risottobias@toot.risottobias.org (@risottobias@toot.risottobias.org)
P2P & web of trust UX nerd.
Post
-
PSA: go.sum is not a lockfile.
Senza categoria@filippo "then what is it?"
best guess at what could go there?
"go.sum detects tampering in transit or in your local ~/go cache, for specific tagged versions of dependencies; it isn't locked to a particular version, it's the last time you pulled & computed hashes for those tags"