golang-dependency-management

Revoir · 65
Indexé dans Registry

Dependency management strategies for Golang projects — go.mod management, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, outdated dependency tracking, binary size analysis, Dependabot/Renovate setup, conflict resolution, and go.work workspaces.

Verified installs0
Stars3.0K
Version1.0.0
Qualité82/100 · Solide
Confiance65/100 · Sandbox uniquement
Audit82/100 · Revue nécessaire

Profil de l’actif

Agents de code et de développement

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Voir la catégorie

Scénario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Adéquation Agent

Claude Code + OpenAI Agents + CLI

Compatible avec Codex, Claude Code, Cursor, CLI ou des Agents personnalisés.

Installer

Prêt

npx skills add samber/cc-skills-golang --skill golang-dependency-management

Maintenance

À jour

1 jours depuis le dernier push

Risque

Revue nécessaire

Permission surface may require sandboxing

Qualité GitHub

3.0K

82/100 Qualité · 73/100 Confiance

Tags de couverture

CodingGitHub automationSécuritéagent-skill

Notes de revue

Permission surface may require sandboxing · Financial research output is not financial advice; require human review before any live investment decision

Carte d’adoption Agent

Confiance, audit et préparation à l’installation en un coup d’œil

Ces scores combinent les métadonnées publiques du dépôt, les signaux de revue OpenAgentSkill, la fraîcheur de maintenance et la préparation à l’installation. Ils servent à présélectionner et ne remplacent pas la revue humaine.

Qualité

Solide
82

Solid option that is likely worth shortlisting for production workflows.

Confiance

Sandbox uniquement
65

Candidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.

Audit

Revue nécessaire
82

Revue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.

Trust Score OpenAgentSkill v5

Revue humaine avant installation

Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

3.0K stars GitHub

Activité du dépôt

3.0K stars et 197 forks

Maintenance

1 jours depuis le dernier push

Licence

MIT

Installer

npx skills add samber/cc-skills-golang --skill golang-dependency-management

Sécurité d’installation

Chemin d’installation standard de package ou runtime

Surface de permissions

shell or command execution, filesystem or document access

Résultats Agent

Pas encore de données de résultats Agent

Documentation

Contexte README/SKILL.md solide

Résumé des risques

Revoir avant production

  • The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access

Préparation à l’installation

Chemin d’installation disponible

  • Le chemin d’installation est disponible
  • La preuve du dépôt est disponible
  • La licence est déclarée
  • Pas encore de preuve de résultat Agent-Proven

Métadonnées lisibles par Agent

Données de décision lisibles par machine pour ce skill.

Utilisez ce bloc ou le JSON intégré pour décider si un Agent doit installer ce skill, choisir une alternative ou demander d’abord une revue humaine.

Ouvrir JSON

Tâches adaptées

  • workflows GitHub automation
  • Équipes Claude Code
  • Équipes qui valorisent les signaux d’adoption GitHub
  • Inspect repository metadata

Agents adaptés

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

Décision d’installation

Commande
npx skills add samber/cc-skills-golang --skill golang-dependency-management
Politique
Revoir
Revue humaine
Oui

Confiance et risque

Confiance
65/100
Audit
82/100
Niveau de risque
Revue nécessaire

Boucle de résultat

Endpoint
/api/agent/outcome
ID d’événement
resolve
Résultats
5

Commande d’installation

npx skills add samber/cc-skills-golang --skill golang-dependency-management

Ne pas utiliser quand

  • Équipes qui nécessitent un SLA soutenu par le fournisseur
  • production agents without a repository review
  • The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.
  • Indices de permissions à haut risque : exécution shell ou de commande
  • Permission surface may require sandboxing

Sécurité Agent v2

54/100 · Éviter l’installation automatique

ExpérimentalRevoir

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Résoudre via API

Élevé

Exécution shell ou de commande

Les métadonnées de la skill font référence à des workflows de terminal, CLI, shell, sous-processus ou exécution de commande.

Moyen

Accès réseau

La skill récupère probablement des pages distantes, API, dépôts ou services externes.

Moyen

Accès au système de fichiers

La skill peut lire ou écrire des fichiers de projet, documents, artefacts générés ou l’état local de l’espace de travail.

