Go in the Nix ecosystem: vulnerability scanning and experiments towards a next-gen builder
- Track: Nix and NixOS
- Room: K.3.601
- Day: Saturday
- Start: 13:15
- End: 13:35
- Video only: k3601
- Chat: Join the conversation!
After looking at the current way Go code is packaged in nixpkgs using buildGoModule
, disadvantages are pointed out with a focus on security (backed by data from govulncheck-nixpkgs project) and performance. Out-of-tree alternatives are presented with a focus on the new and promising approach of gobuild.nix, which implements a hook-based builder with module-level caching.
Speakers
Paul Meyer |