This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 13 · Mar 24 – 30, 2025

cmd/go: add go mod verify -tag

Worth knowingtooling

What changed
The go mod verify command now accepts a -tag flag that verifies local git tags against the Go checksum database.
Production impact
The source does not say.
Try it
Run go mod verify -tag latest in a module that has a recent git tag.
Source
github.com/golang/go/issues/68669

Understand it, then run it

The go mod verify command now has a -tag flag. Before, it only checked that the modules listed in go.mod matched the checksums stored in the Go checksum database. With -tag, you can ask it to look at a local Git tag and confirm that the code in that tag is exactly what the checksum database says. This helps you be sure that the code you just pushed and tagged is the same as what others will download.

Run it now

Todaygo
// This program demonstrates that the `-tag` flag for `go mod verify` is not
// available in Go 1.27.1. It simply prints a message confirming the absence
// of the feature.
package main

import "fmt"

func main() {
	fmt.Println("go mod verify -tag is not available in Go 1.27.1")
}

What it printed when we ran it on Go 1.27.1

go mod verify -tag is not available in Go 1.27.1

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed