Skip to content

Guardrails

golang ​

4 guardrails, all at version v1.

GuardrailDefault severityWhat it checks
golang/checksums-committedwarningThe module commits go.sum, so every module a build downloads is verified against the checksum recorded in the commit.
golang/no-local-replacementserrorNo replace directive points a module at a filesystem path, so the build only uses source that is in the checkout.
golang/toolchain-pinnedwarningThe module names the exact toolchain that compiles it, instead of leaving the go directive as a minimum version.
golang/version-declaredwarningThe module declares the Go version it is built against, and that version is no older than the configured floor.

Shared inputs ​

Every golang guardrail declares these inputs. Individual guardrails can add their own.

InputDescriptionDefault
projectDirDirectory holding the project, relative to the directory the CLI runs in..

Shared collectors ​

Every golang guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.

CollectorGathers
golangThe Go build in the project directory: the module it declares, the Go version it asks for, every module of a workspace, the modules it requires directly and indirectly, and the replacements and lock file beside them.

You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.

Buildnote Limited
Registered in England and Wales, Reg: 16140412