The controller imports mesh-host/validate through a replace onto the forge that holds it, and every build — the build agent's go build in a fresh toolchain container, the Dockerfile's go mod download — would have fetched it through the public proxy and checksum database at build time: a merge breaking main on the network, the class Phase 1 removes. vendor/ is committed; go builds from it with nothing fetched, and refuses to build when it and go.mod disagree, so a pin moved without go mod vendor fails at once. The Dockerfile copies vendor/ and builds with GOPROXY=off.
32 lines
1.3 KiB
AMPL
32 lines
1.3 KiB
AMPL
module github.com/novox/mesh-controller
|
|
|
|
go 1.26.0
|
|
|
|
require (
|
|
github.com/jackc/pgx/v5 v5.10.0
|
|
github.com/nats-io/nats.go v1.54.0
|
|
github.com/novox/mesh-host v0.0.0
|
|
golang.org/x/crypto v0.57.0
|
|
golang.org/x/net v0.58.0
|
|
)
|
|
|
|
require (
|
|
github.com/jackc/pgpassfile v1.0.0 // indirect
|
|
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
|
|
github.com/jackc/puddle/v2 v2.2.2 // indirect
|
|
github.com/klauspost/compress v1.20.0 // indirect
|
|
github.com/nats-io/nkeys v0.4.16 // indirect
|
|
github.com/nats-io/nuid v1.0.1 // indirect
|
|
golang.org/x/sync v0.23.0 // indirect
|
|
golang.org/x/sys v0.48.0 // indirect
|
|
golang.org/x/text v0.42.0 // indirect
|
|
)
|
|
|
|
// The node-engine's own validator (mesh-host/validate, novox/hq to-be 45 D1): one validator, the host's.
|
|
// The host's module path names no forge a build can fetch from, so the module is read from the one
|
|
// that holds it, at the host's commit — **once, by whoever moves the pin, into vendor/**, which is
|
|
// committed. Every build (the build agent's `go build`, the Dockerfile) compiles from vendor/ and
|
|
// fetches nothing; go refuses to build when vendor/ and this file disagree, so a pin moved without
|
|
// `go mod vendor` fails loudly, at once, everywhere.
|
|
replace github.com/novox/mesh-host => git.novox.be/novox/mesh-host v0.0.0-20261006081854-6953b5bafdb2
|