Packages and dependency hashes
A Package belongs to a Source and is declared in packages. It shares the Pin's Version and the Source's code, but has its own Builder and dependency artifacts. nix-pins computes hashes for intermediate dependency fixed-output derivations (FODs); downstream projects still handle the full application build.
A Go Package
{ pin }: {
gofzf = pin.github {
target = "junegunn/fzf";
packages.default = pin.goModule { root = "."; };
};
}
With config passed to the Reader, the Package is available at pins.gofzf.sources.default.packages.default. Read vendorHash or goModules and reuse the corresponding source and version in your downstream buildGoModule.
npm and pnpm
pin.npmPackage uses npmDeps from buildNpmPackage to compute npmDepsHash. The upstream project must provide a usable package-lock.json.
pin.pnpmPackage uses fetchPnpmDeps to compute pnpmDepsHash. Explicitly provide root and a positive integer fetcherVersion. Configure downstream dependency installation with the same pnpm and Node.js versions.
{ pin, pkgs }: {
app = pin.github {
target = "QuantumNous/new-api";
packages.web = pin.pnpmPackage {
root = "web";
fetcherVersion = 3;
pnpm = pkgs.pnpm;
};
};
}
This configuration demonstrates a subdirectory declaration. That directory in the selected upstream version must contain a compatible pnpm-lock.yaml. The tool does not create or repair upstream lockfiles. See Package Builders for further restrictions and downstream usage.
Multiple Packages
Declare different names under a Source's packages. If a Source has only one Package of a given type, its Derived Hash uses vendorHash, npmDepsHash, or pnpmDepsHash. Multiple Packages of the same type add a Package name prefix, such as cli.vendorHash.
Downstream consumers should access artifacts through the Reader's named packages instead of inferring derived keys. The tool decides whether to recompute a hash from the input fingerprint of the intermediate dependency derivation. Reuse depends on the actual build inputs.