agentic #
Nix packages for third-party tools that don't ship their own flakes.
Layout #
flake.nix # flake entrypoint: exposes packages.* and apps.*
flake.lock
packages/
vit/ # one directory per package (callPackage style)
default.nix
package-lock.json # only when we need a fixed/regenerated lock
upstream.json # how CI discovers and bumps this package
scripts/
update-packages.sh # version bump + hash/lock refresh
.github/workflows/
update-packages.yml # weekly cron + manual dispatch
Add a new package by creating packages/<name>/default.nix and wiring it in
flake.nix via pkgs.callPackage ./packages/<name> { }. For automated
updates, also add packages/<name>/upstream.json (see below).
Packages #
| Attr | Upstream | Install (non-Nix) |
|---|---|---|
vit |
solpbc/vit | npm install -g vit |
rook |
solpbc/rook | npm install -g @solpbc/rook |
spinel |
matz/spinel | build from source (make deps && make && make install) |
boxd |
boxd.sh / docs | curl -fsSL https://boxd.sh/downloads/install.sh | sh |
whetuu |
yamafaktory/whetuu | install script / release tarballs |
pullrun |
pullrun/pullrun | curl -fsSL https://github.com/pullrun/pullrun/raw/main/install.sh | bash |
gleam-preview |
gleam-lang/gleam (prereleases) | install docs / release tarballs |
zed-preview |
zed-industries/zed (preview channel) | official Linux installer / zed-linux-x86_64.tar.gz |
halloy |
squidowl/halloy | GitHub releases / halloy-*-x86_64-linux.tar.gz |
pulp |
cheywood/Pulp | Flathub |
mimic |
ArijanJ/Mimic | Flathub |
portfolio |
tchx84/Portfolio | Flathub |
eyg |
CrowdHailer/eyg-lang | curl -fsSL https://eyg.run/install | bash |
lore |
EpicGames/lore | install script / release tarballs |
loreserver |
EpicGames/lore | install script (--server / --demo) / release tarballs |
Usage #
# build
nix build .#vit
nix build .#rook
nix build .#spinel
nix build .#boxd # x86_64-linux / aarch64-linux / aarch64-darwin
nix build .#whetuu # linux + darwin (all four systems)
nix build .#pullrun # linux + darwin (all four systems)
nix build .#gleam-preview # linux + darwin (all four systems)
nix build .#zed-preview # x86_64-linux only
nix build .#halloy # x86_64-linux only
nix build .#pulp # linux only (GNOME/GTK4)
nix build .#mimic # linux only (GTK4/libadwaita)
nix build .#portfolio # linux only (GTK4/libadwaita file manager)
nix build .#eyg # linux + darwin (all four systems)
nix build .#lore # x86_64-linux / aarch64-linux / aarch64-darwin
nix build .#loreserver # same platforms as lore
# run without installing
nix run .#vit -- --help
nix run .#rook -- --help
nix run .#spinel -- --help
nix run .#spin -- new myapp # spin project tool (from the spinel package)
nix run .#boxd -- --help
nix run .#whetuu -- --version
nix run .#pullrun -- --version
nix run .#gleam-preview -- --version
nix run .#zed-preview -- --version
nix run .#halloy -- --version
nix run .#pulp
nix run .#mimic
nix run .#portfolio
nix run .#eyg -- --version
nix run .#eyg -- eval -c '!int_add(1, 1)'
nix run .#lore -- --version
nix run .#loreserver -- --version
# install into your profile
nix profile install .#vit
nix profile install .#rook
nix profile install .#spinel
nix profile install .#boxd
nix profile install .#whetuu
nix profile install .#pullrun
nix profile install .#gleam-preview
nix profile install .#zed-preview
nix profile install .#halloy
nix profile install .#pulp
nix profile install .#mimic
nix profile install .#portfolio
nix profile install .#eyg
nix profile install .#lore
nix profile install .#loreserver
Updating packages #
Automated (recommended) #
A GitHub Action runs every Monday (and on manual dispatch) to:
- Read each
packages/*/upstream.json - Compare the packaged version to the latest upstream tag
- Refresh source hashes, regenerate lockfiles when needed, recompute
npmDepsHash - Verify
nix build .#<pkg> - Open a PR on branch
chore/update-packagesif anything changed
# preferred: flake app (wraps scripts/update-packages.sh; run from this checkout)
nix run .#update -- --check # dry-run: exit 1 if any package is behind
nix run .#update # bump all packages from upstream
nix run .#update -- vit # one package
# same script directly
./scripts/update-packages.sh --check
./scripts/update-packages.sh
./scripts/update-packages.sh vit
upstream.json #
Supported types:
npm-github — tagged npm projects:
{
"type": "npm-github",
"github": "owner/repo",
"tag_prefix": "v"
}
npm-github packages are expected to use buildNpmPackage + fetchFromGitHub
with a version field and optional vendored package-lock.json.
