Hacker News new | past | comments | ask | show | jobs | submit login

you should not create such an imperative simlink almost anything can be packages with nix in a minute or two, so any code you found out the internet would be easy to run and it will take not much more time than to simply check it's build config for malicious code, which you should do anyway



Maybe if you use buildUserFHS and --impure a lot. But NodeJS applications that try to download binaries at install time or python packages with conflicting package versions definitely take more than a minute or two. Just look at the history of Anki in Nixpkgs, or the derivations for JetBrains products or Cypress or any of the other packages that took consistent effort by multiple contributors to even get them working in the first place.

I think it's important to manage expectations about Nix and that includes being realistic about what's easy and simple what isn't.


Yeah, I am aware what I did above would make a lot of nixos purists shudder. But from a pragmatic pov it saves me a lot of time. It's mostly to deal with repos at clients that are filled with scripts hardcoded to /bin/bash.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: