How does the Go checksum database protect the supply chain? What does go mod verify actually check?
sum.golang.org is an append-only, Merkle-tree transparency log (Trillian) of go.sum lines for every public module version. The first time anyone in the world downloads mod@v, its hash is recorded permanently. Your go command verifies downloaded hashes against the log using inclusion and consistency proofs. So even if a proxy, or the author (by force-pushing a tag), serves different bytes to you, the mismatch is detected: "SECURITY ERROR: verifying module: checksum mismatch".
Layers of protection:
go.sumin your repo pins hashes for your team.- The checksum DB pins them for the whole ecosystem (trust on first use, globally).
- The proxy caches immutable copies, so deleted repos stay buildable.
go mod verify
# all modules verified
# checks that module-cache zips / extracted dirs still match the hashes
# recorded at download time (detects local cache tampering)
govulncheck ./... # separate tool: reports vulns in code paths you actually call
Gotchas: go mod verify does not re-contact the network or compare against go.sum from scratch. It checks the local cache. A malicious but consistently served version (typosquatting) is not caught by checksums. For that you need review, govulncheck, and pinning. Mentioning govulncheck's call-graph reachability is a strong senior signal.
More on Modules, Packages & Tooling
- Q416How do internal packages work? Give an example of an allowed and a forbidden import.
- Q417Your CI can't fetch a private module from github.com/acme/secret. Walk through GOPROXY, GOPRIVATE, GONOPROXY, GONOSUMDB and GOINSECURE.
- Q419What do the go and toolchain directives mean since Go 1.21, and how does GOTOOLCHAIN behave?
- Q420What does this print? (Hint: consider the go line in go.mod.)
- Q421What does the Go 1.24 tool directive replace, and how do you use it?
- Q422What is the difference between go get and go install pkg@version in module mode?