gitlab-tag — tagged source packages on GitLab (including GNOME GitLab):
{
"type": "gitlab-tag",
"domain": "gitlab.gnome.org",
"gitlab": "owner/repo",
"tag_prefix": ""
}
Tracks the newest tag matching {tag_prefix} + numeric version (CalVer like
2026.4 or semver). Refreshes version and the fetchFromGitLab hash.
Used by pulp.
github-tag — tagged source packages on GitHub (no npm lockfile):
{
"type": "github-tag",
"github": "owner/repo",
"tag_prefix": "v"
}
Tracks the newest tag matching {tag_prefix} + semver. Refreshes version
and the fetchFromGitHub hash. Used by mimic.
github-unstable — projects without release tags (track branch tip):
{
"type": "github-unstable",
"github": "owner/repo",
"branch": "master"
}
Versions are 0-unstable-YYYY-MM-DD with a pinned rev in fetchFromGitHub.
For spinel, the updater also re-reads PRISM_VERSION / RBS_VERSION from the
upstream Makefile and refreshes the vendored gem hashes when they change.
github-release-binary — prebuilt release assets (no source build):
Single-asset:
{
"type": "github-release-binary",
"github": "owner/repo",
"tag_prefix": "v",
"tag_suffix": "-pre",
"asset": "zed-linux-x86_64.tar.gz"
}
Multi-platform (sources = { … } block, like url-manifest-binary):
{
"type": "github-release-binary",
"github": "owner/repo",
"tag_prefix": "v",
"platforms": {
"x86_64-linux": "tool-v{version}-x86_64-linux-musl.tar.gz",
"aarch64-linux": "tool-v{version}-aarch64-linux-musl.tar.gz",
"x86_64-darwin": "tool-v{version}-x86_64-macos.tar.gz",
"aarch64-darwin": "tool-v{version}-aarch64-macos.tar.gz"
}
}
Tracks the newest non-draft GitHub release whose tag matches
{tag_prefix}{version}{tag_suffix} (semver or CalVer with 2+ numeric
components). Set "tag_prefix": "" for unprefixed tags (e.g. Halloy 2026.8).
Set "tag_prerelease": true to match any prerelease tag (vX.Y.Z-rc1,
vX.Y.Z-beta, …) instead of a fixed suffix. Single-asset mode refreshes one
fetchurl hash; multi-platform mode rewrites every sources.<system>.{url,hash}.
{version} in asset names is the bare version (no tag prefix). Used by
zed-preview (single), whetuu / gleam-preview / pullrun / halloy
(multi; halloy is x86_64-linux only).
url-manifest-binary — prebuilt multi-platform binaries via a version manifest URL (not GitHub releases):
{
"type": "url-manifest-binary",
"manifest_url": "https://boxd.sh/downloads/cli/latest-{platform}.json",
"platforms": {
"x86_64-linux": "linux-amd64",
"aarch64-linux": "linux-arm64",
"aarch64-darwin": "darwin-arm64"
}
}
{platform} is replaced per entry in platforms. Each manifest must expose
version + url; the updater prefetches every platform hash and rewrites the
sources = { … } block in default.nix. Used by boxd.
