Nix packages for third-party projects that don't ship their own flakes
README.md

agentic #

Nix packages for third-party tools that don't ship their own flakes.

Layout #

flake.nix              # flake entrypoint: exposes packages.* and apps.*
flake.lock
packages/
  vit/                 # one directory per package (callPackage style)
    default.nix
    package-lock.json  # only when we need a fixed/regenerated lock
    upstream.json      # how CI discovers and bumps this package
scripts/
  update-packages.sh   # version bump + hash/lock refresh
.github/workflows/
  update-packages.yml  # weekly cron + manual dispatch

Add a new package by creating packages/<name>/default.nix and wiring it in flake.nix via pkgs.callPackage ./packages/<name> { }. For automated updates, also add packages/<name>/upstream.json (see below).

Packages #

Attr Upstream Install (non-Nix)
vit solpbc/vit npm install -g vit
rook solpbc/rook npm install -g @solpbc/rook
spinel matz/spinel build from source (make deps && make && make install)
boxd boxd.sh / docs curl -fsSL https://boxd.sh/downloads/install.sh | sh
whetuu yamafaktory/whetuu install script / release tarballs
pullrun pullrun/pullrun curl -fsSL https://github.com/pullrun/pullrun/raw/main/install.sh | bash
gleam-preview gleam-lang/gleam (prereleases) install docs / release tarballs
zed-preview zed-industries/zed (preview channel) official Linux installer / zed-linux-x86_64.tar.gz
halloy squidowl/halloy GitHub releases / halloy-*-x86_64-linux.tar.gz
pulp cheywood/Pulp Flathub
mimic ArijanJ/Mimic Flathub
portfolio tchx84/Portfolio Flathub
eyg CrowdHailer/eyg-lang curl -fsSL https://eyg.run/install | bash
lore EpicGames/lore install script / release tarballs
loreserver EpicGames/lore install script (--server / --demo) / release tarballs

Usage #

# build
nix build .#vit
nix build .#rook
nix build .#spinel
nix build .#boxd          # x86_64-linux / aarch64-linux / aarch64-darwin
nix build .#whetuu        # linux + darwin (all four systems)
nix build .#pullrun       # linux + darwin (all four systems)
nix build .#gleam-preview # linux + darwin (all four systems)
nix build .#zed-preview   # x86_64-linux only
nix build .#halloy        # x86_64-linux only
nix build .#pulp          # linux only (GNOME/GTK4)
nix build .#mimic         # linux only (GTK4/libadwaita)
nix build .#portfolio     # linux only (GTK4/libadwaita file manager)
nix build .#eyg           # linux + darwin (all four systems)
nix build .#lore          # x86_64-linux / aarch64-linux / aarch64-darwin
nix build .#loreserver    # same platforms as lore

# run without installing
nix run .#vit -- --help
nix run .#rook -- --help
nix run .#spinel -- --help
nix run .#spin -- new myapp   # spin project tool (from the spinel package)
nix run .#boxd -- --help
nix run .#whetuu -- --version
nix run .#pullrun -- --version
nix run .#gleam-preview -- --version
nix run .#zed-preview -- --version
nix run .#halloy -- --version
nix run .#pulp
nix run .#mimic
nix run .#portfolio
nix run .#eyg -- --version
nix run .#eyg -- eval -c '!int_add(1, 1)'
nix run .#lore -- --version
nix run .#loreserver -- --version

# install into your profile
nix profile install .#vit
nix profile install .#rook
nix profile install .#spinel
nix profile install .#boxd
nix profile install .#whetuu
nix profile install .#pullrun
nix profile install .#gleam-preview
nix profile install .#zed-preview
nix profile install .#halloy
nix profile install .#pulp
nix profile install .#mimic
nix profile install .#portfolio
nix profile install .#eyg
nix profile install .#lore
nix profile install .#loreserver

Updating packages #

A GitHub Action runs every Monday (and on manual dispatch) to:

