mirror of
https://github.com/DeterminateSystems/flake-checker.git
synced 2024-10-27 15:40:44 +03:00
Add text around upstream Nixpkgs
This commit is contained in:
parent
afdb2f92b4
commit
d20c110779
@ -1 +1,3 @@
|
||||
Say more here later.
|
||||
We don't recommend using forked or re-exported versions of Nixpkgs.
|
||||
While this may be convenient in some cases, it can introduce unexpected behaviors and unwanted security risks.
|
||||
While <a href="https://github.com/NixOS/nixpkgs">upstream Nixpkgs</a> isn't bulletproof—nothing in software is!—it has a wide range of security measures in place, most notably continuous integration testing with <a href="https://hydra.nixos.org/">Hydra</a>, that mitigate a great deal of supply chain risk.
|
||||
|
@ -77,6 +77,8 @@ Here's an example:
|
||||
inputs.nixpkgs.url = "github:NixOS/nixpkgs";
|
||||
}
|
||||
```
|
||||
|
||||
If you need a customized version of Nixpkgs, we recommend using methods like [overlays] and per-package [overrides].
|
||||
</details>
|
||||
|
||||
<details>
|
||||
@ -87,3 +89,5 @@ Here's an example:
|
||||
|
||||
[flake-lock-action]: https://github.com/determinateSystems/update-flake-lock
|
||||
[nixos]: https://github.com/nixos
|
||||
[overlays]: https://nixos.wiki/wiki/Overlays
|
||||
[overrides]: https://ryantm.github.io/nixpkgs/using/overrides
|
||||
|
Loading…
Reference in New Issue
Block a user