The controller imports mesh-host/validate through a replace onto the forge that holds it, and every build — the build agent's go build in a fresh toolchain container, the Dockerfile's go mod download — would have fetched it through the public proxy and checksum database at build time: a merge breaking main on the network, the class Phase 1 removes. vendor/ is committed; go builds from it with nothing fetched, and refuses to build when it and go.mod disagree, so a pin moved without go mod vendor fails at once. The Dockerfile copies vendor/ and builds with GOPROXY=off.
9 lines
276 B
TOML
9 lines
276 B
TOML
[tools]
|
|
go = '1.26.3'
|
|
"go:github.com/go-critic/go-critic/cmd/gocritic" = "latest"
|
|
"go:github.com/gordonklaus/ineffassign" = "latest"
|
|
"go:github.com/mdempsky/unconvert" = "latest"
|
|
"go:golang.org/x/tools/cmd/goimports" = "latest"
|
|
"go:mvdan.cc/gofumpt" = "latest"
|
|
ruby = '4.0.4'
|