Settle the open points of the Ubuntu and nixpkgs image #42

Merged
clawbot merged 1 commits from issue-38-image-open-points into next 2026-10-04 02:42:58 +02:00
1 Commits
Author SHA1 Message Date
clawbot 1dace858e9 Settle the open points of the Ubuntu and nixpkgs image (closes #38)
check / check (push) Successful in 3m16s
ca-certificates, nix-bin and runit come from a dated Ubuntu snapshot no
older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash
of each snapshot InRelease file apt uses, and the build checks them before
apt-get install, so every package is checked against hashed files. That
install uses the Go image's CA certificate file. ca-certificates is
installed by name. The image writes build-users-group = to
/etc/nix/nix.conf so root can build without a daemon. nixpkgs comes from
its release file on releases.nixos.org, checked by SHA-256, and takes about
500 MiB of disk. runsvinit is archived upstream and is built at a fixed
commit with a go.mod written for the build. The example run scripts put
their code in a main function.

Model: opus-5-5
2026-10-04 00:27:37 +00:00