diff --git a/.github/workflows/nixos-options.yml b/.github/workflows/nixos-options.yml new file mode 100644 index 0000000000000..0435796f98c93 --- /dev/null +++ b/.github/workflows/nixos-options.yml @@ -0,0 +1,28 @@ +name: "Evaluate NixOS options" + +permissions: + contents: read + +on: + pull_request_target: + +jobs: + nixos: + name: nixos-options + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + # pull_request_target checks out the base branch by default + ref: refs/pull/${{ github.event.pull_request.number }}/merge + - uses: cachix/install-nix-action@08dcb3a5e62fa31e2da3d490afc4176ef55ecd72 # v30 + with: + # explicitly enable sandbox + extra_nix_config: sandbox = true + - name: Building NixOS options + run: | + nix-build ./nixos/release.nix \ + -I ./. \ + --option restrict-eval true \ + --option allow-import-from-derivation false \ + -A options