  • Indices de permissions à haut risque : exécution shell ou de commande
  • Permission surface may require sandboxing

Cibles d’installation

Installer ce skill dans votre workflow Agent

Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install samber-golang-dependency-management

Plan de résolution Agent

Laissez un Agent vérifier la pertinence avant l’installation.

L’API Resolve renvoie la skill sélectionnée, des alternatives, la politique de sécurité, les notes d’audit, la cible d’installation et un prompt prêt à l’emploi.

Ouvrir le plan texte

L’Agent doit vérifier

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copier le prompt

Task: Use golang-dependency-management in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20golang-dependency-management%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/samber-golang-dependency-management/install
Install command: npx skills add samber/cc-skills-golang --skill golang-dependency-management
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Relais Agent

Donnez à l’Agent le chemin d’installation, pas un autre annuaire.

Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.

Ouvrir l’API d’installation

Prompt Agent

Use golang-dependency-management for this task. Review https://www.openagentskill.com/api/skills/samber-golang-dependency-management/install, then install with: npx skills add samber/cc-skills-golang --skill golang-dependency-management

Métadonnées Registry

Profil lisible par Agent pour la sélection automatique de skills.

L’API Registry fournit les signaux de décision, confiance, audit, cas d’usage et installation sans analyser l’interface.

Ouvrir Manifest

Adéquation Agent

96/100

GitHub automation

Plateformes

Claude Code, OpenAI Agents

Rapport d’audit

Revue nécessaire · 82/100

Revue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.

Voir le rapport d’auditVoir le rapport d’évaluation

Panneau de décision Agent

Choix principal pour GitHub automation

Use this as a leading candidate, then validate the README and install path in your own agent stack.

96
Préparation
Adopter
Étape

Rôle dans la pile

Choix principal

Pertinence principale

GitHub automation

Libellé de confiance

Prêt pour la production

Chemin d’installation

Commande prête

À utiliser lorsque

  • workflows GitHub automation
  • Équipes Claude Code
  • Équipes qui valorisent les signaux d’adoption GitHub

Preuves

  • 3,022 stars GitHub
  • recent repository activity
  • install command or GitHub repo available
  • profil qualité 82/100
  • 11 événements OpenAgentSkill

revoir d’abord

  • The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.

Chemin d’implémentation

  1. 1Installez-le dans un Agent en sandbox et exécutez une tâche de GitHub automation de bout en bout.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Profil de confiance

Sandbox uniquement

Candidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.

65
Trust Score OpenAgentSkill

Adoption GitHub

Validé

3.0K stars GitHub

Activité stars/forks

Info

3.0K stars et 197 forks; l’activité des issues n’est pas disponible dans les métadonnées actuelles

Maintenance récente

Validé

1 jours depuis le dernier push

Clarté de licence

Validé

MIT

Signaux positifs

  • Revue IA approuvée
  • Le chemin d’installation est disponible
  • La preuve du dépôt est disponible
  • Dépôt maintenu récemment
  • Signal d’adoption GitHub significatif
  • La commande d’installation ne présente aucun motif de haut risque évident
  • La boucle de résultats est prête mais nécessite la première exécution réelle de l’Agent

Réviser avant installation

  • The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • Permission surface: shell or command execution, filesystem or document access
  • Pas encore de rapports de résultats Agent réels
  • Une revue humaine est requise avant une installation sans surveillance

Action recommandée

Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.

Profil qualité

Solide candidat pour les workflows Agent

Solid option that is likely worth shortlisting for production workflows.

82
Stars GitHub
3.0K
Actualité
il y a 1 jours
Prêt à installer
Oui
Licence
MIT
Réviser avant installation: The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.

Adéquation au workflow

Utilisez cette skill dans ces scénarios

Adéquation au workflow

Ajouter à un workflow complet

Liste d’alternatives

Comparer avant installation

Similar skills that may fit this task.

