fix: remove explicit cacert install to resolve version conflict

cacert 3.123 was installed first, but nodejs_22 pulls cacert 3.117 as a
transitive dependency, causing a file conflict on ca-bundle.crt.

Since all packages that need SSL certificates already pull cacert as a
dependency, installing it explicitly is redundant and causes conflicts.
Removing the explicit cacert install lets each package use its resolved
transitive cacert version.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
MythEclipse
2026-06-01 12:38:55 +07:00
co-authored by Claude Opus 4.6
parent 20ff930bb3
commit 86853bbd4e
+2 -2
View File
@@ -8,10 +8,10 @@ ENV NIX_CONFIG="experimental-features = nix-command flakes"
# When installing multiple packages simultaneously, nix may resolve
# different versions of shared dependencies (e.g., cacert 3.123 vs 3.117)
# which causes "An existing package already provides" errors.
# Installing sequentially allows each package to settle before the next.
# We install the big packages first (which pull their own cacert),
# then install standalone cacert last to upgrade, using --allow-import.
ARG NIXPKGS_COMMIT=64c08a7ca051951c8eae34e3e3cb1e202fe36786
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#cacert"
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#nodejs_22"
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#ffmpeg"
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#python3"