Skip to content

Guardrails / golang

Go version is declared ​

golang/version-declared@v1

The module declares the Go version it is built against, and that version is no older than the configured floor.

Idgolang/version-declared
Versionv1
Categorygolang
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgolang

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
golangThe Go build in the project directory: the module it declares, the Go version it asks for, every module of a workspace, the modules it requires directly and indirectly, and the replacements and lock file beside them.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "golang/version-declared@v1",
              "severity": "warning",
              "with": {
                  "projectDir": ".",
                  "minVersion": "1.21"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR
minVersionOldest Go version accepted. A declared version below this is a violation.1.21GUARDRAIL_INPUT_MINVERSION

How to fix ​

Declare the Go version the module builds against in go.mod:

go 1.22

go mod edit -go=1.22 writes it for you. Without the directive, the language version is whatever the toolchain defaults to, so a build can accept syntax on one runner and reject it on another. A module far below the floor is compiled by a toolchain that is no longer supported.

More in golang ​

  • golang/checksums-committed. The module commits go.sum, so every module a build downloads is verified against the checksum recorded in the commit.
  • golang/no-local-replacements. No replace directive points a module at a filesystem path, so the build only uses source that is in the checkout.
  • golang/toolchain-pinned. The module names the exact toolchain that compiles it, instead of leaving the go directive as a minimum version.

All 4 golang guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412