Manual steps (vit / rook) #
If you prefer to bump by hand (same flow for either npm-github package):
- Bump
versioninpackages/<name>/default.nix. - Prefetch the new source hash:
nix-prefetch-url --unpack "https://github.com/solpbc/<name>/archive/refs/tags/vX.Y.Z.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> - Regenerate a lockfile with resolved URLs when needed:
tmp=$(mktemp -d) && cd "$tmp" curl -sL "https://github.com/solpbc/<name>/archive/refs/tags/vX.Y.Z.tar.gz" | tar -xz cd <name>-X.Y.Z rm -f package-lock.json bun.lock npm install --package-lock-only --ignore-scripts cp package-lock.json /path/to/this/repo/packages/<name>/package-lock.json - Set
npmDepsHashto the all-zero fake hash, runnix build .#<name>, paste the hash nix prints asgot:, rebuild.
Or just run ./scripts/update-packages.sh vit / ./scripts/update-packages.sh rook.
Manual steps (spinel) #
Spinel has no release tags yet, so the package pins a git commit as
0-unstable-YYYY-MM-DD. Prefer the updater:
./scripts/update-packages.sh spinel
By hand:
- Bump
version,rev, and thefetchFromGitHubhashinpackages/spinel/default.nix. - If upstream changed
PRISM_VERSION/RBS_VERSIONin its Makefile, updateprismVersion/rbsVersionand re-hash the gems:nix-prefetch-url "https://rubygems.org/gems/prism-X.Y.Z.gem" nix-prefetch-url "https://rubygems.org/gems/rbs-X.Y.Z.gem" nix hash convert --hash-algo sha256 --to sri <base32> nix build .#spineland smoke-test./result/bin/spinel -e 'puts 1'.
Manual steps (zed-preview) #
zed-preview ships official Linux x86_64 preview binaries (tags vX.Y.Z-pre).
Prefer the updater:
./scripts/update-packages.sh zed-preview
By hand:
- Bump
versioninpackages/zed-preview/default.nix(e.g.1.12.0-pre). - Prefetch the tarball hash:
nix-prefetch-url "https://github.com/zed-industries/zed/releases/download/vX.Y.Z-pre/zed-linux-x86_64.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> - Paste the SRI hash into
fetchurl.hash, thennix build .#zed-previewand smoke-test./result/bin/zed-preview --version.
Manual steps (boxd) #
boxd ships official static CLI binaries from boxd.sh
(see quickstart). Prefer the updater:
./scripts/update-packages.sh boxd
By hand:
- Read the manifests and note the shared version:
curl -fsSL https://boxd.sh/downloads/cli/latest-linux-amd64.json curl -fsSL https://boxd.sh/downloads/cli/latest-linux-arm64.json curl -fsSL https://boxd.sh/downloads/cli/latest-darwin-arm64.json - Bump
versioninpackages/boxd/default.nix. - Prefetch each platform binary hash into the matching
sources.<system>.hash:nix-prefetch-url "https://boxd.sh/downloads/cli/boxd-linux-amd64" nix-prefetch-url "https://boxd.sh/downloads/cli/boxd-linux-arm64" nix-prefetch-url "https://boxd.sh/downloads/cli/boxd-darwin-arm64" nix hash convert --hash-algo sha256 --to sri <base32> nix build .#boxdand smoke-test./result/bin/boxd --version.
Manual steps (whetuu) #
whetuu ships official multi-platform release tarballs (static musl on Linux).
Prefer the updater:
./scripts/update-packages.sh whetuu
By hand:
- Bump
versioninpackages/whetuu/default.nix(e.g.0.1.5). - Update each
sources.<system>.urlto the matching release asset and prefetch:nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-x86_64-linux-musl.tar.gz" nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-aarch64-linux-musl.tar.gz" nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-x86_64-macos.tar.gz" nix-prefetch-url "https://github.com/yamafaktory/whetuu/releases/download/vX.Y.Z/whetuu-vX.Y.Z-aarch64-macos.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> nix build .#whetuuand smoke-test./result/bin/whetuu --version.
Manual steps (pullrun) #
pullrun ships official multi-platform release tarballs (CLI + runtime, static).
Prefer the updater:
./scripts/update-packages.sh pullrun
By hand:
- Bump
versioninpackages/pullrun/default.nix(e.g.0.6.7). - Update each
sources.<system>.urlto the matching release asset and prefetch:nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-linux-amd64.tar.gz" nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-linux-arm64.tar.gz" nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-darwin-amd64.tar.gz" nix-prefetch-url "https://github.com/pullrun/pullrun/releases/download/vX.Y.Z/pullrun-X.Y.Z-darwin-arm64.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> nix build .#pullrunand smoke-test./result/bin/pullrun --versionand./result/bin/pullrun-runtime --version.
