The controller imports mesh-host/validate through a replace onto the forge that holds it, and every build — the build agent's go build in a fresh toolchain container, the Dockerfile's go mod download — would have fetched it through the public proxy and checksum database at build time: a merge breaking main on the network, the class Phase 1 removes. vendor/ is committed; go builds from it with nothing fetched, and refuses to build when it and go.mod disagree, so a pin moved without go mod vendor fails at once. The Dockerfile copies vendor/ and builds with GOPROXY=off.
25 lines
704 B
AMPL
25 lines
704 B
AMPL
module github.com/nats-io/nats.go
|
|
|
|
go 1.26.0
|
|
|
|
require (
|
|
github.com/golang/protobuf v1.5.4
|
|
github.com/klauspost/compress v1.20.0
|
|
github.com/nats-io/jwt/v2 v2.8.2
|
|
github.com/nats-io/nkeys v0.4.16
|
|
github.com/nats-io/nuid v1.0.1
|
|
github.com/synadia-io/orbit.go/ntf v0.0.1
|
|
github.com/synadia-io/orbit.go/ntf-client v0.0.3
|
|
google.golang.org/protobuf v1.36.12
|
|
)
|
|
|
|
require (
|
|
github.com/antithesishq/antithesis-sdk-go v0.8.0 // indirect
|
|
github.com/google/go-tpm v0.9.8 // indirect
|
|
github.com/minio/highwayhash v1.0.4 // indirect
|
|
github.com/nats-io/nats-server/v2 v2.15.0 // indirect
|
|
golang.org/x/crypto v0.57.0 // indirect
|
|
golang.org/x/sys v0.48.0 // indirect
|
|
golang.org/x/time v0.16.0 // indirect
|
|
)
|