Use nix-hash for SRI conversion and add install-nix-action

Replace the fragile Python one-liner with nix-hash --sri for
computing flake hashes in CI. Add cachix/install-nix-action@v31
to ensure Nix is available on the runner. Add grep verification
to fail loudly if sed replacements don't take effect.

Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
This commit is contained in:
Michael Lyon
2026-04-03 11:15:21 -06:00
co-authored by claude
parent a1455d88d8
commit 8b0b1e25b3
+8 -5
View File
@@ -64,20 +64,23 @@ jobs:
dist/*.deb
dist/*.rpm
- name: Install Nix
uses: cachix/install-nix-action@v31
- name: Update flake.nix hashes
env:
VERSION: ${{ steps.bump.outputs.version }}
run: |
X86_HASH=$(sha256sum dist/linear-linux-${VERSION}-x86_64.AppImage | awk '{print $1}')
ARM_HASH=$(sha256sum dist/linear-linux-${VERSION}-arm64.AppImage | awk '{print $1}')
X86_SRI="sha256-$(echo -n "$X86_HASH" | python3 -c "import sys,base64,binascii; print(base64.b64encode(binascii.unhexlify(sys.stdin.read())).decode())")"
ARM_SRI="sha256-$(echo -n "$ARM_HASH" | python3 -c "import sys,base64,binascii; print(base64.b64encode(binascii.unhexlify(sys.stdin.read())).decode())")"
X86_SRI=$(nix-hash --type sha256 --flat --sri dist/linear-linux-${VERSION}-x86_64.AppImage)
ARM_SRI=$(nix-hash --type sha256 --flat --sri dist/linear-linux-${VERSION}-arm64.AppImage)
sed -i "s|version = \".*\";|version = \"${VERSION}\";|" flake.nix
sed -i "s|hash = \"sha256-.*\"; # x86_64|hash = \"${X86_SRI}\"; # x86_64|" flake.nix
sed -i "s|hash = \"sha256-.*\"; # aarch64|hash = \"${ARM_SRI}\"; # aarch64|" flake.nix
grep -q "${X86_SRI}" flake.nix || { echo "::error::Failed to update x86_64 hash"; exit 1; }
grep -q "${ARM_SRI}" flake.nix || { echo "::error::Failed to update aarch64 hash"; exit 1; }
- name: Commit flake.nix update
env:
VERSION: ${{ steps.bump.outputs.version }}