Skip to content

Guardrails / golang

Go toolchain is pinned ​

golang/toolchain-pinned@v1

The module names the exact toolchain that compiles it, instead of leaving the go directive as a minimum version.

Idgolang/toolchain-pinned
Versionv1
Categorygolang
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgolang

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
golangThe Go build in the project directory: the module it declares, the Go version it asks for, every module of a workspace, the modules it requires directly and indirectly, and the replacements and lock file beside them.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "golang/toolchain-pinned@v1",
              "severity": "warning",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Name the toolchain next to the go directive:

go 1.22

toolchain go1.22.3

go mod edit -toolchain=go1.22.3 writes it for you. The go directive sets the lowest Go version the module builds with, not the one it is built by. Without a toolchain line, the compiler is whichever Go the runner happens to have, and a compiler change arrives without warning.

More in golang ​

  • golang/checksums-committed. The module commits go.sum, so every module a build downloads is verified against the checksum recorded in the commit.
  • golang/no-local-replacements. No replace directive points a module at a filesystem path, so the build only uses source that is in the checkout.
  • golang/version-declared. The module declares the Go version it is built against, and that version is no older than the configured floor.

All 4 golang guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412