mirror of
https://github.com/luxfi/utils.git
synced 2026-07-26 22:49:03 +00:00
main
Chasing these one at a time was whack-a-mole — every repair surfaced the next moved tag (age, pq, threshold, zap, consensus, constants, sdk, keys…). This is the systematic pass instead: every distinct luxfi/hanzoai module@version in the workspace (692 of them) was resolved against proxy.golang.org + a direct fetch, and any go.sum line disagreeing with what is actually served was corrected. Not an attack, and checked rather than assumed: for each case the proxy and a direct fetch AGREE with each other and differ from the recorded hash. Two independent transports agreeing means nothing is rewriting bytes in flight — the tags moved at source. sum.golang.org still holds the original, but GOPRIVATE covers github.com/luxfi/* with GOSUMDB=off, so our own modules never consult the checksum DB and a moved tag splits consumers silently instead of failing at publish time. Only the recorded hash changes. No selected version moves, and `go mod tidy` was deliberately NOT run, so nothing is upgraded as a side effect. Verified: `go list -m all` resolves with no checksum error. The durable fix is upstream: treat a published version as immutable. Cut x.y.z+1 instead of moving a tag — with GOSUMDB off, no consumer can detect it.
Languages
Go
100%