Skip to content

Guardrails / golang

Go module checksums are committed ​

golang/checksums-committed@v1

The module commits go.sum, so every module a build downloads is verified against the checksum recorded in the commit.

Idgolang/checksums-committed
Versionv1
Categorygolang
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgolang

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
golangThe Go build in the project directory: the module it declares, the Go version it asks for, every module of a workspace, the modules it requires directly and indirectly, and the replacements and lock file beside them.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "golang/checksums-committed@v1",
              "severity": "warning",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Commit the checksum file the Go tooling writes:

bash
go mod tidy
git add go.sum

go.sum holds the checksum of every module in the dependency graph. Without it, nothing verifies that what the build downloaded is what the module authors published, so a swapped or rewritten version reaches the binary unnoticed.

More in golang ​

  • golang/no-local-replacements. No replace directive points a module at a filesystem path, so the build only uses source that is in the checkout.
  • golang/toolchain-pinned. The module names the exact toolchain that compiles it, instead of leaving the go directive as a minimum version.
  • golang/version-declared. The module declares the Go version it is built against, and that version is no older than the configured floor.

All 4 golang guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412