Tout comparer

Vue d’ensemble

--- name: golang-dependency-management description: "Dependency management strategies for Golang projects — go.mod management, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, outdated dependency tracking, binary size analysis, Dependabot/Renovate setup, conflict resolution, and go.work workspaces. Use when adding, removing, or upgrading Go dependencies, auditing vulnerabilities, resolving version conflicts, or setting up automated dependency updates." user-invocable: true license: MIT compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang. metadata: author: samber version: "1.3.0" openclaw: emoji: "📦" homepage: https://github.com/samber/cc-skills-golang requires: bins: - go - govulncheck install: - kind: go package: golang.org/x/vuln/cmd/govulncheck@latest bins: [govulncheck] allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent Bash(govulncheck:*) AskUserQuestion ---

**Persona:** You are a Go dependency steward. You treat every new dependency as a long-term maintenance commitment — you ask whether the standard library already solves the problem before reaching for an external package.

**Dependencies:**

- govulncheck: `go install golang.org/x/vuln/cmd/govulncheck@latest`

# Go Dependency Management

## AI Agent Rule: Ask Before Adding Dependencies

**Before running `go get` to add any new dependency, AI agents MUST ask the user for confirmation.** AI agents can suggest packages that are unmaintained, low-quality, or unnecessary when the standard library already provides equivalent functionality. Using `go get -u` to upgrade an existing dependency is safe.

Before proposing a dependency, evaluate:

- Does the standard library already cover the use case? - Is the license compatible? - Are there well-known alternatives? - What it does and why it's needed?

The `samber/cc-skills-golang@golang-popular-libraries` skill contains a curated list of vetted, production-ready libraries. Prefer recommending packages from that list. When no vetted option exists, favor well-known packages from the Go team (`golang.org/x/...`) or established organizations over obscure alternatives.

## Key Rules

- `go.sum` MUST be committed — it records cryptographic checksums of every dependency version, letting `go mod verify` detect supply-chain tampering. Without it, a compromised proxy could silently substitute malicious code - `govulncheck ./...` or `go tool govulncheck ./...` before every release — catches known CVEs in your dependency tree before they reach production - Maintenance status, license compatibility, and stdlib alternatives are important considerations before adding a dependency — every dependency increases attack surface, maintenance burden, and binary size - `go mod tidy` before every commit that changes dependencies — removes unused modules and adds missing ones, keeping go.mod honest

## go.mod & go.sum

### Essential Commands

| Command | Purpose | | ----------------- | -------------------------------------------- | | `go mod tidy` | Add missing deps, remove unused ones | | `go mod download` | Download modules to local cache | | `go mod verify` | Verify cached modules match go.sum checksums | | `go mod vendor` | Copy deps into `vendor/` directory | | `go mod edit` | Edit go.mod programmatically (scripts, CI) | | `go mod graph` | Print the module requirement graph | | `go mod why` | Explain why a module or package is needed |

### Vendoring

Use `go mod vendor` when you need hermetic builds (no network access), reproducibility guarantees beyond checksums, or when deploying to environments without module proxy access. CI pipelines and Docker builds sometimes benefit from vendoring. Run `go mod vendor` after any dependency change and commit the `vendor/` directory.

## Installing & Upgrading Dependencies

### Adding a Dependency

```bash go get github.com/google/uuid # Latest version go get github.com/google/uuid@v1.6.0 # Specific version go get github.com/google/uuid@latest # Explicitly latest go get github.com/google/uuid@<commit> # Specific commit (pseudo-version) ```

Before pinning a version, inspect the module's available versions, importers, and known vulnerabilities on pkg.go.dev → See `samber/cc-skills-golang@golang-pkg-go-dev` skill.

### Upgrading

```bash go get -u ./... # Upgrade ALL direct+indirect deps to latest minor/patch go get -u=patch ./... # Upgrade to latest patch only (safer) go get github.com/pkg@v1.5 # Upgrade specific package ```

**Prefer `go get -u=patch`** for routine updates. Patch and minor updates are usually lower risk than major upgrades, but still require review. For dependency updates, run:

```bash go get -u=patch ./... go mod tidy go test ./... go vet ./... govulncheck ./... # or: go tool govulncheck ./... ```

Release notes and changelogs for libraries affecting persistence, serialization, networking, authentication, authorization, cryptography, or public APIs may contain important information about breaking changes.

### Removing a Dependency

```bash go get github.com/google/uuid@none # Mark for removal go mod tidy # Clean up go.mod and go.sum ```

