chainsaw go
Run go through Chainsaw — refuse malicious/typosquatted modules at `go get`
Run go through Chainsaw — refuse malicious/typosquatted modules at
go get
chainsaw go [args...]
Run go with an install-time supply-chain check in front of it.
Chainsaw evaluates the packages go would install, refuses on a hit, and
otherwise hands off to the real go with your arguments untouched. Anything
that is not an install verb (go build, go run, …) delegates immediately.
Guarded: go get, go install pkg@version, go run pkg@version, go mod download.
go mod download with no named module scans go.sum. A local build
(go install ./..., go run .) is not an install and delegates.
Offline by default. The bundled checks — typosquat detection and a
known-malicious floor — run entirely on your machine and send nothing. For the
full OpenSSF malicious-packages feed, run the opt-in chainsaw guard update,
which is the only networked step. Set CHAINSAW_OFFLINE=1 to refuse network
access outright.
Fails open by default: when a signal cannot be evaluated, Chainsaw prints a
visible notice and lets the install proceed, so a thin feed never breaks your
build. See chainsaw guard coverage to make that fail closed instead.
Exit codes: 0 when the install proceeds (Chainsaw then returns the real tool’s own exit code), 1 when Chainsaw refuses.
--help and every other flag are forwarded to go untouched, so
chainsaw go --help shows go’s help, not this text. Use
chainsaw help go to see this page.
To make the check automatic, add the shell shims: eval "$(chainsaw guard init)".
Examples
chainsaw go get github.com/sirupsen/logrus@v1.9.3
# Go 1.17+ binary install — also guarded
chainsaw go install github.com/x/tool@latest
# scans go.sum
chainsaw go mod download
Flags
This command forwards its arguments to the underlying tool unchanged, so it parses no flags of its own. Anything after the command name goes to the wrapped package manager verbatim.