golang-dependency-management
Dependency management strategies for Golang projects — go.mod management, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, outdated dependency tracking, binary size analysis, Dependabot/Renovate setup, conflict resolution, and go.work workspaces.
供给资产档案
编程与开发 Agent
代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。
场景
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
适配 Agent
Claude Code + OpenAI Agents + CLI
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add samber/cc-skills-golang --skill golang-dependency-management
维护状态
新鲜
距上次推送 1 天
风险
需审查
Permission surface may require sandboxing
GitHub 质量
3.0K
82/100 质量 · 73/100 信任
覆盖标签
审查说明
Permission surface may require sandboxing · Financial research output is not financial advice; require human review before any live investment decision
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
强可靠的选择,值得加入生产工作流候选列表。
信任
仅限沙盒有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
安装前需人工审查
仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。
Stars
3.0K 个 GitHub Stars
仓库活跃度
3.0K 个 Star,197 个 Fork
维护状态
距上次推送 1 天
许可证
MIT
安装
npx skills add samber/cc-skills-golang --skill golang-dependency-management
安装安全性
标准软件包或运行时安装路径
权限范围
shell or command execution, filesystem or document access
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 已声明许可证
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- GitHub automation 工作流
- Claude Code 团队
- 重视 GitHub 采用信号的团队
- Inspect repository metadata
适用 Agent
安装决策
- 命令
- npx skills add samber/cc-skills-golang --skill golang-dependency-management
- 策略
- 审查
- 人工审查
- 是
信任与风险
- 信任
- 65/100
- 审计
- 82/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
安装命令
npx skills add samber/cc-skills-golang --skill golang-dependency-management不适用场景
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.
- 高风险权限提示:Shell 或命令执行
- Permission surface may require sandboxing
Agent 安全 v2
54/100 · 避免自动安装
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
- 高风险权限提示:Shell 或命令执行
- Permission surface may require sandboxing
安装目标
在你的 Agent 工作流中安装此 Skill
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install samber-golang-dependency-managementAgent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20golang-dependency-management%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20golang-dependency-management%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/samber-golang-dependency-management/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use golang-dependency-management in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20golang-dependency-management%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/samber-golang-dependency-management/install
Install command: npx skills add samber/cc-skills-golang --skill golang-dependency-management
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/samber-golang-dependency-management/install
LLM 文本格式
/api/skills/samber-golang-dependency-management/install?format=text
寻找替代方案
/api/skills/search?q=golang-dependency-management&limit=3
Agent 提示词
Use golang-dependency-management for this task. Review https://www.openagentskill.com/api/skills/samber-golang-dependency-management/install, then install with: npx skills add samber/cc-skills-golang --skill golang-dependency-managementRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Manifest
/api/registry/manifest/samber-golang-dependency-management
LLM 文本
/api/registry/manifest/samber-golang-dependency-management?format=text
安装别名
/api/registry/install/samber-golang-dependency-management
推荐
/api/registry/recommend?task=Use%20golang-dependency-management%20in%20an%20agent%20workflow&limit=3
适配 Agent
GitHub automation
平台
Claude Code, OpenAI Agents
Agent 决策面板
适合 GitHub automation 的首选
将其作为优先候选,再在你的 Agent 环境中验证 README 与安装路径。
栈中角色
首选
主要匹配
GitHub automation
信任标签
可用于生产
安装路径
命令已就绪
适用场景
- GitHub automation 工作流
- Claude Code 团队
- 重视 GitHub 采用信号的团队
证据
- 3,022 个 GitHub Stars
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 82/100 质量档案
- 11 个 OpenAgentSkill 交互事件
先审查
- The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
仅限沙盒
有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。
GitHub 采用度
通过3.0K 个 GitHub Stars
Star/Fork 活跃度
信息3.0K 个 Star,197 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过距上次推送 1 天
许可证清晰度
通过MIT
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 有意义的 GitHub 采用信号
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- The SKILL.md contains a truncated code block ending with 'go' that appears to be a typo or incomplete command.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- Permission surface: shell or command execution, filesystem or document access
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。
质量档案
强 适用于 Agent 工作流的候选
可靠的选择,值得加入生产工作流候选列表。
工作流匹配
在这些场景使用此 Skill
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Reduce risk
Security and compliance
I need my agent to scan a project for security risks and summarize what needs attention.
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
工作流匹配
加入完整工作流
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Design, build, test, and ship interfaces
Frontend and UI
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
概览
--- name: golang-dependency-management description: "Dependency management strategies for Golang projects — go.mod management, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, outdated dependency tracking, binary size analysis, Dependabot/Renovate setup, conflict resolution, and go.work workspaces. Use when adding, removing, or upgrading Go dependencies, auditing vulnerabilities, resolving version conflicts, or setting up automated dependency updates." user-invocable: true license: MIT compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang. metadata: author: samber version: "1.3.0" openclaw: emoji: "📦" homepage: https://github.com/samber/cc-skills-golang requires: bins: - go - govulncheck install: - kind: go package: golang.org/x/vuln/cmd/govulncheck@latest bins: [govulncheck] allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent Bash(govulncheck:*) AskUserQuestion ---
**Persona:** You are a Go dependency steward. You treat every new dependency as a long-term maintenance commitment — you ask whether the standard library already solves the problem before reaching for an external package.