  1. Read each packages/*/upstream.json
  2. Compare the packaged version to the latest upstream tag
  3. Refresh source hashes, regenerate lockfiles when needed, recompute npmDepsHash
  4. Verify nix build .#<pkg>
  5. Open a PR on branch chore/update-packages if anything changed
# preferred: flake app (wraps scripts/update-packages.sh; run from this checkout)
nix run .#update -- --check   # dry-run: exit 1 if any package is behind
nix run .#update              # bump all packages from upstream
nix run .#update -- vit       # one package

# same script directly
./scripts/update-packages.sh --check
./scripts/update-packages.sh
./scripts/update-packages.sh vit

upstream.json #

Supported types:

npm-github — tagged npm projects:

{
  "type": "npm-github",
  "github": "owner/repo",
  "tag_prefix": "v"
}

npm-github packages are expected to use buildNpmPackage + fetchFromGitHub with a version field and optional vendored package-lock.json.

gitlab-tag — tagged source packages on GitLab (including GNOME GitLab):

{
  "type": "gitlab-tag",
  "domain": "gitlab.gnome.org",
  "gitlab": "owner/repo",
  "tag_prefix": ""
}

Tracks the newest tag matching {tag_prefix} + numeric version (CalVer like 2026.4 or semver). Refreshes version and the fetchFromGitLab hash. Used by pulp.

github-tag — tagged source packages on GitHub (no npm lockfile):

{
  "type": "github-tag",
  "github": "owner/repo",
  "tag_prefix": "v"
}

Tracks the newest tag matching {tag_prefix} + semver. Refreshes version and the fetchFromGitHub hash. Used by mimic.

github-unstable — projects without release tags (track branch tip):

{
  "type": "github-unstable",
  "github": "owner/repo",
  "branch": "master"
}

Versions are 0-unstable-YYYY-MM-DD with a pinned rev in fetchFromGitHub. For spinel, the updater also re-reads PRISM_VERSION / RBS_VERSION from the upstream Makefile and refreshes the vendored gem hashes when they change.

github-release-binary — prebuilt release assets (no source build):

Single-asset:

{
  "type": "github-release-binary",
  "github": "owner/repo",
  "tag_prefix": "v",
  "tag_suffix": "-pre",
  "asset": "zed-linux-x86_64.tar.gz"
}

Multi-platform (sources = { … } block, like url-manifest-binary):

{
  "type": "github-release-binary",
  "github": "owner/repo",
  "tag_prefix": "v",
  "platforms": {
    "x86_64-linux": "tool-v{version}-x86_64-linux-musl.tar.gz",
    "aarch64-linux": "tool-v{version}-aarch64-linux-musl.tar.gz",
    "x86_64-darwin": "tool-v{version}-x86_64-macos.tar.gz",
    "aarch64-darwin": "tool-v{version}-aarch64-macos.tar.gz"
  }
}

Tracks the newest non-draft GitHub release whose tag matches {tag_prefix}{version}{tag_suffix} (semver or CalVer with 2+ numeric components). Set "tag_prefix": "" for unprefixed tags (e.g. Halloy 2026.8). Set "tag_prerelease": true to match any prerelease tag (vX.Y.Z-rc1, vX.Y.Z-beta, …) instead of a fixed suffix. Single-asset mode refreshes one fetchurl hash; multi-platform mode rewrites every sources.<system>.{url,hash}. {version} in asset names is the bare version (no tag prefix). Used by zed-preview (single), whetuu / gleam-preview / pullrun / halloy (multi; halloy is x86_64-linux only).

url-manifest-binary — prebuilt multi-platform binaries via a version manifest URL (not GitHub releases):

{
  "type": "url-manifest-binary",
  "manifest_url": "https://boxd.sh/downloads/cli/latest-{platform}.json",
  "platforms": {
    "x86_64-linux": "linux-amd64",
    "aarch64-linux": "linux-arm64",
    "aarch64-darwin": "darwin-arm64"
  }
}

{platform} is replaced per entry in platforms. Each manifest must expose version + url; the updater prefetches every platform hash and rewrites the sources = { … } block in default.nix. Used by boxd.

