rubyPackages: Add command to audit packages (#443737)
This commit is contained in:
6
maintainers/scripts/audit-ruby-packages/audit-ruby-packages.bash
Executable file
6
maintainers/scripts/audit-ruby-packages/audit-ruby-packages.bash
Executable file
@@ -0,0 +1,6 @@
|
||||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash -p bundler-audit
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
bundle-audit check "$(nix-build --no-out-link maintainers/scripts/audit-ruby-packages/default.nix)"
|
||||
15
maintainers/scripts/audit-ruby-packages/default.nix
Normal file
15
maintainers/scripts/audit-ruby-packages/default.nix
Normal file
@@ -0,0 +1,15 @@
|
||||
let
|
||||
pkgs = import ../../.. { };
|
||||
lockFileBody = pkgs.lib.concatStringsSep "\n" (
|
||||
pkgs.lib.mapAttrsToList (name: props: " ${name} (${props.version})") (
|
||||
pkgs.lib.filterAttrs (name: _props: name != "recurseForDerivations") pkgs.rubyPackages
|
||||
)
|
||||
);
|
||||
in
|
||||
pkgs.runCommand "bundle-audit" { } ''
|
||||
mkdir "$out"
|
||||
echo 'GEM' > "$out/Gemfile.lock"
|
||||
echo ' remote: https://rubygems.org/' >> "$out/Gemfile.lock"
|
||||
echo ' specs:' >> "$out/Gemfile.lock"
|
||||
echo '${lockFileBody}' >> "$out/Gemfile.lock"
|
||||
''
|
||||
Reference in New Issue
Block a user