**Dependencies:**
- govulncheck: `go install golang.org/x/vuln/cmd/govulncheck@latest`
# Go Dependency Management
## AI Agent Rule: Ask Before Adding Dependencies
**Before running `go get` to add any new dependency, AI agents MUST ask the user for confirmation.** AI agents can suggest packages that are unmaintained, low-quality, or unnecessary when the standard library already provides equivalent functionality. Using `go get -u` to upgrade an existing dependency is safe.
Before proposing a dependency, evaluate:
- Does the standard library already cover the use case? - Is the license compatible? - Are there well-known alternatives? - What it does and why it's needed?
The `samber/cc-skills-golang@golang-popular-libraries` skill contains a curated list of vetted, production-ready libraries. Prefer recommending packages from that list. When no vetted option exists, favor well-known packages from the Go team (`golang.org/x/...`) or established organizations over obscure alternatives.
## Key Rules
- `go.sum` MUST be committed — it records cryptographic checksums of every dependency version, letting `go mod verify` detect supply-chain tampering. Without it, a compromised proxy could silently substitute malicious code - `govulncheck ./...` or `go tool govulncheck ./...` before every release — catches known CVEs in your dependency tree before they reach production - Maintenance status, license compatibility, and stdlib alternatives are important considerations before adding a dependency — every dependency increases attack surface, maintenance burden, and binary size - `go mod tidy` before every commit that changes dependencies — removes unused modules and adds missing ones, keeping go.mod honest
## go.mod & go.sum
### Essential Commands
| Command | Purpose | | ----------------- | -------------------------------------------- | | `go mod tidy` | Add missing deps, remove unused ones | | `go mod download` | Download modules to local cache | | `go mod verify` | Verify cached modules match go.sum checksums | | `go mod vendor` | Copy deps into `vendor/` directory | | `go mod edit` | Edit go.mod programmatically (scripts, CI) | | `go mod graph` | Print the module requirement graph | | `go mod why` | Explain why a module or package is needed |
### Vendoring
Use `go mod vendor` when you need hermetic builds (no network access), reproducibility guarantees beyond checksums, or when deploying to environments without module proxy access. CI pipelines and Docker builds sometimes benefit from vendoring. Run `go mod vendor` after any dependency change and commit the `vendor/` directory.
## Installing & Upgrading Dependencies
### Adding a Dependency
```bash go get github.com/google/uuid # Latest version go get github.com/google/uuid@v1.6.0 # Specific version go get github.com/google/uuid@latest # Explicitly latest go get github.com/google/uuid@<commit> # Specific commit (pseudo-version) ```
Before pinning a version, inspect the module's available versions, importers, and known vulnerabilities on pkg.go.dev → See `samber/cc-skills-golang@golang-pkg-go-dev` skill.
### Upgrading
```bash go get -u ./... # Upgrade ALL direct+indirect deps to latest minor/patch go get -u=patch ./... # Upgrade to latest patch only (safer) go get github.com/pkg@v1.5 # Upgrade specific package ```
**Prefer `go get -u=patch`** for routine updates. Patch and minor updates are usually lower risk than major upgrades, but still require review. For dependency updates, run:
```bash go get -u=patch ./... go mod tidy go test ./... go vet ./... govulncheck ./... # or: go tool govulncheck ./... ```
Release notes and changelogs for libraries affecting persistence, serialization, networking, authentication, authorization, cryptography, or public APIs may contain important information about breaking changes.
### Removing a Dependency
```bash go get github.com/google/uuid@none # Mark for removal go mod tidy # Clean up go.mod and go.sum ```
### Installing CLI Tools
For Go 1.24+ modules, pin executable tools in `go.mod` with `tool` directives. Do not create a new `tools.go` blank-import file unless the module must support Go <1.24.
```bash # Add tools to the current module. go get -tool github.com/golangci/golangci-lint/v2/cmd/golangci-lint@latest go get -tool golang.org/x/vuln/cmd/govulncheck@latest go get -tool golang.org/x/perf/cmd/benchstat@latest
# Run pinned tools reproducibly. go tool golangci-lint run ./... go tool govulncheck ./... go tool benchstat old.txt new.txt
# Install all module-pinned tools into GOBIN/PATH when needed. go install tool
# Update pinned tools deliberately, then review go.mod/go.sum. go get -u tool go mod tidy ```
`go.mod` shape for a module targeting Go 1.26 or newer. This is an example target, not a cap; keep the project's actual `go` directive and do not change it just to add tools.
