一键导入
add-package
Add a new package derivation to this NUR repository.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Add a new package derivation to this NUR repository.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | add-package |
| description | Add a new package derivation to this NUR repository. |
The user will provide a GitHub URL (or package name). Follow the steps below based on the package type.
Fetch the GitHub repo page to determine:
v1.0.0 vs V1.0.0)go.mod, Cargo.toml, or release assets)Create pkgs/<name>/default.nix following the appropriate template below.
Then wire it up in default.nix:
<name> = pkgs.callPackage ./pkgs/<name> {};
Use stdenvNoCC.mkDerivation with fetchurl per platform. Follow pkgs/opencode/default.nix exactly as the template:
finalAttrs patternpassthru.sources keyed by Nix system strings (aarch64-darwin, x86_64-linux, etc.)nix-prefetch-url for each platform URLplatforms = builtins.attrNames finalAttrs.passthru.sourcesUse buildGoModule. Follow pkgs/git-sync/default.nix as the template:
{
lib,
buildGoModule,
fetchFromGitHub,
}:
buildGoModule rec {
pname = "<name>";
version = "<version>";
src = fetchFromGitHub {
owner = "<owner>";
repo = "<repo>";
rev = "v${version}"; # adjust prefix if the tag uses a capital V or no prefix
hash = "<sri-hash>";
};
vendorHash = "sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=";
passthru.updateScript = ./update.sh;
meta = {
description = "...";
homepage = "https://github.com/<owner>/<repo>";
changelog = "https://github.com/<owner>/<repo>/releases/tag/v${version}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [];
mainProgram = "<binary-name>";
};
}
go.mod requires a Go version not provided by the default toolchain, add:
{ ..., go_1_XX }: (buildGoModule.override { go = go_1_XX; }) rec { ... }
Check available versions with nix eval 'nixpkgs#go_1_XX.version'.doCheck = false.postInstall to set up $out/share/<name>/ with the full tree and write real wrapper scripts in $out/bin/ using printf — not symlinks — so BASH_SOURCE[0] resolves correctly.Use rustPlatform.buildRustPackage. Follow pkgs/tredis/default.nix as the template:
{
lib,
rustPlatform,
fetchFromGitHub,
}:
rustPlatform.buildRustPackage rec {
pname = "<name>";
version = "<version>";
src = fetchFromGitHub {
owner = "<owner>";
repo = "<repo>";
rev = "v${version}";
hash = "<sri-hash>";
};
cargoHash = "sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=";
passthru.updateScript = ./update.sh;
meta = {
description = "...";
homepage = "https://github.com/<owner>/<repo>";
changelog = "https://github.com/<owner>/<repo>/releases/tag/v${version}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [];
mainProgram = "<binary-name>";
};
}
Cargo.lock uses version 4 and the build fails with "requires -Znext-lockfile-bump", the flake's nixpkgs pin is too old — run nix flake update.useFetchCargoVendor = true; it is the default in nixpkgs 25.05+.buildNpmPackage or mkYarnPackagepython3Packages.buildPythonApplication with pyproject = true for modern packagesstdenv.mkDerivation with zigBuildHookFetch the source hash:
nix-prefetch-url --unpack "https://github.com/<owner>/<repo>/archive/refs/tags/v<version>.tar.gz" 2>/dev/null \
| xargs -I{} nix hash convert --hash-algo sha256 --to sri {}
For the dependency hash (vendorHash / cargoHash), use the fake placeholder first, then build to get the real value from the error output:
nix build .#<name>
# error will print: got: sha256-<real-hash>
Substitute the real hash into default.nix.
Create pkgs/<name>/update.sh (executable) following the pattern of pkgs/tredis/update.sh (Rust) or pkgs/go-qo/update.sh (Go):
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p curl jq nix
set -euo pipefail
SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" &>/dev/null && pwd)
DEFAULT_NIX_FILE="$SCRIPT_DIR/default.nix"
NUR_ROOT=$(cd -- "$SCRIPT_DIR/../.." && pwd)
latest_version=$(curl --silent --fail \
"https://api.github.com/repos/<owner>/<repo>/releases/latest" \
| jq -r .tag_name | sed 's/^v//') # adjust prefix stripping to match the tag format
current_version=$(grep 'version = "' "$DEFAULT_NIX_FILE" | head -n1 | cut -d '"' -f 2)
if [[ "$latest_version" == "$current_version" ]]; then
echo "<name> is already up-to-date at version $latest_version"
exit 0
fi
echo "Updating <name> from $current_version to $latest_version"
sed -i -E "s/^( *version = \").*(\";)/\1$latest_version\2/" "$DEFAULT_NIX_FILE"
hash_base64=$(nix-prefetch-url --unpack --type sha256 \
"https://github.com/<owner>/<repo>/archive/refs/tags/v${latest_version}.tar.gz" 2>/dev/null)
src_hash=$(nix hash convert --hash-algo sha256 --to sri "$hash_base64")
sed -i -E "s|( *hash = \").*(\";)|\1${src_hash}\2|" "$DEFAULT_NIX_FILE"
# Replace with the appropriate hash field name:
# cargoHash for Rust, vendorHash for Go
sed -i -E 's|( *cargoHash = \").*(\";)|\1sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=\2|' "$DEFAULT_NIX_FILE"
dep_hash=$(nix build "${NUR_ROOT}#<name>" 2>&1 | grep "got:" | awk '{print $NF}' || true)
if [[ -z "$dep_hash" ]]; then
echo "Failed to determine dependency hash" >&2
exit 1
fi
sed -i -E "s|( *cargoHash = \").*(\";)|\1${dep_hash}\2|" "$DEFAULT_NIX_FILE"
echo "Successfully updated <name> to version $latest_version"
For pre-built binaries, the update script should update the version and re-fetch each platform URL hash individually (see pkgs/opencode/update.sh).
pkgs/<name>/default.nix created with correct hashesdefault.nixnix build .#<name> succeedspkgs/<name>/update.sh created and executable (chmod +x)passthru.updateScript = ./update.sh set in default.nix