go-bip39 no longer exists upstream: copy it into the repo, as keyfunc does? #122

Closed
opened 2026-10-06 02:28:04 +02:00 by clawbot · 3 comments
Collaborator

secret imports github.com/tyler-smith/go-bip39 v1.1.0 in internal/cli (generate.go, init.go, vault.go), in pkg/agehd, and in the tests of pkg/agehd and pkg/bip85. Its repository no longer exists. The Go module proxy still serves v1.1.0 and go.sum pins it, so builds work, but a build with GOPROXY=direct fails and the library will get no fixes.

For keyfunc you ruled "vendor it into internal/bip39" (sneak/keyfunc#42); the copy is sneak/keyfunc#69. keyfunc imports secret's pkg/bip85, and because that package's test imports go-bip39, go mod tidy keeps go-bip39's two lines in keyfunc's go.sum for as long as secret imports it there.

Question for sneak: should secret do the same?

  • Copy it into internal/bip39 with its upstream licence file beside it, as keyfunc did (recommended). secret then builds without the proxy for it, and once keyfunc requires that secret version, go-bip39 leaves keyfunc's go.sum too.
  • Keep it: nothing changes here, and keyfunc keeps the two go.sum lines.

Definition of done

  • sneak has answered here.
  • Keep: closes with no change. Copy: internal/bip39 holds the copied code with upstream's licence file unchanged beside it, nothing imports github.com/tyler-smith/go-bip39, it is gone from go.mod and go.sum, every test vector is unchanged, make check passes; branch cut from next, PR to next.

Model: opus-5-5

`secret` imports `github.com/tyler-smith/go-bip39` v1.1.0 in `internal/cli` (`generate.go`, `init.go`, `vault.go`), in `pkg/agehd`, and in the tests of `pkg/agehd` and `pkg/bip85`. Its repository no longer exists. The Go module proxy still serves v1.1.0 and `go.sum` pins it, so builds work, but a build with `GOPROXY=direct` fails and the library will get no fixes. For keyfunc you ruled "vendor it into internal/bip39" (https://git.eeqj.de/sneak/keyfunc/issues/42); the copy is https://git.eeqj.de/sneak/keyfunc/pulls/69. keyfunc imports `secret`'s `pkg/bip85`, and because that package's test imports go-bip39, `go mod tidy` keeps go-bip39's two lines in keyfunc's `go.sum` for as long as `secret` imports it there. **Question for sneak:** should `secret` do the same? - Copy it into `internal/bip39` with its upstream licence file beside it, as keyfunc did (recommended). `secret` then builds without the proxy for it, and once keyfunc requires that `secret` version, go-bip39 leaves keyfunc's `go.sum` too. - Keep it: nothing changes here, and keyfunc keeps the two `go.sum` lines. ## Definition of done - sneak has answered here. - Keep: closes with no change. Copy: `internal/bip39` holds the copied code with upstream's licence file unchanged beside it, nothing imports `github.com/tyler-smith/go-bip39`, it is gone from `go.mod` and `go.sum`, every test vector is unchanged, `make check` passes; branch cut from `next`, PR to `next`. Model: opus-5-5
sneak was assigned by clawbot 2026-10-06 02:28:04 +02:00
Owner

vendor it in, yes, obviously

vendor it in, yes, obviously
Author
Collaborator

Ruling (sneak, #122 (comment)): "vendor it in, yes, obviously". Done the way keyfunc did it (sneak/keyfunc#69).

Plan, one PR to next:

  • Copy the part of github.com/tyler-smith/go-bip39 v1.1.0 that secret uses (and what it calls) into internal/bip39, with upstream's LICENSE beside it byte for byte. English word list only, unless something here uses another.
  • Move every import (internal/cli, pkg/agehd, and the tests of pkg/agehd and pkg/bip85) to internal/bip39; the module leaves go.mod and go.sum.
  • Carry over upstream's tests of the copied code with every test vector unchanged; existing secret test vectors unchanged.
  • Beyond trimming, change only what the linter asks for; each suppressed rule a one-line disclosure. No licence analysis anywhere.

Model: opus-5-5

Ruling (sneak, https://git.eeqj.de/sneak/secret/issues/122#issuecomment-131678): "vendor it in, yes, obviously". Done the way keyfunc did it (https://git.eeqj.de/sneak/keyfunc/pulls/69). Plan, one PR to `next`: - Copy the part of `github.com/tyler-smith/go-bip39` v1.1.0 that `secret` uses (and what it calls) into `internal/bip39`, with upstream's `LICENSE` beside it byte for byte. English word list only, unless something here uses another. - Move every import (`internal/cli`, `pkg/agehd`, and the tests of `pkg/agehd` and `pkg/bip85`) to `internal/bip39`; the module leaves `go.mod` and `go.sum`. - Carry over upstream's tests of the copied code with every test vector unchanged; existing `secret` test vectors unchanged. - Beyond trimming, change only what the linter asks for; each suppressed rule a one-line disclosure. No licence analysis anywhere. Model: opus-5-5
sneak was unassigned by clawbot 2026-10-07 11:25:47 +02:00
clawbot self-assigned this 2026-10-07 11:25:47 +02:00
Author
Collaborator

Built in #130: the part of go-bip39 v1.1.0 that secret uses is now internal/bip39, with upstream's LICENSE beside it and upstream's tests of that code. Every import moved there, and go-bip39 is gone from go.mod and go.sum. No derived key or mnemonic changes.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/secret/pulls/130: the part of go-bip39 v1.1.0 that `secret` uses is now `internal/bip39`, with upstream's `LICENSE` beside it and upstream's tests of that code. Every import moved there, and go-bip39 is gone from `go.mod` and `go.sum`. No derived key or mnemonic changes. Model: opus-5-5
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#122