### Installing CLI Tools

For Go 1.24+ modules, pin executable tools in `go.mod` with `tool` directives. Do not create a new `tools.go` blank-import file unless the module must support Go <1.24.

```bash # Add tools to the current module. go get -tool github.com/golangci/golangci-lint/v2/cmd/golangci-lint@latest go get -tool golang.org/x/vuln/cmd/govulncheck@latest go get -tool golang.org/x/perf/cmd/benchstat@latest

# Run pinned tools reproducibly. go tool golangci-lint run ./... go tool govulncheck ./... go tool benchstat old.txt new.txt

# Install all module-pinned tools into GOBIN/PATH when needed. go install tool

# Update pinned tools deliberately, then review go.mod/go.sum. go get -u tool go mod tidy ```

`go.mod` shape for a module targeting Go 1.26 or newer. This is an example target, not a cap; keep the project's actual `go` directive and do not change it just to add tools.

```go.mod module example.com/project

go 1.26

tool ( github.com/golangci/golangci-lint/v2/cmd/golangci-lint golang.org/x/vuln/cmd/govulncheck golang.org/x/perf/cmd/benchstat ) ```

For Go <1.24 only, use the legacy `tools.go` blank-import workaround:

```go //go:build tools

package tools

import ( _ "github.com/golangci/golangci-lint/v2/cmd/golangci-lint" _ "golang.org/x/vuln/cmd/govulncheck" ) ```

Rule: Go 1.24+ = `tool` directives. Go <1.24 = `tools.go` fallback.

### Go 1.26+ module target note

When using a Go 1.26 or newer toolchain, `go mod init` may create a module with an older default `go` directive. If the project intentionally targets Go 1.26+ APIs, update the directive deliberately:

```bash go mod edit -go=1.26 go mod tidy ```

For future Go versions, use the project's intended target version. Do not use APIs newer than the module's `go` directive until the project explicitly agrees to upgrade it.

## Deep Dives

- **[Versioning & MVS](./references/versioning.md)** — Semantic versioning rules (major.minor.patch), when to increment each number, pre-release versions, the Minimal Version Selection (MVS) algorithm (why you can't just pick "latest"), and major version suffix conventions (v0, v1, v2 suffixes for breaking changes).

- **[Auditing Dependencies](./references/auditing.md)** — Vulnerability scanning with `govulncheck`, tracking outdated dependencies, analyzing which dependencies make the binary large (`goweight`), and distinguishing test-only vs binary dependencies to keep `go.mod` clean.

- **[Dependency Conflicts & Resolution](./references/conflicts.md)** — Diagnosing version conflicts (what `go get` does when you request incompatible versions), resolution strategies (`replace` directives for local development, `exclude` for broken versions, `retract` for published versions that should be skipped), and workflows for conflicts across your dependency tree.

- **[Go Workspaces](./references/workspaces.md)** — `go.work` files for multi-module development (e.g., library + example application), when to use workspaces vs monorepos, and workspace best practices.

- **[Automated Dependency Updates](./references/automated-updates.md)** — Setting up Dependabot or Renovate for automatic dependency update PRs, auto-merge strategies (when to merge automatically vs require review), and handling security updates.

- **[Visualizing the Dependency Graph](./references/visualization.md)** — `go mod graph` to inspect the full dependency tree, `modgraphviz` to visualize it, and interactive tools to find which dependency chains cause bloat.

## Cross-References

- → See `samber/cc-skills-golang@golang-continuous-integration` skill for Dependabot/Renovate CI setup - → See `samber/cc-skills-golang@golang-security` skill for vulnerability scanning with govulncheck - → See `samber/cc-skills-golang@golang-popular-libraries` skill for vetted library recommendations