Manual steps (gleam-preview) #
gleam-preview ships official multi-platform prerelease binaries (tags
vX.Y.Z-rcN, etc.). The binary is installed as gleam-preview so it can
coexist with nixpkgs gleam. Prefer the updater:
./scripts/update-packages.sh gleam-preview
By hand:
- Bump
versioninpackages/gleam-preview/default.nix(e.g.1.18.0-rc1). - Update each
sources.<system>.urlto the matching release asset and prefetch:nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-x86_64-unknown-linux-musl.tar.gz" nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-aarch64-unknown-linux-musl.tar.gz" nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-x86_64-apple-darwin.tar.gz" nix-prefetch-url "https://github.com/gleam-lang/gleam/releases/download/vX.Y.Z-rcN/gleam-vX.Y.Z-rcN-aarch64-apple-darwin.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> nix build .#gleam-previewand smoke-test./result/bin/gleam-preview --version.
Manual steps (halloy) #
halloy ships an official Linux x86_64 release tarball (IRC client). Prefer the
updater:
./scripts/update-packages.sh halloy
By hand:
- Bump
versioninpackages/halloy/default.nix(e.g.2026.8). - Update
sources.x86_64-linux.urland prefetch:nix-prefetch-url "https://github.com/squidowl/halloy/releases/download/X.Y/halloy-X.Y-x86_64-linux.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> nix build .#halloyand smoke-test./result/bin/halloy --version.
Manual steps (pulp) #
pulp is a GNOME RSS reader built from source (Meson + Python + GTK4). Prefer
the updater:
./scripts/update-packages.sh pulp
By hand:
- Bump
versioninpackages/pulp/default.nix(e.g.2026.4). - Prefetch the source hash:
nix-prefetch-url --unpack "https://gitlab.gnome.org/cheywood/Pulp/-/archive/X.Y/Pulp-X.Y.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> - Paste the SRI hash into
fetchFromGitLab.hash, thennix build .#pulp.
Manual steps (portfolio) #
portfolio is a minimalist GTK4 file manager built from source (Meson + Python).
Prefer the updater:
./scripts/update-packages.sh portfolio
By hand:
- Bump
versioninpackages/portfolio/default.nix(e.g.1.0.3). - Prefetch the source hash:
nix-prefetch-url --unpack "https://github.com/tchx84/Portfolio/archive/refs/tags/vX.Y.Z.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> - Paste the SRI hash into
fetchFromGitHub.hash, thennix build .#portfolio.
Manual steps (lore / loreserver) #
lore and loreserver ship separate multi-platform release tarballs (dynamic
glibc on Linux; no darwin-x86_64; aarch64-linux is Neoverse/Graviton only).
Prefer the updater:
./scripts/update-packages.sh lore
./scripts/update-packages.sh loreserver
By hand:
- Bump
versioninpackages/lore/default.nixandpackages/loreserver/default.nix(e.g.0.8.5). - Update each
sources.<system>.urlto the matching release asset and prefetch:# lore CLI nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/lore-vX.Y.Z-x86_64-unknown-linux-gnu.tar.gz" nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/lore-vX.Y.Z-aarch64-unknown-linux-gnu-neoverse-512tvb.tar.gz" nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/lore-vX.Y.Z-aarch64-apple-darwin.tar.gz" # loreserver nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/loreserver-vX.Y.Z-x86_64-unknown-linux-gnu.tar.gz" nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/loreserver-vX.Y.Z-aarch64-unknown-linux-gnu-neoverse-512tvb.tar.gz" nix-prefetch-url "https://github.com/EpicGames/lore/releases/download/vX.Y.Z/loreserver-vX.Y.Z-aarch64-apple-darwin.tar.gz" nix hash convert --hash-algo sha256 --to sri <base32> nix build .#lore/nix build .#loreserverand smoke-test./result/bin/lore --version/./result/bin/loreserver --version.