Go + Standard Toolchain
Category: Tech Stack · Areas: all
Description
Category
tech-stack
Areas
all
Slot
language-runtime
Components
- Language: Go (version pinned in
go.mod) - Build system:
go build/go test(standard toolchain) - Formatter:
gofmt(non-negotiable) - Linter:
golangci-lintwith.golangci.ymlconfig - Security scanner:
gosec+govulncheck - CLI framework: Cobra (for CLI projects)
- Testing:
go testwith build tags for test levels
Constraints
- All code must pass
gofmt -l .(zero diff) - All code must pass
go vet ./... - All code must pass
golangci-lint runwith project.golangci.yml - Errors must be wrapped with context:
fmt.Errorf("context: %w", err)— no nakedreturn err - No
panicoutside ofmain()or initialization — return errors - Pass
context.Contextas first parameter to functions that do I/O or may be cancelled - Define interfaces in the consuming package, not the providing package
- Version metadata embedded at build time via
-ldflags "-X main.Version=..." govulncheck ./...must pass (no known vulnerabilities)
Lint Policy (golangci-lint baseline)
Enabled linters:
govet(withenable-all, disablefieldalignment)staticcheckineffassignmisspellunconvertgosec(severity: high, confidence: high)gocritic(diagnostic, performance, style tags)
Disabled linters (too opinionated):
wsl,wrapcheck,varnamelen,nlreturn,exhaustructparalleltest,testpackage,mnd,funlen
Generated files (.pb.go, .gen.go, mock_*.go) excluded from linting.
When to use
All Go projects — CLIs, services, libraries. The standard toolchain and
go fmt are universal; golangci-lint + gosec are the quality layer on top.
Artifact Impact
Selecting this concern requires these artifacts to change (a selected concern absent from them is drift):
- ADR: Go + standard toolchain (gofmt, golangci-lint, gosec, govulncheck) as the language-runtime
- TD: error-wrapping, context-passing, interface-in-consumer conventions; lint baseline
Practices by activity
Agents working in any of these activities inherit the practices below through runtime work context, such as a DDx bead context digest.
Requirements (Frame activity)
- Specify minimum Go version in
go.mod - Identify test levels needed: unit, integration (VCR/stubbed), functional (binary), E2E (live)
- If the project hits external HTTP APIs, plan for VCR recording in integration tests
Design
- Package layout:
cmd/for CLI entry points,internal/for application logic - Define interfaces in the consumer package; return concrete types where practical
- Use minimal, consumer-driven interfaces
- Guard shared state explicitly; prefer immutable data; use
errgroupfor concurrent work - Embed version metadata:
Version,BuildTime,GitCommitvia-ldflags
Implementation
- Formatting:
go fmt ./...(run before every commit — enforced bygofmt -l .check) - Error wrapping:
fmt.Errorf("context: %w", err)— always add context - Sentinel errors: define with
errors.Newfor expected conditions; compare witherrors.Is - Concurrency: pass
context.Contextfirst; useerrgroup.WithContextfor fan-out; avoid goroutine leaks - Logging: structured with
log/slog(stdlib) or project-chosen structured logger; nofmt.Print*in library code - No
panicoutside startup; inmain(), convert panics to fatal log + exit
Testing
- Run with:
go test ./... - Race detection:
go test -race ./...for concurrent code - Build tags for test levels:
- (no tag): fast unit tests, no external deps
-tags=integration: VCR playback, no live APIs-tags=functional: built binary CLI tests-tags=e2e: live API tests (requires credentials)
- Table-driven tests for pure functions
- HTTP stubs: VCR cassette recording (
VCR_MODE=recordto capture,VCR_MODE=playbackfor CI) - Use
testify/assertortestify/requirefor assertions; not baret.Fatalcomparisons - Coverage:
go test -coverprofile=coverage.out ./...+go tool cover -func; 80% threshold
Quality Gates (pre-commit / CI)
go fmt ./...(orgofmt -l .check)go vet ./...golangci-lint rungosec ./...(high severity/confidence)govulncheck ./...go test -race ./...(unit + integration tags)
Dependency Management
go mod tidyafter any dependency changego mod downloadfor reproducible builds- No vendoring unless required by deployment constraints
govulncheck ./...before releases
Innsigle seal: model-primary by HELIX
The signature covers the markdown source of this page, not these HTML bytes. This page quotes that seal; verify it against the source file.
- Composition
- model-primary
- Issuer
- HELIX
helix - Signing key
ed25519:b0865d76d834a52c48506414d16f4e5a(build key)- Signed source
concerns/go-std.md- Signed
- 2026-09-23T14:11:58Z
- Content digest
sha256:5c71de4b…03afcadc
This build key is endorsed by the human key for build signing; the signature is not a detector and not a truth guarantee.
Raw attestation JSON
{
"payload": {
"innsigle": "1",
"type": "https://innsigle.dev/claim/colophon/v1",
"issued_at": "2026-09-23T14:11:58Z",
"issuer": {
"id": "helix",
"name": "HELIX",
"key_id": "ed25519:b0865d76d834a52c48506414d16f4e5a",
"key_url": "https://documentdrivendx.github.io/helix/.well-known/innsigle/keys.json"
},
"subjects": [
{
"uri": "https://documentdrivendx.github.io/helix/concerns/go-std/",
"digest": {
"alg": "sha256",
"value": "5c71de4bfeec7576e09fae945ea7754d5963fd6b3cdd98004e6f742403afcadc"
}
}
],
"colophon": {
"schema_version": "1",
"composition": "model-primary",
"ingredients": [
{
"kind": "model",
"name": "Claude",
"role": "draft"
},
{
"kind": "tool",
"name": "sloptimizer",
"role": "rewrite"
},
{
"kind": "human",
"name": "operator",
"role": "structure-edit"
}
],
"notes": null
}
},
"payload_encoding": "json",
"signatures": [
{
"key_id": "ed25519:b0865d76d834a52c48506414d16f4e5a",
"alg": "ed25519",
"sig": "uMao3wllY1yNou5j7lDYxyizl7hYDRR1NW1jFO9MuDKTvBxaM3Mdg-kX6tnD7akMJHhlZu2as1NOFe47i6CvBA",
"signed_at": "2026-09-23T14:11:58Z"
}
]
}