Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cmd/go: remove module whitelist in favor of notary #30601

rsc opened this Issue Mar 5, 2019 · 1 comment


None yet
3 participants
Copy link

rsc commented Mar 5, 2019

I am going to check in to cmd/go a short whitelist of known hashes for popular modules, to let us understand a bit more of the impact of the notary providing expected hashes, before we have a notary available.

This issue is to remove that whitelist and associated TODOs.

@rsc rsc added this to the Go1.13 milestone Mar 5, 2019

@rsc rsc added the release-blocker label Mar 5, 2019


This comment has been minimized.

Copy link

gopherbot commented Mar 5, 2019

Change mentions this issue: cmd/go: add notary simulation and GONOVERIFY support

gopherbot pushed a commit that referenced this issue Mar 7, 2019

cmd/go: add notary simulation and GONOVERIFY support
As an experiment to better understand the impact of
having an authoritative source of truth for module hashes
before the real notary is available, this CL adds the basic
notary authorization checks using a partial whitelist of
known go.sum values for popular modules.

In addition to the temporary whitelist, this CL adds code
implementing $GONOVERIFY, a new 'go help modules-auth',
and clearer error messages for verification mismatches.

See #25530 for notary proposal.
Filed #30601 to remove whitelist when notary lands.

Change-Id: Ibcb6ac39c5e60455edf003d8c20af6932aeb7e88
Reviewed-by: Bryan C. Mills <>

@bcmills bcmills added the modules label Mar 7, 2019

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.