Manual steps (vit / rook) #

If you prefer to bump by hand (same flow for either npm-github package):

  1. Bump version in packages/<name>/default.nix.
  2. Prefetch the new source hash:
    nix-prefetch-url --unpack "https://github.com/solpbc/<name>/archive/refs/tags/vX.Y.Z.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. Regenerate a lockfile with resolved URLs when needed:
    tmp=$(mktemp -d) && cd "$tmp"
    curl -sL "https://github.com/solpbc/<name>/archive/refs/tags/vX.Y.Z.tar.gz" | tar -xz
    cd <name>-X.Y.Z
    rm -f package-lock.json bun.lock
    npm install --package-lock-only --ignore-scripts
    cp package-lock.json /path/to/this/repo/packages/<name>/package-lock.json
    
  4. Set npmDepsHash to the all-zero fake hash, run nix build .#<name>, paste the hash nix prints as got:, rebuild.

Or just run ./scripts/update-packages.sh vit / ./scripts/update-packages.sh rook.

Manual steps (spinel) #

Spinel has no release tags yet, so the package pins a git commit as 0-unstable-YYYY-MM-DD. Prefer the updater:

./scripts/update-packages.sh spinel

By hand:

  1. Bump version, rev, and the fetchFromGitHub hash in packages/spinel/default.nix.
  2. If upstream changed PRISM_VERSION / RBS_VERSION in its Makefile, update prismVersion / rbsVersion and re-hash the gems:
    nix-prefetch-url "https://rubygems.org/gems/prism-X.Y.Z.gem"
    nix-prefetch-url "https://rubygems.org/gems/rbs-X.Y.Z.gem"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. nix build .#spinel and smoke-test ./result/bin/spinel -e 'puts 1'.

Manual steps (zed-preview) #

zed-preview ships official Linux x86_64 preview binaries (tags vX.Y.Z-pre). Prefer the updater:

./scripts/update-packages.sh zed-preview

By hand:

  1. Bump version in packages/zed-preview/default.nix (e.g. 1.12.0-pre).
  2. Prefetch the tarball hash:
    nix-prefetch-url "https://github.com/zed-industries/zed/releases/download/vX.Y.Z-pre/zed-linux-x86_64.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. Paste the SRI hash into fetchurl.hash, then nix build .#zed-preview and smoke-test ./result/bin/zed-preview --version.

Manual steps (boxd) #

boxd ships official static CLI binaries from boxd.sh (see quickstart). Prefer the updater:

./scripts/update-packages.sh boxd

By hand:

  1. Read the manifests and note the shared version:
    curl -fsSL https://boxd.sh/downloads/cli/latest-linux-amd64.json
    curl -fsSL https://boxd.sh/downloads/cli/latest-linux-arm64.json
    curl -fsSL https://boxd.sh/downloads/cli/latest-darwin-arm64.json
    
  2. Bump version in packages/boxd/default.nix.
  3. Prefetch each platform binary hash into the matching sources.<system>.hash:
    nix-prefetch-url "https://boxd.sh/downloads/cli/boxd-linux-amd64"
    nix-prefetch-url "https://boxd.sh/downloads/cli/boxd-linux-arm64"
    nix-prefetch-url "https://boxd.sh/downloads/cli/boxd-darwin-arm64"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  4. nix build .#boxd and smoke-test ./result/bin/boxd --version.

Manual steps (whetuu) #

whetuu ships official multi-platform release tarballs (static musl on Linux). Prefer the updater:

./scripts/update-packages.sh whetuu

By hand:

  1. Bump version in packages/whetuu/default.nix (e.g. 0.1.5).
  2. Update each sources.<system>.url to the matching release asset and prefetch:
    nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-x86_64-linux-musl.tar.gz"
    nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-aarch64-linux-musl.tar.gz"
    nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-x86_64-macos.tar.gz"
    nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-aarch64-macos.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. nix build .#whetuu and smoke-test ./result/bin/whetuu --version.

