Go Dependency Security¶
Source: hooks/ways/softwaredev/code/supplychain/depscan/go/go.md
Frontmatter
| Field | Value |
|---|---|
description |
Go dependency security, govulncheck, module verification, replace directives |
vocabulary |
govulncheck go.sum go.mod replace directive go install go get module proxy checksum |
refire |
0.15 |
scope |
agent, subagent |
Scanning¶
# Official Go team tool — only reports vulns in code paths you actually call
govulncheck ./...
osv-scanner --lockfile=go.sum
Go-Specific Risks¶
replacedirectives ingo.modcan point dependencies to arbitrary local paths or forks. Check for unexpected replacements.go generateruns arbitrary commands.//go:generatecomments in source files execute whatever follows. Review before runninggo generate.- Go's checksum database (sum.golang.org) provides transparency — modules can't be silently changed after publication. This is a genuine supply chain advantage.
go installfrom a URL downloads and compiles in one step. Know the source.