Reference

Package Builders

Dependency hashes for Go Modules, npm, and pnpm, and how to use them downstream.

Use these constructors in a Source's packages. The current public Builders are pin.goModule, pin.npmPackage, and pin.pnpmPackage. There is no Cargo Builder; the crates.io Checker only checks versions.

Fields and artifacts

ConstructorRequired fieldsDerived HashDependency artifact
pin.goModulerootvendorHashgoModules
pin.npmPackagerootnpmDepsHashnpmDeps
pin.pnpmPackageroot, positive integer fetcherVersionpnpmDepsHashpnpmDeps

root is the dependency directory relative to the Source root. Set root = "." explicitly even for the root directory. Other arguments are forwarded to the corresponding Nixpkgs Builder. The tool injects the locked src, version, and dependency hash.

Go Modules

{ pin }: {
  fzf = pin.github {
    target = "junegunn/fzf";
    packages.default = pin.goModule { root = "."; };
  };
}

Uses pkgs.buildGoModule, mapping root to modRoot. The hash covers goModules, not the final application.

npm

{ pin }: {
  cpa = pin.github {
    target = "seakee/CPA-Manager-Plus";
    packages.web = pin.npmPackage { root = "."; };
  };
}

Uses pkgs.buildNpmPackage, mapping root to npmRoot and prefetching npmDeps. The upstream project needs matching package.json and package-lock.json files. The tool does not generate upstream lockfiles.

pnpm

{ pin, pkgs }: {
  app = pin.github {
    target = "QuantumNous/new-api";
    packages.web = pin.pnpmPackage {
      root = "web";
      fetcherVersion = 3;
      pnpm = pkgs.pnpm;
    };
  };
}

Uses pkgs.fetchPnpmDeps. fetcherVersion is the implementation version of the Nixpkgs dependency Fetcher, not the pnpm major version. Choose a value supported by your Nixpkgs. pnpm defaults to the supplied pkgs.pnpm; override it explicitly to use another major version.

This example demonstrates subdirectory configuration. The locked upstream version must provide a compatible pnpm-lock.yaml. root must be a nonempty string. The entire declared workspace is locked: nonempty pnpmWorkspaces and --filter, --filter-prod, or -F filters in pnpmInstallFlags are not accepted.

Downstream usage

Pass both the Pins File and configuration to the Reader to access named Packages. A downstream pnpm example:

let
  pkgs = import <nixpkgs> {};
  pins = import ../nix/pins.nix {
    inherit pkgs;
    file = ./pins.json;
    config = ./pins-config.nix;
  };
  source = pins.app.sources.default;
in
pkgs.stdenv.mkDerivation {
  pname = "app-web";
  version = pins.app.version;
  src = source.src;
  pnpmDeps = source.packages.web.pnpmDeps;
  pnpmRoot = "web";
  nativeBuildInputs = [ pkgs.nodejs pkgs.pnpm pkgs.pnpmConfigHook ];
  buildPhase = "pnpm run build";
  installPhase = ''
    mkdir -p $out
    cp -r web/dist/. $out/
  '';
}

Adjust application scripts, output directories, and installation steps for your project. Dependency prefetching and downstream installation should use the same pnpm package, Node.js, and root directory. The relative Reader path above follows the quick-start directory layout; other projects should use their own pinned Reader path.