| ▲ | p4bl0 a day ago |
| True, but beware of the domain name you're using. Because VeriSign may unilaterally decide to delete your domain name along with thousands of others [1] and you're back to square one… [1] https://neil.fraser.name/news/2026/09/03/ |
|
| ▲ | dolmen a day ago | parent | next [-] |
| Or if your goal is to open source code, think about the lifetime of the entity owning the domain: the source code might be of interest to users beyond the control of the domain name. Domain controled by an individual or a company? What if the domain is not renewed, or taken over by an hostile entity? Deepcopy [1] is a Go package that is still heavily used despite its creator has disappeared 9 years ago. At least GitHub is a stable and trusted host as a distribution point and communication point for users. [1]: https://pkg.go.dev/github.com/mohae/deepcopy |
|
| ▲ | Groxx a day ago | parent | prev | next [-] |
| I broadly like Go's "the import is the hosted location (or a pointer to it)" quite a lot, as it largely solves name-squatting and ownership and a lot more (while allowing major risks with domain sales/abandonment), but yeah - I really do wish they baked a SHA into the go.mod (not just go.sum) so you could find a library and get a known-good download from any proxy with any name. A few languages now have content-addressed imports/packages, instead of just adding hashes as verification, and I hope we see more in the future. Signed modules / including the signature hash would also solve a lot, e.g. it'd mean domain sales no longer silently inherit full permissions. It's sorta a shame that Go keeps doing such a good job at a minimum-viable wheel-rewrite, but then lets it linger for so long without catching up to the rest of the programming world. |
| |
| ▲ | hnlmorg 21 hours ago | parent | next [-] | | > I really do wish they baked a SHA into the go.mod (not just go.sum) so you could find a library and get a known-good download from any proxy with any name. You already can use SHA in go.mod in exactly the same way you would use a version string. I don’t know about using multiple proxies in go mod though. | | |
| ▲ | Groxx 9 hours ago | parent [-] | | Kinda. If there's a versioned release at the same SHA, the next `go mod tidy` will replace it with the version. And while the go.sum file in a module is returned by proxy.golang.org (somewhat surprisingly), that only includes the module's dependencies, not itself. So you're still stuck trusting a goproxy to serve you the correct data. |
| |
| ▲ | throwaway894345 a day ago | parent | prev [-] | | > It's sorta a shame that Go keeps doing such a good job at a minimum-viable wheel-rewrite, but then lets it linger for so long without catching up to the rest of the programming world. How many mainstream languages have content addressed imports? I can’t think of any, so I assume I’m misunderstanding your meaning of the term because you seem to be suggesting that it is common and Go is the outlier for lacking it? | | |
| ▲ | Groxx a day ago | parent [-] | | Go is not really an outlier for not having signed packages (there are a fair number that have it, but far from most)... but definitely stuck behind common accepted practice. By decades, if comparing against some (e.g. Java). Which keeps happening with stuff they rebuild from scratch - an excellent and somewhat unique first showing, far beyond what most first attempts manage, but followed by near-complete stagnation while issues that everyone familiar with the field predicted from miles away pile up. | | |
| ▲ | vips7L 18 hours ago | parent [-] | | Coming from the Java side this is typical of Google libraries. They start off impressive and gain wide adoption but then they stop supporting changes the community wants, missing basic features. | | |
| ▲ | Groxx 12 hours ago | parent | next [-] | | Yeah, it still very much tastes like Google in many of the worst ways :/ clearly Google isn't actually running the project, it's far too well run for that, but the same general "why would anyone need [that thing nearly the entire open source world does outside Google's monorepo]?" ignorance pervades a lot of it. Which is a shame because there is quite a lot to like about Go in practice. And in spite of it all I'm thrilled that it is eating into Python's share in a lot of places. | |
| ▲ | 12 hours ago | parent | prev [-] | | [deleted] |
|
|
|
|
|
| ▲ | ablob a day ago | parent | prev | next [-] |
| At least the fallout will be less if you have to resolve your custom domain differently in the intranet due to something like this. If github is "taken down" you can't just resolve the whole domain differently, you need to only resolve the packages differently. If your "Golang domain" is taken down, it should be a lot easier to hotfix until something proper is implemented (the quickest and dirtiest would be a hostfile-entry). |
|
| ▲ | cyh555 a day ago | parent | prev | next [-] |
| reading the article confuses me though I don't want to do the context switching by googling what 3rd level domain is about |
| |
| ▲ | hnarn 20 hours ago | parent [-] | | All you need to know is that for some reason you could buy foo.bar.com without owning bar.com directly from the registrar. It is being retired because very few people use it. It kind of sucks but this is how domains work, it’s not real estate. |
|
|
| ▲ | alavilli a day ago | parent | prev | next [-] |
| [flagged] |
|
| ▲ | 20 hours ago | parent | prev [-] |
| [deleted] |