New nixpkgs pin
Stick to the nixos-unstable branch so folks that use the public build
cache get cache hits.
In particular, make sure to pick up
e8cc900eaec34c2b7399678f0cd47c1b0e36a6ef, which makes useNixStoreImage
actually work.
Check that an unreferenced package does not appear in the guest.