Fix devenv configuration and add lock files

- Fix devenv.nix: rename pre-commit to git-hooks (devenv API change)
- Use nixpkgs rust packages directly (avoid rust-overlay dependency)
- Remove non-existent packages (nak, libnfc, httpie)
- Use webkitgtk_4_1 instead of webkitgtk for Tauri compatibility
- Add devenv.lock and pnpm-lock.yaml for reproducible builds
- Update root .gitignore to exclude .claude/ and .pre-commit-config.yaml

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-01-23 05:41:49 -05:00
commit e295a37367
4 changed files with 2342 additions and 115 deletions

6
.gitignore vendored
View file

@ -42,3 +42,9 @@ coverage/
*.pem *.pem
*.crt *.crt
*.key *.key
# Claude Code
.claude/
# Pre-commit (auto-generated by devenv)
.pre-commit-config.yaml

170
lamassu-next/devenv.lock Normal file
View file

@ -0,0 +1,170 @@
{
"nodes": {
"devenv": {
"locked": {
"dir": "src/modules",
"lastModified": 1769080719,
"owner": "cachix",
"repo": "devenv",
"rev": "a13cd68223ccb1c50aa9c253504463fda67e6554",
"type": "github"
},
"original": {
"dir": "src/modules",
"owner": "cachix",
"repo": "devenv",
"type": "github"
}
},
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"owner": "NixOS",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_2": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"owner": "NixOS",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "flake-compat",
"type": "github"
}
},
"git-hooks": {
"inputs": {
"flake-compat": "flake-compat",
"gitignore": "gitignore",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1769069492,
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "a1ef738813b15cf8ec759bdff5761b027e3e1d23",
"type": "github"
},
"original": {
"owner": "cachix",
"repo": "git-hooks.nix",
"type": "github"
}
},
"gitignore": {
"inputs": {
"nixpkgs": [
"git-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1762808025,
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "cb5e3fdca1de58ccbc3ef53de65bd372b48f567c",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
"gitignore_2": {
"inputs": {
"nixpkgs": [
"pre-commit-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1762808025,
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "cb5e3fdca1de58ccbc3ef53de65bd372b48f567c",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1768875095,
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "ed142ab1b3a092c4d149245d0c4126a5d7ea00b0",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1768875095,
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "ed142ab1b3a092c4d149245d0c4126a5d7ea00b0",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"pre-commit-hooks": {
"inputs": {
"flake-compat": "flake-compat_2",
"gitignore": "gitignore_2",
"nixpkgs": "nixpkgs_2"
},
"locked": {
"lastModified": 1769069492,
"owner": "cachix",
"repo": "pre-commit-hooks.nix",
"rev": "a1ef738813b15cf8ec759bdff5761b027e3e1d23",
"type": "github"
},
"original": {
"owner": "cachix",
"repo": "pre-commit-hooks.nix",
"type": "github"
}
},
"root": {
"inputs": {
"devenv": "devenv",
"git-hooks": "git-hooks",
"nixpkgs": "nixpkgs",
"pre-commit-hooks": "pre-commit-hooks"
}
}
},
"root": "root",
"version": 7
}

