name: Update packages on: schedule: - cron: '0 6 * * 1' workflow_dispatch: permissions: contents: write pull-requests: write jobs: update: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: cachix/install-nix-action@v31 with: extra_nix_config: | experimental-features = nix-command flakes access-tokens = github.com=${{ secrets.GITHUB_TOKEN }} - name: Update packages run: | python_pkgs=(toutatis ignorant ghunt user-scanner) go_pkgs=(github-recon gravatar-recon spilltea usbguard-tui jwt-tui) for pkg in "${python_pkgs[@]}"; do echo "==> $pkg" nix run nixpkgs#nix-update -- --flake "$pkg" || true done for pkg in "${go_pkgs[@]}"; do echo "==> $pkg" nix run nixpkgs#nix-update -- --flake --build "$pkg" || true done - uses: peter-evans/create-pull-request@v7 with: token: ${{ secrets.GITHUB_TOKEN }} commit-message: "auto-update: bump package versions" title: "Auto-update packages" body: | Automated package updates via `nix-update`. Check individual diffs to see what changed. branch: auto-update delete-branch: true