-20
ci/README.md
-20
ci/README.md
···- `REPOSITORY`: The repository from which to fetch the base branch. Defaults to <https://github.com/NixOS/nixpkgs.git>.-This directory contains scripts and files used and related to [`nixpkgs-vet`](https://github.com/NixOS/nixpkgs-vet/), which the CI uses to implement `pkgs/by-name` checks, along with many other Nixpkgs architecture rules.-Updates the pinned [`nixpkgs-vet` tool](https://github.com/NixOS/nixpkgs-vet) in [`ci/nixpkgs-vet/pinned-version.txt`](./nixpkgs-vet/pinned-version.txt) to the latest [release](https://github.com/NixOS/nixpkgs-vet/releases).-- Because it makes the CI check very fast, since no Nix builds need to be done, even for mass rebuilds.-- Because it improves security, since we don't have to build potentially untrusted code from PRs.-The tool only needs a very minimal Nix evaluation at runtime, which can work with [readonly-mode](https://nixos.org/manual/nix/stable/command-ref/opt-common.html#opt-readonly-mode) and [restrict-eval](https://nixos.org/manual/nix/stable/command-ref/conf-file.html#conf-restrict-eval).
-3
ci/nixpkgs-vet.sh
-3
ci/nixpkgs-vet.sh
···
-1
ci/nixpkgs-vet/pinned-version.txt
-1
ci/nixpkgs-vet/pinned-version.txt
···
-22
ci/nixpkgs-vet/update-pinned-tool.sh
-22
ci/nixpkgs-vet/update-pinned-tool.sh
···