In this post:
--- start quote ---
How about a different version of Ruby or Node? Let’s say that our project depends on Ruby 2.6 and Node 10. We can go and search for those specific versions
--- end quote ---
So, to begin with, we still need a "version manager", because we want specific package versions. But look at how this is implemented in nix:
let
pkgs = import <nixpkgs> { };
in
pkgs.mkShell {
buildInputs = [
pkgs.hello
pkgs.ruby_2_6
pkgs.nodejs-10_x
];
}
Why? Because unlike every sane package/dependency manager where you specify a package and a version, nix pretends each version is a separate package.And these packages aren't even correct. If you do go and search for ruby, for example [1], you get the following:
ruby Version: 2.7.4
ruby_3_0 Version: 3.0.2
ruby_2_6 Version: 2.6.8
This... This is laughable. How do I install ruby 2.6.8? Oh, there's no ruby_2_6_8, because of course there isn't. And this could be difference between a secure system and all your base are belong to us.And they call this reproducible builds?
And that's before getting into the ridiculous
--- start quote ---
All the software that we installed depends on the specific version of the nixpkgs channel that we installed on our system [whose only version is a commit hash in a git repo]
--- end quote ---
So you need an extra tool [2] for, quote, "painless dependencies for Nix projects."
Yes, sure. I'm definitely ditching my version managers in favor of this tool, that hasn't solved these issues in 18 years of its existence.
[1] https://search.nixos.org/packages?channel=21.05&from=0&size=...