## Quick Reference

```bash # Start a new module go mod init github.com/user/project

# Add a dependency go get github.com/google/uuid@v1.6.0

# Upgrade all deps (patch only, safer) go get -u=patch ./...

# Remove unused deps go mod tidy

# Check for vulnerabilities govulncheck ./... # or: go tool govulncheck ./...

# Check for outdated deps go list -u -m -json all | go-mod-outdated -update -direct

# Analyze binary size by dependency goweight

# Understand why a dep exists go mod why -m github.com/some/module

# Visualize dependency graph go mod graph | modgraphviz | dot -Tpng -o deps.png

# Verify checksums go mod verify ```

Détails techniques

Version
1.0.0
Licence
MIT
Dernière mise à jour
21 août 2026
Publié
21 août 2026

Instantané de décision

Choix principal

96
Prêt
Adopter
Étape

3,022 stars GitHub

Audit

Revue d’installation

Revue d’installation et d’adoption

82
Revue nécessaire
Sécurité
76/100
Maintenance
100/100
Installer
92/100
Ouvrir l’audit completVoir le rapport d’évaluation

Preuves validées par Agent

Preuves validées par Agent

Rapports après resolve, revue, installation et une exécution limitée.

0
Validé
Needs first agent runAuto-installation: revoir d’abordDernier: Inconnu
Taux de réussite
Échec récent
Résultats
0
Qualité de sortie
Échecs
0
Non pertinent
0
Installations
0
Bloqué par le risque
0
Configuration requise
0
Production
0

Aucune donnée de résultat Agent pour l’instant. La première exécution peut signaler succès, besoin de configuration, blocage de risque, échec ou non-pertinence via /api/agent/outcome.

Installer

Ajouter au workflow Agent

Gratuit et open source. Examinez le rapport avant l’installation dans des Agents de production.

Boucle de croissance

Kit de partage

X

Brouillon guidé par scénario pour golang-dependency-management, prêt pour une publication manuelle sur X.

Note du curateur
golang-dependency-management: Dependency management strategies for Golang projects — go.mod management, installing/upgradin...

3.0K stars

https://www.openagentskill.com/skills/samber-golang-dependency-management?ref=x
Ouvrir le brouillon X
Réponse facultative avec commande d’installation
Listing + install path for golang-dependency-management:
https://www.openagentskill.com/skills/samber-golang-dependency-management?ref=x

Install: npx skills add samber/cc-skills-golang --skill golang-dependency-management

Source de la fiche

Indexé par Registry

Revendiable

Cette fiche a été indexée à partir de sources publiques et n’est pas marquée officielle tant qu’une revendication de mainteneur n’est pas approuvée.

Créateur
samber
Indexé par
Index communautaire OpenAgentSkill

L’attribution renvoie au dépôt public ou au profil du créateur. Les créateurs peuvent revendiquer la fiche pour mettre à jour les signaux de propriété.

Revendiquer ce skill

Revendication du propriétaire

Revendiquer cette fiche de skill

Cette fiche Indexé par Registry est attribuée à samber, mais n’est pas encore marquée officielle. Revendiquez-la pour ajouter un signal de propriétaire vérifié et rendre les futures mises à jour de lancement, d’installation et d’audit plus fiables.

Kit de backlinks créateur

Ajoutez les badges de preuve à votre README

Affichez la fiche canonique, les signaux actuels de confiance et d’audit, ainsi que de vraies preuves Agent-Proven là où les développeurs évaluent le dépôt.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/samber-golang-dependency-management?metric=listed&label=Listed)](https://www.openagentskill.com/skills/samber-golang-dependency-management)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/samber-golang-dependency-management?metric=trust&label=Trust)](https://www.openagentskill.com/skills/samber-golang-dependency-management)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/samber-golang-dependency-management?metric=audit&label=Audit)](https://www.openagentskill.com/skills/samber-golang-dependency-management/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/samber-golang-dependency-management?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/samber-golang-dependency-management)

Auteur

S

samber

@samber

Adéquation plateforme

Signaux de santé

Stars GitHub
3.0K
Score de qualité
48/100
Dernier push GitHub
21 août 2026
Indications de framework
Inconnu
Vues OpenAgentSkill
11
Copies d’installation
0
Clics sortants
0

Signal de communauté

Indiquez si ce skill semble utile à votre workflow Agent. Les retours agrégés améliorent le classement au fil du temps.

Confiance et sécurité

Sandbox uniquement

65
  • Adoption GitHub3.0K stars GitHubValidé
  • Activité stars/forks3.0K stars et 197 forks; l’activité des issues n’est pas disponible dans les métadonnées actuellesInfo
  • Maintenance récente1 jours depuis le dernier pushValidé
  • Clarté de licenceMITValidé
  • Complétude README/SKILL.mdLes métadonnées incluent suffisamment de contexte d’usage et de workflowValidé
  • Risque dépendances/runtimecommand execution surface, external package install surfaceInfo