Skip to content

Repository files navigation

trev's nix repository

check vulnerable nix user repository

Extra packages, bundlers, images and libs for nix

Packages

Packages are cached and kept up-to-date automatically. Available here or the Nix User Repository.

Version bumper for projects using git and semantic versioning

nix run github:spotdemo4/trevpkgs#bumper

Catppuccin theme for GTK

gtk = {
  enable = true;
  theme = {
    package = pkgs.trev.catppuccin-gtk.override {
      themeVariants = [ "sky" ];
      colorVariants = [ "dark" ];
    };
    name = "Catppuccin-Sky-Dark";
  };

  # https://raw.githubusercontent.com/nix-community/home-manager/f2d3e04e278422c7379e067e323734f3e8c585a7/modules/misc/news/2025/11/2025-11-26_11-55-28.nix
  gtk4.theme = config.gtk.theme;
};

Catppuccin theme for Zen Browser

Using with 0xc000022070/zen-browser-flake:

programs.zen-browser.profiles.default = {
  userChrome = builtins.readFile "${pkgs.trev.catppuccin-zen-browser}/Mocha/Sky/userChrome.css";
  userContent = builtins.readFile "${pkgs.trev.catppuccin-zen-browser}/Mocha/Sky/userContent.css";
};

Calculates video quality metrics with FFmpeg (SSIM, PSNR, VMAF, VIF)

nix run github:spotdemo4/trevpkgs#ffmpeg-quality-metrics

Flake package releaser

nix run github:spotdemo4/trevpkgs#flake-release

Bundles your Gleam-on-Erlang project into an escript

nix run github:spotdemo4/trevpkgs#gleescript

A tool to audit Erlang & Elixir dependencies

nix run github:spotdemo4/trevpkgs#go-over

Private, fast, and honest web browser

nix run github:spotdemo4/trevpkgs#helium

Intel graphics system firmware update library

nix run github:spotdemo4/trevpkgs#igsc

Provides convenient, on-demand access to serverless cloud compute from Python scripts on your local computer

buildInputs = with pkgs.python314Packages; [
  modal
];

Nix hash fixer

nix run github:spotdemo4/trevpkgs#fix-hash

Nix vulnerability scanner

nix run github:spotdemo4/trevpkgs#nix-scan

Prometheus exporter for nvtop

nix run github:spotdemo4/trevpkgs#nvtop-exporter

Static code analysis engine to find security issues in code

nix run github:spotdemo4/trevpkgs#opengrep

Protobuf plugin for generating OpenAPI specs matching the Connect RPC interface

nix run github:spotdemo4/trevpkgs#protoc-gen-connect-openapi

Scans your Python dependencies for known security vulnerabilities

nix run github:spotdemo4/trevpkgs#pysentry

QSV high-speed encoding performance experiment tool

nix run github:spotdemo4/trevpkgs#qsvenc

Cross-platform dependency update tool, with patches for nix

nix run github:spotdemo4/trevpkgs#renovate

Shell hook for nix development shells

Displays info about the environment and creates a pre-push hook that runs nix flake check

devShells.x86_64-linux.default = pkgs.mkShell {
  shellHook = pkgs.shellhook.ref;
};

Build backend for uv; latest version

build-system = with pkgs.python314Packages; [
  setuptools
  uv-build-latest
];

A feature-rich command-line audio/video downloader; unstable version

nix run github:spotdemo4/trevpkgs#yt-dlp

A protobuf 3 implementation for zig

nix run github:spotdemo4/trevpkgs#zig-protobuf

Images

Docker container images

nix (nixos/nix)

nix build github:spotdemo4/trevpkgs#images.x86_64-linux.nix &&
docker load -i result
nix build github:spotdemo4/trevpkgs#images.x86_64-linux.ffmpeg &&
docker load -i result

Bundlers

A collection of nix bundlers

image

A better alternative to github:NixOS/bundlers#toDockerImage that also sets org.opencontainers.image labels according to the packages meta attributes

nix bundle --bundler github:spotdemo4/trevpkgs#image

appimage

An alternative to ralismark/nix-appimage that uses bwrap to create compressed AppImages

nix bundle --bundler github:spotdemo4/trevpkgs#appimage

Libs

mkFlake

Utility function to simplify creating flakes.

outputs = { trev, ... }:
  trev.libs.mkFlake (
    system: pkgs: {
      packages.default = pkgs.rustPlatform.buildRustPackage (
        final: with pkgs.lib; {
          name = "rust-example";
          src = fileset.toSource {
            root = ./.;
            fileset = fileset.unions [
              ./Cargo.lock
              ./Cargo.toml
              (fileset.fileFilter (file: file.hasExt "rs") ./.)
            ];
          };
          cargoLock.lockFile = ./Cargo.lock;
        }
      );
    }
  );

To build rust-example into a statically linked binary:

nix build .#default.x86_64-unknown-linux-musl

To build rust-example into a different architecture:

nix build .#default.aarch64-unknown-linux-gnu

Linux builders also automatically attempt macOS cross-compilation using the Apple SDK packaged by nixpkgs:

nix build .#default.arm64-apple-darwin

Darwin cross-compilation is best-effort per package. Target binaries cannot run on the Linux builder, so builds and checks must inspect them without executing them. For target-specific package logic, use pkgs.stdenv.hostPlatform; the system callback argument remains the build system.

