Two gaps in the packaging as submitted.
Inputs floated: `github:NixOS/nixpkgs/nixos-unstable` resolves to whatever
that branch points at today, so two people — or the same person a week
apart — could get different builds from identical source. A flake's whole
value is reproducibility. Normally `flake.lock` pins this; the tree has no
lock, and a contributor without Nix installed cannot generate one, so the
revisions are pinned in `inputs` directly instead. Same determinism,
no tooling required to keep it honest.
Nothing executed it: ai-memory has no other Nix coverage, so `flake.nix`
was source no job ran. It could break through a dependency bump, a
toolchain change, or a new build script and stay green forever, and the
first person to notice would be a NixOS user.
Adds a `nix` workflow that runs `nix build` and then executes
`./result/bin/ai-memory --version`, so a package that builds but cannot
run still fails. It is scoped to changes in flake.nix / Cargo.lock /
Cargo.toml / rust-toolchain.toml plus a weekly schedule and manual
dispatch, rather than every pull request: a full release build under Nix
costs more wall-clock than the rest of the matrix combined and almost no
PR can affect it.
Refs #405
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>