Manual steps (pullrun) #

pullrun ships official multi-platform release tarballs (CLI + runtime, static). Prefer the updater:

./scripts/update-packages.sh pullrun

By hand:

  1. Bump version in packages/pullrun/default.nix (e.g. 0.6.7).
  2. Update each sources.<system>.url to the matching release asset and prefetch:
    nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-linux-amd64.tar.gz"
    nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-linux-arm64.tar.gz"
    nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-darwin-amd64.tar.gz"
    nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-darwin-arm64.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. nix build .#pullrun and smoke-test ./result/bin/pullrun --version and ./result/bin/pullrun-runtime --version.

Manual steps (gleam-preview) #

gleam-preview ships official multi-platform prerelease binaries (tags vX.Y.Z-rcN, etc.). The binary is installed as gleam-preview so it can coexist with nixpkgs gleam. Prefer the updater:

./scripts/update-packages.sh gleam-preview

By hand:

  1. Bump version in packages/gleam-preview/default.nix (e.g. 1.18.0-rc1).
  2. Update each sources.<system>.url to the matching release asset and prefetch:
    nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-x86_64-unknown-linux-musl.tar.gz"
    nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-aarch64-unknown-linux-musl.tar.gz"
    nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-x86_64-apple-darwin.tar.gz"
    nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-aarch64-apple-darwin.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. nix build .#gleam-preview and smoke-test ./result/bin/gleam-preview --version.

Manual steps (halloy) #

halloy ships an official Linux x86_64 release tarball (IRC client). Prefer the updater:

./scripts/update-packages.sh halloy

By hand:

  1. Bump version in packages/halloy/default.nix (e.g. 2026.8).
  2. Update sources.x86_64-linux.url and prefetch:
    nix-prefetch-url "https://github.com/squidowl/halloy/releases/download/X.Y/halloy-X.Y-x86_64-linux.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. nix build .#halloy and smoke-test ./result/bin/halloy --version.

Manual steps (pulp) #

pulp is a GNOME RSS reader built from source (Meson + Python + GTK4). Prefer the updater:

./scripts/update-packages.sh pulp

By hand:

  1. Bump version in packages/pulp/default.nix (e.g. 2026.4).
  2. Prefetch the source hash:
    nix-prefetch-url --unpack "https://gitlab.gnome.org/cheywood/Pulp/-/archive/X.Y/Pulp-X.Y.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. Paste the SRI hash into fetchFromGitLab.hash, then nix build .#pulp.

Manual steps (portfolio) #

portfolio is a minimalist GTK4 file manager built from source (Meson + Python). Prefer the updater:

./scripts/update-packages.sh portfolio

By hand:

  1. Bump version in packages/portfolio/default.nix (e.g. 1.0.3).
  2. Prefetch the source hash:
    nix-prefetch-url --unpack "https://github.com/tchx84/Portfolio/archive/refs/tags/vX.Y.Z.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. Paste the SRI hash into fetchFromGitHub.hash, then nix build .#portfolio.

Manual steps (lore / loreserver) #

lore and loreserver ship separate multi-platform release tarballs (dynamic glibc on Linux; no darwin-x86_64; aarch64-linux is Neoverse/Graviton only). Prefer the updater:

./scripts/update-packages.sh lore
./scripts/update-packages.sh loreserver

By hand:

  1. Bump version in packages/lore/default.nix and packages/loreserver/default.nix (e.g. 0.8.5).
  2. Update each sources.<system>.url to the matching release asset and prefetch:
    # lore CLI
    nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/lore-vX.Y.Z-x86_64-unknown-linux-gnu.tar.gz"
    nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/lore-vX.Y.Z-aarch64-unknown-linux-gnu-neoverse-512tvb.tar.gz"
    nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/lore-vX.Y.Z-aarch64-apple-darwin.tar.gz"
    # loreserver
    nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/loreserver-vX.Y.Z-x86_64-unknown-linux-gnu.tar.gz"
    nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/loreserver-vX.Y.Z-aarch64-unknown-linux-gnu-neoverse-512tvb.tar.gz"
    nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/loreserver-vX.Y.Z-aarch64-apple-darwin.tar.gz"
    nix hash convert --hash-algo sha256 --to sri <base32>
    
  3. nix build .#lore / nix build .#loreserver and smoke-test ./result/bin/lore --version / ./result/bin/loreserver --version.