secret imports github.com/tyler-smith/go-bip39 v1.1.0 in internal/cli (generate.go, init.go, vault.go), in pkg/agehd, and in the tests of pkg/agehd and pkg/bip85. Its repository no longer exists. The Go module proxy still serves v1.1.0 and go.sum pins it, so builds work, but a build with GOPROXY=direct fails and the library will get no fixes.
For keyfunc you ruled "vendor it into internal/bip39" (sneak/keyfunc#42); the copy is sneak/keyfunc#69. keyfunc imports secret's pkg/bip85, and because that package's test imports go-bip39, go mod tidy keeps go-bip39's two lines in keyfunc's go.sum for as long as secret imports it there.
Question for sneak: should secret do the same?
Copy it into internal/bip39 with its upstream licence file beside it, as keyfunc did (recommended). secret then builds without the proxy for it, and once keyfunc requires that secret version, go-bip39 leaves keyfunc's go.sum too.
Keep it: nothing changes here, and keyfunc keeps the two go.sum lines.
Definition of done
sneak has answered here.
Keep: closes with no change. Copy: internal/bip39 holds the copied code with upstream's licence file unchanged beside it, nothing imports github.com/tyler-smith/go-bip39, it is gone from go.mod and go.sum, every test vector is unchanged, make check passes; branch cut from next, PR to next.
Model: opus-5-5
`secret` imports `github.com/tyler-smith/go-bip39` v1.1.0 in `internal/cli` (`generate.go`, `init.go`, `vault.go`), in `pkg/agehd`, and in the tests of `pkg/agehd` and `pkg/bip85`. Its repository no longer exists. The Go module proxy still serves v1.1.0 and `go.sum` pins it, so builds work, but a build with `GOPROXY=direct` fails and the library will get no fixes.
For keyfunc you ruled "vendor it into internal/bip39" (https://git.eeqj.de/sneak/keyfunc/issues/42); the copy is https://git.eeqj.de/sneak/keyfunc/pulls/69. keyfunc imports `secret`'s `pkg/bip85`, and because that package's test imports go-bip39, `go mod tidy` keeps go-bip39's two lines in keyfunc's `go.sum` for as long as `secret` imports it there.
**Question for sneak:** should `secret` do the same?
- Copy it into `internal/bip39` with its upstream licence file beside it, as keyfunc did (recommended). `secret` then builds without the proxy for it, and once keyfunc requires that `secret` version, go-bip39 leaves keyfunc's `go.sum` too.
- Keep it: nothing changes here, and keyfunc keeps the two `go.sum` lines.
## Definition of done
- sneak has answered here.
- Keep: closes with no change. Copy: `internal/bip39` holds the copied code with upstream's licence file unchanged beside it, nothing imports `github.com/tyler-smith/go-bip39`, it is gone from `go.mod` and `go.sum`, every test vector is unchanged, `make check` passes; branch cut from `next`, PR to `next`.
Model: opus-5-5
sneak
was assigned by clawbot2026-10-06 02:28:04 +02:00
Copy the part of github.com/tyler-smith/go-bip39 v1.1.0 that secret uses (and what it calls) into internal/bip39, with upstream's LICENSE beside it byte for byte. English word list only, unless something here uses another.
Move every import (internal/cli, pkg/agehd, and the tests of pkg/agehd and pkg/bip85) to internal/bip39; the module leaves go.mod and go.sum.
Carry over upstream's tests of the copied code with every test vector unchanged; existing secret test vectors unchanged.
Beyond trimming, change only what the linter asks for; each suppressed rule a one-line disclosure. No licence analysis anywhere.
Model: opus-5-5
Ruling (sneak, https://git.eeqj.de/sneak/secret/issues/122#issuecomment-131678): "vendor it in, yes, obviously". Done the way keyfunc did it (https://git.eeqj.de/sneak/keyfunc/pulls/69).
Plan, one PR to `next`:
- Copy the part of `github.com/tyler-smith/go-bip39` v1.1.0 that `secret` uses (and what it calls) into `internal/bip39`, with upstream's `LICENSE` beside it byte for byte. English word list only, unless something here uses another.
- Move every import (`internal/cli`, `pkg/agehd`, and the tests of `pkg/agehd` and `pkg/bip85`) to `internal/bip39`; the module leaves `go.mod` and `go.sum`.
- Carry over upstream's tests of the copied code with every test vector unchanged; existing `secret` test vectors unchanged.
- Beyond trimming, change only what the linter asks for; each suppressed rule a one-line disclosure. No licence analysis anywhere.
Model: opus-5-5
sneak
was unassigned by clawbot2026-10-07 11:25:47 +02:00
clawbot
self-assigned this 2026-10-07 11:25:47 +02:00
Built in #130: the part of go-bip39 v1.1.0 that secret uses is now internal/bip39, with upstream's LICENSE beside it and upstream's tests of that code. Every import moved there, and go-bip39 is gone from go.mod and go.sum. No derived key or mnemonic changes.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/secret/pulls/130: the part of go-bip39 v1.1.0 that `secret` uses is now `internal/bip39`, with upstream's `LICENSE` beside it and upstream's tests of that code. Every import moved there, and go-bip39 is gone from `go.mod` and `go.sum`. No derived key or mnemonic changes.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
secretimportsgithub.com/tyler-smith/go-bip39v1.1.0 ininternal/cli(generate.go,init.go,vault.go), inpkg/agehd, and in the tests ofpkg/agehdandpkg/bip85. Its repository no longer exists. The Go module proxy still serves v1.1.0 andgo.sumpins it, so builds work, but a build withGOPROXY=directfails and the library will get no fixes.For keyfunc you ruled "vendor it into internal/bip39" (sneak/keyfunc#42); the copy is sneak/keyfunc#69. keyfunc imports
secret'spkg/bip85, and because that package's test imports go-bip39,go mod tidykeeps go-bip39's two lines in keyfunc'sgo.sumfor as long assecretimports it there.Question for sneak: should
secretdo the same?internal/bip39with its upstream licence file beside it, as keyfunc did (recommended).secretthen builds without the proxy for it, and once keyfunc requires thatsecretversion, go-bip39 leaves keyfunc'sgo.sumtoo.go.sumlines.Definition of done
internal/bip39holds the copied code with upstream's licence file unchanged beside it, nothing importsgithub.com/tyler-smith/go-bip39, it is gone fromgo.modandgo.sum, every test vector is unchanged,make checkpasses; branch cut fromnext, PR tonext.Model: opus-5-5
vendor it in, yes, obviously
Ruling (sneak, #122 (comment)): "vendor it in, yes, obviously". Done the way keyfunc did it (sneak/keyfunc#69).
Plan, one PR to
next:github.com/tyler-smith/go-bip39v1.1.0 thatsecretuses (and what it calls) intointernal/bip39, with upstream'sLICENSEbeside it byte for byte. English word list only, unless something here uses another.internal/cli,pkg/agehd, and the tests ofpkg/agehdandpkg/bip85) tointernal/bip39; the module leavesgo.modandgo.sum.secrettest vectors unchanged.Model: opus-5-5
Built in #130: the part of go-bip39 v1.1.0 that
secretuses is nowinternal/bip39, with upstream'sLICENSEbeside it and upstream's tests of that code. Every import moved there, and go-bip39 is gone fromgo.modandgo.sum. No derived key or mnemonic changes.Model: opus-5-5