build(nix): pin flake inputs and verify the flake in CI

Two gaps in the packaging as submitted.

Inputs floated: `github:NixOS/nixpkgs/nixos-unstable` resolves to whatever
that branch points at today, so two people — or the same person a week
apart — could get different builds from identical source. A flake's whole
value is reproducibility. Normally `flake.lock` pins this; the tree has no
lock, and a contributor without Nix installed cannot generate one, so the
revisions are pinned in `inputs` directly instead. Same determinism,
no tooling required to keep it honest.

Nothing executed it: ai-memory has no other Nix coverage, so `flake.nix`
was source no job ran. It could break through a dependency bump, a
toolchain change, or a new build script and stay green forever, and the
first person to notice would be a NixOS user.

Adds a `nix` workflow that runs `nix build` and then executes
`./result/bin/ai-memory --version`, so a package that builds but cannot
run still fails. It is scoped to changes in flake.nix / Cargo.lock /
Cargo.toml / rust-toolchain.toml plus a weekly schedule and manual
dispatch, rather than every pull request: a full release build under Nix
costs more wall-clock than the rest of the matrix combined and almost no
PR can affect it.

Refs #405

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
AkitaOnRails
2026-08-19 13:04:31 -03:00
co-authored by Claude Opus 5
parent 3c92ed77c6
commit 100424bccd
3 changed files with 74 additions and 4 deletions
+14 -3
View File
@@ -22,11 +22,22 @@
{
description = "Long-term memory for AI coding agents";
# Inputs are pinned to explicit revisions rather than floating branches.
#
# A flake's value is reproducibility, and `github:NixOS/nixpkgs/nixos-unstable`
# resolves to whatever that branch points at today, so two people — or the
# same person a week apart — can get different builds from identical source.
# Normally `flake.lock` handles this; pinning here achieves the same
# determinism and keeps the tree honest for contributors who do not have
# Nix installed and so cannot regenerate a lock.
#
# To update: bump these revisions deliberately, in their own commit, and
# let the `nix` CI job prove the result still builds.
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
flake-utils.url = "github:numtide/flake-utils";
nixpkgs.url = "github:NixOS/nixpkgs/0ae2bc1419c3f345984c2629e72e7a631820fa4d";
flake-utils.url = "github:numtide/flake-utils/11707dc2f618dd54ca8739b309ec4fc024de578b";
rust-overlay = {
url = "github:oxalica/rust-overlay";
url = "github:oxalica/rust-overlay/99607a06c2ea1290cd3258c11d1416dde9201f94";
inputs.nixpkgs.follows = "nixpkgs";
};
};