View all possible cross-compilation targets with:

nix flake show

mkImage

Creates a docker save-formatted image for a given src. Other attributes will be passed to dockerTools.buildLayeredImage

images.default = pkgs.mkImage {
  src = self.packages.${system}.default;
  contents = with pkgs; [ dockerTools.caCertificates ];
};
nix build .#images.x86_64-linux.default
docker load -i result

mkAppImage

Creates an AppImage for a given src. squashfsArgs can be used to modify the compression.

appimages.default = pkgs.mkAppImage {
  src = self.packages.${system}.default;
};
nix build .#appimages.x86_64-linux.default

mkChecks

Utility function to simplify creating flake checks. Can take an src pointing to a derivation, a root pointing to a directory, or neither for checks that do not need a source.

Directories can be filtered with files, filter, ignore and include. The order is: root/files -> filter applied -> ignore'd file(s) removed -> include file(s) added

filter's file attributes are inherited from fileset.fileFilter

checks = pkgs.lib.mkChecks {
  rust = {
    src = self.packages.${system}.default;
    packages = with pkgs; [
      rustfmt
      clippy
    ];
    script = ''
      cargo test --offline
      cargo fmt --check
      cargo clippy --offline -- -D warnings
    '';
  };

  tombi = {
    root = ./.;
    filter = file: file.hasExt "toml";
    packages = with pkgs; [
      tombi
    ];
    forEach = ''
      tombi format --offline --check "$file"
      tombi lint --offline --error-on-warnings "$file"
    '';
  };
};

mkApps

Utility function to simplify creating flake apps. Strings are shorthand for an app script. Structured entries accept script, optional packages, and optional inputsFrom. Like pkgs.mkShell, inputsFrom collects and flattens each derivation's buildInputs, nativeBuildInputs, propagatedBuildInputs, and propagatedNativeBuildInputs into the app's runtime PATH.

let
  devShell = pkgs.mkShell {
    packages = with pkgs; [
      go
      buf
    ];
  };
in
{
  devShells.default = devShell;

  apps = pkgs.mkApps {
    default = "go run .";
    configure = {
      inputsFrom = [ devShell ];
      script = "buf generate";
    };
  };
}
nix run
nix run .#configure

mkRustPackage

Wraps rustPlatform.buildRustPackage, building dependencies in a separate derivation (cargoArtifacts) from a stubbed copy of the workspace. Source changes and version bumps only rebuild the workspace crates. Dependencies are vendored from Cargo.lock, so cargoHash isn't needed. The check phase also runs in the dependency derivation, against the stubs, so the dependencies of custom check commands (e.g. cargo clippy) are built there too. cargoArtifactsArgs can be used to modify the dependency derivation, e.g. overriding checkPhase if it needs other source files.

pkgs.mkRustPackage (finalAttrs: {
  pname = "rust-pkg";
  version = "1.0.0";
  src = ./.;
});

mkGoModule

Wraps buildGoModule, building the vendored dependencies in a separate derivation (goCache) and restoring its build cache. Source changes and version bumps only rebuild the main module's packages. The dependency derivation only uses vendor/modules.txt and the vendor directory, which is named without the version, so it only changes when the dependencies do. vendorHash is required and proxyVendor isn't supported. goCacheArgs can be used to modify the dependency derivation.

Dependencies of tests are cached for the build directory used on Linux, on Darwin they're rebuilt in the check phase.

pkgs.mkGoModule (finalAttrs: {
  pname = "go-pkg";
  version = "1.0.0";
  src = ./.;
  vendorHash = "sha256-...";
});

bufFetchDeps & bufHook

Creates a fixed-output derivation for buf dependencies

pkgs.stdenv.mkDerivation (finalAttrs: {
  pname = "protobuf-pkg";
  version = "1.0.0";
  src = ./.;

  bufDeps = pkgs.bufFetchDeps {
    inherit (finalAttrs) pname version src;
    hash = "...";
  };

  nativeBuildInputs = with pkgs; [
    bufHook
  ];
});

gleamFetchDeps, gleamErlangHook & gleamJavascriptHook

  • Creates a fixed-output derivation for gleam dependencies
  • Builds with either erlang (gleamErlangHook) or Javascript (gleamJavascriptHook)
pkgs.stdenv.mkDerivation (finalAttrs: {
  pname = "gleam-pkg";
  version = "1.0.0";
  src = ./.;

  gleamDeps = pkgs.gleamFetchDeps {
    inherit (finalAttrs) pname version src;
    hash = "...";
  };

  nativeBuildInputs = with pkgs; [
    gleamErlangHook
  ];
});

