How safe is follows?

5 Likes

I think it’s worth pointing out that because:

If we consider the median, when you add a follows line you are, typically, asking a flake to replace it with a nixpkgs likely a year and a half newer than anything its author ever tested. One time in twenty you are asking it to consolidate across five years. :grimacing:

… you are also asking nix to update the dependencies of a given flake by 1.5 years in the median case. The 1.5 years of neglect you’re seeing also means there’s 1.5 years of missing dependency updates.

Arguably your data shows that it is unsafe - by some definition of the word “unsafe” - not to use follows, in the sense that you’re going to be exposed to a hecking lot of vulnerabilities if you don’t.


Personally I don’t think unsafe:: may not build is as useful of a definition as unsafe:: likely to be riddled with CVEs - in the first case nix tells you and you can assess whether you should un-follows your input, in the latter case you are blissfully ignorant of the house of cards you’ve built.

As such, I would recommend always using follows and just seeing whether it breaks. Removing follows when needed is cheap, you just have to understand what you’re doing.

Better yet, minimize the number of flakes you’re using, and rely on nixpkgs-native versions of software, since they’re properly integrated and updated. Kinda the point of a distro. Add packages that don’t exist upstream yet yourself, or assume maintenance where you see problems.

But yes, sometimes you want to use flakes instead for various reasons. flake-edit has a useful subcommand to automate doing the .follows thing recursively.

11 Likes

Omniflake lets you just as easily unify if you want; I just thought it was an interesting investigation.