`copyTarget = false`, and the swapped buildPhase/installPhase — is
now gone.
- librsvg native dep (#424) preserved on all three derivations. Added
pkgs.git too — naersk auto-included it; crane is more minimal, so
hive-c0re's `lifecycle::tests::setup_proposed_*` (which shell out to
`git init`+commit) need it explicit to pass under `cargo test` in
the sandbox.
- build.rs + hive-c0re/Cargo.toml comments updated from "naersk
derivation" to "crane derivation".
- 3 doc-list-indentation lints in hive-sh4re/src/lib.rs cleaned up
(replaced `+`-at-line-start with `and`/`/` so doc continuations
don't trigger `clippy::doc_lazy_continuation`).
Validated locally: `nix build .#default --fallback` succeeds, all
117 tests pass, all four bins in `result/bin/`.