No module is replaced by a directory
golang/no-local-replacements@v1
No replace directive points a module at a filesystem path, so the build only uses source that is in the checkout.
| Id | golang/no-local-replacements |
| Version | v1 |
| Category | golang |
| Default severity | error |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | golang |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
golang | The Go build in the project directory: the module it declares, the Go version it asks for, every module of a workspace, the modules it requires directly and indirectly, and the replacements and lock file beside them. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "golang/no-local-replacements@v1",
"severity": "error",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Remove the directive and require the module by its own path, or replace it with a module path and version instead of a directory:
replace github.com/company/queue => github.com/company/queue/v2 v2.1.0For local development across several modules, list the directories in the use block of a go.work file instead of adding another replace:
go 1.22
use (
./widget
./queue
)A replace that points at a directory builds from something the checkout doesn't contain, so it compiles on the author's laptop and nowhere else.
More in golang
golang/checksums-committed. The module commitsgo.sum, so every module a build downloads is verified against the checksum recorded in the commit.golang/toolchain-pinned. The module names the exact toolchain that compiles it, instead of leaving thegodirective as a minimum version.golang/version-declared. The module declares the Go version it is built against, and that version is no older than the configured floor.