go-bip39 no longer exists upstream: keep it, or copy it into the repo? #42

Closed
opened 2026-10-03 14:26:38 +02:00 by clawbot · 3 comments
Collaborator

keyfunc reads, checks and creates mnemonics with github.com/tyler-smith/go-bip39 v1.1.0 (internal/mnemonic, internal/derive, internal/childmnemonic). That repository no longer exists on GitHub. The public Go module proxy still serves v1.1.0, and go.sum pins its content by hash, so make build, docker build . and go install work. A build with GOPROXY=direct fails, and the library will get no fixes. sneak/secret depends on the same module.

There is no maintained successor: the best-known fork, github.com/cosmos/go-bip39, was last changed in December 2020.

Question for sneak: what should keyfunc 1.0 do about it?

  • Keep it as it is (recommended): BIP-39 is a fixed standard, the code is small and finished, and the hash in go.sum means a build can only ever get the same bytes. Nothing changes; this issue closes.
  • Copy the library's source (MIT) into internal/bip39 with its license notice, so the build no longer needs the proxy for it. The test vectors stay the same, so no derived key changes.
  • Switch to the cosmos/go-bip39 fork: it is also unmaintained, so it gains nothing.

Definition of done

  • sneak has answered here.
  • Keep: closes with no change. Copy: internal/bip39 holds the copied source and license notice, nothing imports github.com/tyler-smith/go-bip39, every test vector is unchanged, make check passes; branch cut from next, PR to next.

Model: opus-5-5

keyfunc reads, checks and creates mnemonics with `github.com/tyler-smith/go-bip39` v1.1.0 (`internal/mnemonic`, `internal/derive`, `internal/childmnemonic`). That repository no longer exists on GitHub. The public Go module proxy still serves v1.1.0, and `go.sum` pins its content by hash, so `make build`, `docker build .` and `go install` work. A build with `GOPROXY=direct` fails, and the library will get no fixes. `sneak/secret` depends on the same module. There is no maintained successor: the best-known fork, `github.com/cosmos/go-bip39`, was last changed in December 2020. **Question for sneak:** what should keyfunc 1.0 do about it? - Keep it as it is (recommended): BIP-39 is a fixed standard, the code is small and finished, and the hash in `go.sum` means a build can only ever get the same bytes. Nothing changes; this issue closes. - Copy the library's source (MIT) into `internal/bip39` with its license notice, so the build no longer needs the proxy for it. The test vectors stay the same, so no derived key changes. - Switch to the `cosmos/go-bip39` fork: it is also unmaintained, so it gains nothing. ## Definition of done - sneak has answered here. - Keep: closes with no change. Copy: `internal/bip39` holds the copied source and license notice, nothing imports `github.com/tyler-smith/go-bip39`, every test vector is unchanged, `make check` passes; branch cut from `next`, PR to `next`. Model: opus-5-5
sneak was assigned by clawbot 2026-10-03 14:26:38 +02:00
Owner

vendor it into internal/bip39

vendor it into internal/bip39
sneak was unassigned by clawbot 2026-10-06 01:40:31 +02:00
clawbot self-assigned this 2026-10-06 01:40:31 +02:00
Author
Collaborator

Plan

Copy from github.com/tyler-smith/go-bip39 v1.1.0 (the bytes go.sum pins today) into internal/bip39:

  • internal/bip39/LICENSE: the upstream LICENSE, byte for byte.
  • internal/bip39/bip39.go: the upstream bip39.go, keeping only what keyfunc calls (NewMnemonic, NewSeed, IsMnemonicValid) and the functions, variables and errors those use. SetWordList, GetWordList, GetWordIndex, NewEntropy, MnemonicToByteArray, NewSeedWithErrorChecking and compareByteSlices are left out. The package comment says in one line where the code came from.
  • internal/bip39/english.go: the English word list only; keyfunc uses no other language. Upstream's start-up check of the list's checksum becomes a test.
  • Tests: upstream bip39_test.go and example_test.go for the kept code, every test vector unchanged; tests of the left-out functions are dropped.
  • Imports in internal/mnemonic, internal/derive, internal/childmnemonic, internal/childmnemonic/childmnemonic_test.go and internal/cli/cli_test.go move to sneak.berlin/go/keyfunc/internal/bip39. github.com/tyler-smith/go-bip39 leaves go.mod and go.sum.
  • README: internal/bip39 joins the package list under Design; this issue's line leaves TODO.

.golangci.yml stays as it is. The copied code is changed where the linter asks; a //nolint with its reason only where a fix would change behaviour.

Done when all of the above is in, no derived key or mnemonic changes (the existing tests and the upstream vectors pass unchanged), and make check passes. One PR to next that closes this issue.

Model: opus-5-5

Plan Copy from `github.com/tyler-smith/go-bip39` v1.1.0 (the bytes `go.sum` pins today) into `internal/bip39`: - `internal/bip39/LICENSE`: the upstream `LICENSE`, byte for byte. - `internal/bip39/bip39.go`: the upstream `bip39.go`, keeping only what keyfunc calls (`NewMnemonic`, `NewSeed`, `IsMnemonicValid`) and the functions, variables and errors those use. `SetWordList`, `GetWordList`, `GetWordIndex`, `NewEntropy`, `MnemonicToByteArray`, `NewSeedWithErrorChecking` and `compareByteSlices` are left out. The package comment says in one line where the code came from. - `internal/bip39/english.go`: the English word list only; keyfunc uses no other language. Upstream's start-up check of the list's checksum becomes a test. - Tests: upstream `bip39_test.go` and `example_test.go` for the kept code, every test vector unchanged; tests of the left-out functions are dropped. - Imports in `internal/mnemonic`, `internal/derive`, `internal/childmnemonic`, `internal/childmnemonic/childmnemonic_test.go` and `internal/cli/cli_test.go` move to `sneak.berlin/go/keyfunc/internal/bip39`. `github.com/tyler-smith/go-bip39` leaves `go.mod` and `go.sum`. - README: `internal/bip39` joins the package list under Design; this issue's line leaves TODO. `.golangci.yml` stays as it is. The copied code is changed where the linter asks; a `//nolint` with its reason only where a fix would change behaviour. Done when all of the above is in, no derived key or mnemonic changes (the existing tests and the upstream vectors pass unchanged), and `make check` passes. One PR to `next` that closes this issue. Model: opus-5-5
Author
Collaborator

Implemented in #69 as planned above, with one deviation: go-bip39 leaves go.mod, but go mod tidy keeps its two go.sum lines, because a test in sneak/secret's pkg/bip85 imports it.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/keyfunc/pulls/69 as planned above, with one deviation: go-bip39 leaves `go.mod`, but `go mod tidy` keeps its two `go.sum` lines, because a test in `sneak/secret`'s `pkg/bip85` imports it. Model: opus-5-5
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/keyfunc#42