‹ BackHN Continuity

Thread

Don't couple your Go code to GitHub

325 points · 177 comments · birdculture

  1. p4bl0 · · focus · HN ↗
    True, but beware of the domain name you're using. Because VeriSign may unilaterally decide to delete your domain name along with thousands of others [1] and you're back to square one…

    [1] <a href="https:&#x2F;&#x2F;neil.fraser.name&#x2F;news&#x2F;2026&#x2F;09&#x2F;03&#x2F;" rel="nofollow">https:&#x2F;&#x2F;neil.fraser.name&#x2F;news&#x2F;2026&#x2F;09&#x2F;03&#x2F;

    1. Groxx · · focus · HN ↗
      I broadly like Go&#x27;s &quot;the import is the hosted location (or a pointer to it)&quot; quite a lot, as it largely solves name-squatting and ownership and a lot more (while allowing major risks with domain sales&#x2F;abandonment), but yeah - I really do wish they baked a SHA into the go.mod (not just go.sum) so you could find a library and get a known-good download from any proxy with any name. A few languages now have content-addressed imports&#x2F;packages, instead of just adding hashes as verification, and I hope we see more in the future.

      Signed modules &#x2F; including the signature hash would also solve a lot, e.g. it&#x27;d mean domain sales no longer silently inherit full permissions. It&#x27;s sorta a shame that Go keeps doing such a good job at a minimum-viable wheel-rewrite, but then lets it linger for so long without catching up to the rest of the programming world.

      1. hnlmorg · · focus · HN ↗
        &gt; I really do wish they baked a SHA into the go.mod (not just go.sum) so you could find a library and get a known-good download from any proxy with any name.

        You already can use SHA in go.mod in exactly the same way you would use a version string.

        I don’t know about using multiple proxies in go mod though.

        1. Groxx · · focus · HN ↗
          Kinda. If there&#x27;s a versioned release at the same SHA, the next `go mod tidy` will replace it with the version.

          And while the go.sum file in a module is returned by proxy.golang.org (somewhat surprisingly), that only includes the module&#x27;s dependencies, not itself. So you&#x27;re still stuck trusting a goproxy to serve you the correct data.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.