Skip to content

Guardrails / golang

No module is replaced by a directory ​

golang/no-local-replacements@v1

No replace directive points a module at a filesystem path, so the build only uses source that is in the checkout.

Idgolang/no-local-replacements
Versionv1
Categorygolang
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgolang

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
golangThe Go build in the project directory: the module it declares, the Go version it asks for, every module of a workspace, the modules it requires directly and indirectly, and the replacements and lock file beside them.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "golang/no-local-replacements@v1",
              "severity": "error",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Remove the directive and require the module by its own path, or replace it with a module path and version instead of a directory:

replace github.com/company/queue => github.com/company/queue/v2 v2.1.0

For local development across several modules, list the directories in the use block of a go.work file instead of adding another replace:

go 1.22

use (
	./widget
	./queue
)

A replace that points at a directory builds from something the checkout doesn't contain, so it compiles on the author's laptop and nowhere else.

More in golang ​

  • golang/checksums-committed. The module commits go.sum, so every module a build downloads is verified against the checksum recorded in the commit.
  • golang/toolchain-pinned. The module names the exact toolchain that compiles it, instead of leaving the go directive as a minimum version.
  • golang/version-declared. The module declares the Go version it is built against, and that version is no older than the configured floor.

All 4 golang guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412