```go.mod module example.com/project
go 1.26
tool ( github.com/golangci/golangci-lint/v2/cmd/golangci-lint golang.org/x/vuln/cmd/govulncheck golang.org/x/perf/cmd/benchstat ) ```
For Go <1.24 only, use the legacy `tools.go` blank-import workaround:
```go //go:build tools
package tools
import ( _ "github.com/golangci/golangci-lint/v2/cmd/golangci-lint" _ "golang.org/x/vuln/cmd/govulncheck" ) ```
Rule: Go 1.24+ = `tool` directives. Go <1.24 = `tools.go` fallback.
### Go 1.26+ module target note
When using a Go 1.26 or newer toolchain, `go mod init` may create a module with an older default `go` directive. If the project intentionally targets Go 1.26+ APIs, update the directive deliberately:
```bash go mod edit -go=1.26 go mod tidy ```
For future Go versions, use the project's intended target version. Do not use APIs newer than the module's `go` directive until the project explicitly agrees to upgrade it.
## Deep Dives
- **[Versioning & MVS](./references/versioning.md)** — Semantic versioning rules (major.minor.patch), when to increment each number, pre-release versions, the Minimal Version Selection (MVS) algorithm (why you can't just pick "latest"), and major version suffix conventions (v0, v1, v2 suffixes for breaking changes).
- **[Auditing Dependencies](./references/auditing.md)** — Vulnerability scanning with `govulncheck`, tracking outdated dependencies, analyzing which dependencies make the binary large (`goweight`), and distinguishing test-only vs binary dependencies to keep `go.mod` clean.
- **[Dependency Conflicts & Resolution](./references/conflicts.md)** — Diagnosing version conflicts (what `go get` does when you request incompatible versions), resolution strategies (`replace` directives for local development, `exclude` for broken versions, `retract` for published versions that should be skipped), and workflows for conflicts across your dependency tree.
- **[Go Workspaces](./references/workspaces.md)** — `go.work` files for multi-module development (e.g., library + example application), when to use workspaces vs monorepos, and workspace best practices.
- **[Automated Dependency Updates](./references/automated-updates.md)** — Setting up Dependabot or Renovate for automatic dependency update PRs, auto-merge strategies (when to merge automatically vs require review), and handling security updates.
- **[Visualizing the Dependency Graph](./references/visualization.md)** — `go mod graph` to inspect the full dependency tree, `modgraphviz` to visualize it, and interactive tools to find which dependency chains cause bloat.
## Cross-References
- → See `samber/cc-skills-golang@golang-continuous-integration` skill for Dependabot/Renovate CI setup - → See `samber/cc-skills-golang@golang-security` skill for vulnerability scanning with govulncheck - → See `samber/cc-skills-golang@golang-popular-libraries` skill for vetted library recommendations
## Quick Reference
```bash # Start a new module go mod init github.com/user/project
# Add a dependency go get github.com/google/uuid@v1.6.0
# Upgrade all deps (patch only, safer) go get -u=patch ./...
# Remove unused deps go mod tidy
# Check for vulnerabilities govulncheck ./... # or: go tool govulncheck ./...
# Check for outdated deps go list -u -m -json all | go-mod-outdated -update -direct
# Analyze binary size by dependency goweight
# Understand why a dep exists go mod why -m github.com/some/module
# Visualize dependency graph go mod graph | modgraphviz | dot -Tpng -o deps.png
# Verify checksums go mod verify ```
技术详情
- 版本
- 1.0.0
- 许可证
- MIT
- 最近更新
- 2026年8月21日
- 发布时间
- 2026年8月21日
决策摘要
首选
3,022 个 GitHub Stars
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 golang-dependency-management 准备的场景化草稿,可手动发布到 X。
golang-dependency-management: Dependency management strategies for Golang projects — go.mod management, installing/upgradin... 3.0K stars https://www.openagentskill.com/skills/samber-golang-dependency-management?ref=x
可选:带安装命令的回复
Listing + install path for golang-dependency-management: https://www.openagentskill.com/skills/samber-golang-dependency-management?ref=x Install: npx skills add samber/cc-skills-golang --skill golang-dependency-management
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- samber
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 samber,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/samber-golang-dependency-management)
[](https://www.openagentskill.com/skills/samber-golang-dependency-management)
[](https://www.openagentskill.com/skills/samber-golang-dependency-management/audit)
[](https://www.openagentskill.com/skills/samber-golang-dependency-management)作者
samber
@samber
健康信号
- GitHub Stars
- 3.0K
- 质量评分
- 48/100
- 最近 GitHub 推送
- 2026年8月21日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 11
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
仅限沙盒
- GitHub 采用度3.0K 个 GitHub Stars通过
- Star/Fork 活跃度3.0K 个 Star,197 个 Fork; 当前元数据中没有议题活跃度信息信息
- 近期维护距上次推送 1 天通过
- 许可证清晰度MIT通过
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险command execution surface, external package install surface信息
相关 Skill
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Stars