4 ms·
Go is tough to get approved in certain Red Hat markets. Simply because it calls out to github for packages without an audit tool. A lot of finance companies hav
by gabereiser 3y ago
Go is tough to get approved in certain Red Hat markets. Simply because it calls out to github for packages without an audit tool. A lot of finance companies have blocked the use of Golang because of that. Totally fine with Java and their own Nexus. Same with Javascript and their own NPM on Nexus. But they can't see past `go get github.com...`
When they totally could be doing `go get sources.redhat.com...`
- klooney 3y agoGo has a thing for that now- everything goes through a proxy (https://proxy.golang.org https://proxy.golang.org), and if you set GO_PROXY, you can send it through your proxy (Nexus et al).
- a1o 3y agoI don't know for Go case how it would work, but what I saw in case of Maven is it's company wide blocked and you have to get your packages through Sonatype Nexus - and Nexus either has it's own packages or it has a proxy for Maven packages. So I wonder in case of Go, if it would be unfeasible to block GitHub so they would just block the entire use of the language in company developed software.
- gabereiser 3y agoexactly. If you block go packages via firewall IT rules, you block github.com software engineering work. It's the one thing I think that's holding Golang back. Deno as well. I know it looks novel but it's a security nightmare.
- klooney 3y agoBlocking the official Google Go proxy will work pretty well, go get will just fail by default. If someone works around that on a developer machine, it shouldn't matter, because release builds should still come from an automated system, right?
- gabereiser 3y agoyeah, go modules have streamlined golang development so much. Providing a custom domain configuration on your site allows go to grab the code vs a user visiting it in their browser.
- wbl 3y agoThe audit tool is go.sum