Setups

slack-bot: every dependency it pins is still served, and matched the hash it committed

All 532 dependency hashes pinned in its go.sum were still served on 2026-09-13, and every one matched the hash the project committed.

About slack-bot

We fetched each pinned version from https://proxy.golang.org/<module>/@v/<version>.mod (or .zip for the lines that pin a source archive) and recomputed Go's h1 dirhash over the bytes served, comparing each with the hash in the project's own go.sum. It took 13 seconds. All 532 pinned hashes matched.

Its go.sum pins 532 hashes across 434 module versions, of which 98 name a module's source archive and 434 name only its go.mod.

We fetched 63.4 MB from proxy.golang.org to do it.

We cloned the repository at commit e441f8231f48 from its go.sum and read it under sandbox-exec -- (deny default) after importing the base BSD profile, reads allowed only under the system and toolchain paths and the scratch directory, writes confined to that scratch directory, the environment replaced with env -i. The user's home directory is on no allow list. Python 3.14.6 and no Go toolchain -- this is a hash comparison, not a build. We did not build the project and we did not install a Go toolchain: no module archive was extracted to a path and nothing from any of them was executed. This says whether the pinned dependencies are still fetchable and unchanged on that day, and nothing about whether the project compiles.

Source