...
▽

Text file src/README.vendor

Documentation: Index

     1Vendoring in std and cmd
     2========================
     3
     4The Go command maintains copies of external packages needed by the
     5standard library in the src/vendor and src/cmd/vendor directories.
     6
     7There are two modules, std and cmd, defined in src/go.mod and
     8src/cmd/go.mod. When a package outside std or cmd is imported
     9by a package inside std or cmd, the import path is interpreted
    10as if it had a "vendor/" prefix. For example, within "crypto/tls",
    11an import of "golang.org/x/crypto/cryptobyte" resolves to
    12"vendor/golang.org/x/crypto/cryptobyte". When a package with the
    13same path is imported from a package outside std or cmd, it will
    14be resolved normally. Consequently, a binary may be built with two
    15copies of a package at different versions if the package is
    16imported normally and vendored by the standard library.
    17
    18Vendored packages are internally renamed with a "vendor/" prefix
    19to preserve the invariant that all packages have distinct paths.
    20This is necessary to avoid compiler and linker conflicts. Adding
    21a "vendor/" prefix also maintains the invariant that standard
    22library packages begin with a dotless path element.
    23
    24The module requirements of std and cmd do not influence version
    25selection in other modules. They are only considered when running
    26module commands like 'go get' and 'go mod vendor' from a directory
    27in GOROOT/src.
    28
    29Maintaining vendor directories
    30==============================
    31
    32Before updating vendor directories, ensure that module mode is enabled.
    33Make sure that GO111MODULE is not set in the environment, or that it is
    34set to 'on' or 'auto', and if you use a go.work file, set GOWORK=off.
    35
    36Also, ensure that 'go env GOROOT' shows the root of this Go source
    37tree. Otherwise, the results are undefined. It's recommended to build
    38Go from source and use that 'go' binary to update its source tree.
    39
    40Requirements may be added, updated, and removed with 'go get'.
    41The vendor directory may be updated with 'go mod vendor'.
    42Tree inconsistencies are reported by 'go test cmd/internal/moddeps'.
    43A typical sequence might be:
    44
    45    cd src  # or src/cmd
    46    go get golang.org/x/net@master
    47    go mod tidy
    48    go mod vendor
    49    go test cmd/internal/moddeps
    50
    51Use caution when passing '-u' to 'go get'. The '-u' flag updates
    52modules providing all transitively imported packages, not only
    53the module providing the target package.
    54
    55Note that 'go mod vendor' only copies packages that are transitively
    56imported by packages in the current module. If a new package is needed,
    57it should be imported before running 'go mod vendor'.
    58
    59Go release cycle considerations
    60===============================
    61
    62Applying changes to packages that are vendored follows the considerations
    63written down at go.dev/s/release.
    64
    65When the Go tree is open for development, a specific change may be pulled in
    66at any time that it is needed. During the release freeze, the bar for changes
    67in vendored packages is the same as it is for changes in non-vendored packages.
    68After a major release is out, minor Go releases follow a more involved process
    69documented at go.dev/wiki/MinorReleases#cherry-pick-cls-for-vendored-golangorgx-packages.
    70
    71In addition to individual updates that happen on demand, all dependencies in
    72the std and cmd modules are updated to their latest available versions at least
    73twice during every major release cycle. This is done to avoid the possibility of
    74some dependencies being left on very old versions and in turn make their eventual
    75update more disruptive. This recurring process is tracked in go.dev/issue/36905.
    76The golang.org/x/build/cmd/updatestd command exists to assist with that process.

View as plain text