name: Pull request diff on: pull_request: branches: - main jobs: diff-expr: name: Diff nix expressions runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - uses: cachix/install-nix-action@v17 with: extra_nix_config: | access-tokens = github.com=${{ secrets.GITHUB_TOKEN }} trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nixcache:8KKuGz95Pk4UJ5W/Ni+pN+v+LDTkMMFV4yrGmAYgkDg= hydra.nixos.org-1:CNHJZBh9K4tP3EKF6FkkgeVYsS3ohTl+oS0Qa8bezVs= experimental-features = nix-command flakes ca-derivations post-build-hook = ${{ github.workspace }}/scripts/post-build-hook substituters = https://cache.chir.rs/ - name: Download patched nix run: nix build github:DarkKirb/nix-packages#nix-s3-dedup - name: Set up secrets run: | echo "$NIX_CACHE_KEY" > ~/cache.key sudo mkdir /root/.aws echo "$AWS_CREDENTIALS" | sudo tee /root/.aws/credentials > /dev/null env: NIX_CACHE_KEY: ${{secrets.NIX_CACHE_KEY}} AWS_CREDENTIALS: ${{secrets.AWS_CREDENTIALS}} - run: | for job in nixos-8gb-fsn1-1 nutty-noon thinkrac installer nas; do nix show-derivation -r "github:DarkKirb/nixos-config/main#hydraJobs.$job.x86_64-linux" > old-$job.json done echo "Difference between this PR and main:" > review echo "" >> review for job in nixos-8gb-fsn1-1 nutty-noon thinkrac installer nas; do nix show-derivation -r ".#hydraJobs.$job.x86_64-linux" > new-$job.json echo "## Changes for $job:" >> review echo '```' >> review python scripts/diff-drvs.py old-$job.json new-$job.json >> review echo '```' >> review done mv review .github/workflows - uses: harupy/comment-on-pr@master env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: filename: review