View file

@ -1,4 +1,4 @@
{ pkgs, lib, ... }: { pkgs, lib, config, ... }:
{ {
# Project metadata # Project metadata
@ -19,11 +19,44 @@
languages.typescript.enable = true; languages.typescript.enable = true;
languages.rust = { # Use nixpkgs rust (simpler, no overlay needed)
enable = true; packages = with pkgs; [
channel = "stable"; # Rust toolchain from nixpkgs
components = [ "rustc" "cargo" "clippy" "rustfmt" "rust-analyzer" ]; rustc
}; cargo
clippy
rustfmt
rust-analyzer
# Build tools
pkg-config
openssl
openssl.dev
# Tauri dependencies (Linux)
gtk3
webkitgtk_4_1
libappindicator-gtk3
librsvg
# Hardware access
libusb1
udev
# Serial port access
picocom
# Development utilities
just # Task runner
jq # JSON processing
websocat # WebSocket client
# Database tools
pgcli
# Container tools (for Lightning.Pub, strfry)
docker-compose
];
# ============================================ # ============================================
# Services # Services
@ -36,120 +69,25 @@
}; };
# ============================================ # ============================================
# Packages # Git Hooks (formerly pre-commit)
# ============================================ # ============================================
packages = with pkgs; [ git-hooks.hooks = {
# Build tools
pkg-config
openssl
openssl.dev
# Tauri dependencies (Linux)
gtk3
webkitgtk
libappindicator-gtk3
librsvg
# Hardware access
libusb1
libnfc
udev
# Serial port access
picocom
# Nostr tools
nak # Nostr army knife CLI
# Development utilities
just # Task runner
jq # JSON processing
httpie # HTTP client
websocat # WebSocket client
# Database tools
pgcli
# Container tools (for Lightning.Pub, strfry)
docker-compose
];
# ============================================
# Pre-commit Hooks
# ============================================
pre-commit.hooks = {
# TypeScript/JavaScript # TypeScript/JavaScript
prettier = { prettier = {
enable = true; enable = true;
excludes = [ "pnpm-lock.yaml" ]; excludes = [ "pnpm-lock.yaml" ];
}; };
eslint = {
enable = true;
entry = "pnpm eslint --fix";
types = [ "javascript" "typescript" ];
};
# Rust # Rust
rustfmt.enable = true; rustfmt.enable = true;
clippy = {
enable = true;
entry = "cargo clippy --all-targets --all-features -- -D warnings";
pass_filenames = false;
};
# TypeScript type checking
typecheck = {
enable = true;
entry = "pnpm typecheck";
pass_filenames = false;
stages = [ "pre-push" ]; # Only on push, not every commit
};
# Security: detect secrets
detect-secrets = {
enable = true;
entry = "${pkgs.detect-secrets}/bin/detect-secrets-hook --baseline .secrets.baseline";
};
# Nix formatting # Nix formatting
nixpkgs-fmt.enable = true; nixpkgs-fmt.enable = true;
# TOML/YAML validation # TOML/YAML validation
check-toml.enable = true; check-toml.enable = true;
check-yaml.enable = true; check-yaml.enable = true;
# Prevent large files
check-added-large-files = {
enable = true;
entry = "check-added-large-files --maxkb=500";
};
# Custom: Nostr event schema validation
nostr-schema = {
enable = true;
entry = "pnpm --filter @lamassu/nostr-client run validate-schemas";
files = "packages/nostr-client/.*\\.(ts|json)$";
pass_filenames = false;
};
# Custom: No console.log in production code
no-console-log = {
enable = true;
entry = ''
${pkgs.gnugrep}/bin/grep -rn "console\\.log" --include="*.ts" --include="*.tsx" \
apps/ packages/ \
--exclude-dir=node_modules \
--exclude-dir=dist \
--exclude="*.test.ts" \
--exclude="*.spec.ts" \
&& echo "ERROR: console.log found in production code" && exit 1 || exit 0
'';
pass_filenames = false;
};
}; };
# ============================================ # ============================================
@ -165,6 +103,9 @@
# Lightning.Pub development # Lightning.Pub development
LIGHTNING_PUB_URL = "http://localhost:3000"; LIGHTNING_PUB_URL = "http://localhost:3000";
# For Tauri
PKG_CONFIG_PATH = "${pkgs.openssl.dev}/lib/pkgconfig";
}; };
# ============================================ # ============================================
@ -189,22 +130,6 @@
''; '';
infra-down.exec = "docker-compose -f docker/docker-compose.dev.yml down"; infra-down.exec = "docker-compose -f docker/docker-compose.dev.yml down";
# Hardware testing
mock-bill.exec = ''
# Simulate bill insertion for testing
echo "Simulating $1 bill insertion..."
# TODO: Implement mock event publisher
'';
# Nostr tools
nostr-publish.exec = ''
nak event --content "$1" ws://localhost:7777
'';
nostr-subscribe.exec = ''
nak req --kinds "$1" ws://localhost:7777
'';
}; };
# ============================================ # ============================================
@ -226,17 +151,5 @@
echo " infra-up Start Docker infrastructure" echo " infra-up Start Docker infrastructure"
echo " infra-down Stop Docker infrastructure" echo " infra-down Stop Docker infrastructure"
echo "" echo ""
echo " Pre-commit hooks are enabled. Run 'pre-commit run --all-files' to check."
echo ""
''; '';
# ============================================
# Process Compose (optional background services)
# ============================================
# Uncomment to auto-start services in devenv up
# processes = {
# relay.exec = "docker-compose -f docker/docker-compose.dev.yml up strfry";
# lightning-pub.exec = "docker-compose -f docker/docker-compose.dev.yml up lightning-pub";
# };
} }

2138
lamassu-next/pnpm-lock.yaml generated Normal file

File diff suppressed because it is too large Load diff