True, but beware of the domain name you're using. Because VeriSign may unilaterally decide to delete your domain name along with thousands of others [1] and you're back to square one…
I broadly like Go's "the import is the hosted location (or a pointer to it)" quite a lot, as it largely solves name-squatting and ownership and a lot more (while allowing major risks with domain sales/abandonment), but yeah - I really do wish they baked a SHA into the go.mod (not just go.sum) so you could find a library and get a known-good download from any proxy with any name. A few languages now have content-addressed imports/packages, instead of just adding hashes as verification, and I hope we see more in the future.
Signed modules / including the signature hash would also solve a lot, e.g. it'd mean domain sales no longer silently inherit full permissions. It's sorta a shame that Go keeps doing such a good job at a minimum-viable wheel-rewrite, but then lets it linger for so long without catching up to the rest of the programming world.
> I really do wish they baked a SHA into the go.mod (not just go.sum) so you could find a library and get a known-good download from any proxy with any name.
You already can use SHA in go.mod in exactly the same way you would use a version string.
I don’t know about using multiple proxies in go mod though.
Kinda. If there's a versioned release at the same SHA, the next `go mod tidy` will replace it with the version.
And while the go.sum file in a module is returned by proxy.golang.org (somewhat surprisingly), that only includes the module's dependencies, not itself. So you're still stuck trusting a goproxy to serve you the correct data.
p4bl0 · · focus · HN ↗
[1] <a href="https://neil.fraser.name/news/2026/09/03/" rel="nofollow">https://neil.fraser.name/news/2026/09/03/
Groxx · · focus · HN ↗
Signed modules / including the signature hash would also solve a lot, e.g. it'd mean domain sales no longer silently inherit full permissions. It's sorta a shame that Go keeps doing such a good job at a minimum-viable wheel-rewrite, but then lets it linger for so long without catching up to the rest of the programming world.
hnlmorg · · focus · HN ↗
You already can use SHA in go.mod in exactly the same way you would use a version string.
I don’t know about using multiple proxies in go mod though.
Groxx · · focus · HN ↗
And while the go.sum file in a module is returned by proxy.golang.org (somewhat surprisingly), that only includes the module's dependencies, not itself. So you're still stuck trusting a goproxy to serve you the correct data.