Skip to main content

Go in the Nix ecosystem: vulnerability scanning and experiments towards a next-gen builder

K.3.601 | Day 1 | 13:15 - 13:35 | Speakers: Paul Meyer

Go in the Nix ecosystem: vulnerability scanning and experiments towards a next-gen builder
A picture of a devroom at FOSDEM 2024
Open in browser
Get involved in the conversation!Join the chat

Notes

Abstract

After looking at the current way Go code is packaged in nixpkgs using buildGoModule, disadvantages are pointed out with a focus on security (backed by data from govulncheck-nixpkgs project) and performance. Out-of-tree alternatives are presented with a focus on the new and promising approach of gobuild.nix, which implements a hook-based builder with module-level caching.

Attachments

Speakers

Paul Meyer

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.