Preface: Nix is sometimes difficult because it forces you to be explicit about what you mean. For instance, your example specifies particular versions of end-user packages. Do you want all of them to use the same shared libraries? Do you want each of them to use the libraries that they were tested with at the time those specific versions were released? Should we use the latest secure+patched libraries, but the older application versions? Do you want the patches to your applications known at time of release, or the latest? Most systems don't allow this much specificity or power.
Yes. An example that i had to do recently. I forget the exact issue, but I wanted to express the thought: "keep the rest of my system up to date, but pin only the notmuch package to an older version. Oh, and to make sure it is not unspecified: that older version should also use the dynamic libraries that it is tested to work with, potentially older than the rest of my system."
in code;
```
nixpkgs.overlays = [(self: super: {
notmuch = nixpkgs-old.legacyPackages.x86_64-linux.notmuch;
})];
```
Where nixpkgs is basically 21.11 and nixpkgs-old is a particular git commit hash.
But you can express other nuanced thoughts as well:
- bring in an old application, but don't change anything else on my system (non-interference)
- patch some core library, AND recompile EVERYTHING that uses it (global replacement)
- only replace a core library for the software used for a particular service, no where else (targeted patching)
- change some ./configure flags but otherwise track the latest security updates for a release, recompile only the things needed (dynamic customization)
- recompile everything with optimization flags (source based distro)
- only update what github revision used as source for an application, otherwise everything the same (stay on bleeding edge for a specific application)
I think people tend to overthink Flakes, they are a standard code organization schema and an entrypoint into the Nix language that ensures everything is tracked and locked. It makes things reproducible, both the successes and (perhaps more important!) the bugs and failures.