Overlays

import nixpkgs {
  overlays = [
    trev.overlays.packages
    trev.overlays.images
    trev.overlays.libs
  ];
}

trev

An overlay that adds all of the overlays but with the prefix trev (e.g. pkgs.trev.bumper)

import nixpkgs {
  overlays = [ trev.overlays.trev ];
}

NixOS Modules

Overlay

Adds the trev overlay to the nixosSystem's pkgs

nixosConfigurations = {
  laptop = nixpkgs.lib.nixosSystem {
    modules = [
      trev.nixosModules.overlay
      ({ pkgs, ... }: {
        environment.systemPackages = with pkgs; [
          trev.bumper
        ];
      })
    ];
  };
};

Examples

Development flake

A flake for developing rust projects

{
  nixConfig = {
    extra-substituters = [
      "https://nix.trev.zip"
    ];
    extra-trusted-public-keys = [
      "trev:I39N/EsnHkvfmsbx8RUW+ia5dOzojTQNCTzKYij1chU="
    ];
  };

  inputs = {
    systems.url = "github:nix-systems/default";
    nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
    trevpkgs = {
      url = "github:spotdemo4/trevpkgs";
      inputs.systems.follows = "systems";
      inputs.nixpkgs.follows = "nixpkgs";
    };
  };

  outputs =
    {
      trevpkgs,
      ...
    }:
    trevpkgs.libs.mkFlake (
      system: pkgs: {

        # nix develop [#...]
        devShells = {
          default = pkgs.mkShell {
            shellHook = pkgs.shellhook.ref;
            packages = with pkgs; [
              rustc
              cargo
            ];
          };
        };

        # nix run [#...]
        apps = pkgs.mkApps {
          default = "cargo run";
          test = "cargo test";
        };

        # nix build [#...]
        packages = {
          default = pkgs.rustPlatform.buildRustPackage (
            final: with pkgs.lib; {
              pname = "rust-template";
              version = "0.4.8";

              src = fileset.toSource {
                root = ./.;
                fileset = fileset.unions [
                  ./Cargo.lock
                  ./Cargo.toml
                  (fileset.fileFilter (file: file.hasExt "rs") ./.)
                ];
              };
              cargoLock.lockFile = ./Cargo.lock;
            }
          );
        };

        # nix build #images.[...]
        images = {
          default = pkgs.mkImage {
            src = self.packages.${system}.default;
          };
        };

        # nix flake check
        checks = pkgs.mkChecks {
          rust = {
            src = self.packages.${system}.default;
            packages = with pkgs; [
              rustfmt
              clippy
            ];
            script = ''
              cargo test --offline
              cargo fmt --check
              cargo clippy --offline -- -D warnings
            '';
          };

          tombi = {
            root = ./.;
            filter = file: file.hasExt "toml";
            packages = with pkgs; [
              tombi
            ];
            forEach = ''
              tombi format --offline --check "$file"
              tombi lint --offline --error-on-warnings "$file"
            '';
          };
        };
      }
    );
}

Templates for various languages can be found at spotdemo4/templates

NixOS flake

A flake for NixOS utilizing the Nix User Repository

{
  nixConfig = {
    extra-substituters = [
      "https://nix.trev.zip"
    ];
    extra-trusted-public-keys = [
      "trev:I39N/EsnHkvfmsbx8RUW+ia5dOzojTQNCTzKYij1chU="
    ];
  };

  inputs = {
    nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
    nur = {
      url = "github:nix-community/NUR";
      inputs.nixpkgs.follows = "nixpkgs";
    };
  };

  outputs = { self, nixpkgs, nur }: {
    nixosConfigurations = {
      laptop = nixpkgs.lib.nixosSystem {
        modules = [
          nur.modules.nixos.default # Add the NUR overlay

          ({ pkgs, ... }: {
            environment.systemPackages = [pkgs.nur.repos.trev.bumper]; # Use the NUR overlay
          })
        ];
      };
    };
  };
}

Cache

Every package in this repo is built and cached each update. To pull from the cache instead of building:

Single flake

{
  nixConfig = {
    extra-substituters = [
      "https://nix.trev.zip"
    ];
    extra-trusted-public-keys = [
      "trev:I39N/EsnHkvfmsbx8RUW+ia5dOzojTQNCTzKYij1chU="
    ];
  };
}

Entire NixOS system

{
  nix.settings = {
    trusted-substituters = [
      "https://nix.trev.zip"
    ];
    trusted-public-keys = [
      "trev:I39N/EsnHkvfmsbx8RUW+ia5dOzojTQNCTzKYij1chU="
    ];
  };
}

About

extra packages, bundlers and libs for nix

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages