Go module checksums are committed
golang/checksums-committed@v1
The module commits go.sum, so every module a build downloads is verified against the checksum recorded in the commit.
| Id | golang/checksums-committed |
| Version | v1 |
| Category | golang |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | golang |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
golang | The Go build in the project directory: the module it declares, the Go version it asks for, every module of a workspace, the modules it requires directly and indirectly, and the replacements and lock file beside them. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "golang/checksums-committed@v1",
"severity": "warning",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Commit the checksum file the Go tooling writes:
go mod tidy
git add go.sumgo.sum holds the checksum of every module in the dependency graph. Without it, nothing verifies that what the build downloaded is what the module authors published, so a swapped or rewritten version reaches the binary unnoticed.
More in golang
golang/no-local-replacements. Noreplacedirective points a module at a filesystem path, so the build only uses source that is in the checkout.golang/toolchain-pinned. The module names the exact toolchain that compiles it, instead of leaving thegodirective as a minimum version.golang/version-declared. The module declares the Go version it is built against, and that version is no older than the configured floor.