跳到主要内容
知仓学习社ZHICANG

go-cli-distribution

Prepare reproducible Go CLI artifacts across operating systems and architectures with toolchain-derived target matrices, capability profiles, portab…

不碰外部(只输出文字)无严重或高危命中hashgraph-online/awesome-codex-plugins

它会碰到什么

扫了多少9 个文本文件,41 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Go CLI Distribution

Treat compilation as the start of release verification, not the finish. Declare

the matrix, record every build input, and execute the final artifacts.

Core Workflow

  1. Derive supported GOOS/GOARCH targets from the pinned toolchain and dependencies.
  2. Verify platform files and modern //go:build capability constraints.
  3. Pin toolchain, modules, tags, CGO mode, linker flags, and source revision.
  4. Build deterministic target-specific artifacts with deliberate version metadata.
  5. Execute each artifact and test help, version, commands, streams, status, and signals.
  6. Package immutable archives, then generate and verify integrity metadata.
  7. Verify container and versioned go install paths when those are supported.

Read Next

| Task | Load |

|---|---|

| Prepare a complete multi-platform release | guidelines.md, workflows/prepare-cross-platform-release.md |

| Apply build, verification, container, and install rules | references/distribution/rules.md |

| Implement constraints or build commands | references/distribution/examples.md |

| Use cross-build, CGO, metadata, or container patterns | references/distribution/patterns.md |

| Review release readiness | references/distribution/checklist.md |

| Understand portability and artifact tradeoffs | references/distribution/knowledge.md |

Guardrails

  • Use //go:build; do not introduce legacy-only // +build constraints.
  • Do not assume CGO_ENABLED=0 proves a self-contained artifact.
  • Cross-compilation alone does not establish runtime support.
  • Generate checksums only after final packaging and verify them after upload.
  • Use platform config and cache directory APIs; do not assume Unix home layouts.
  • Treat build tags as capability selection, never authentication or authorization.
  • Define and snapshot-test the artifact contract before release. The protected

tagged release job builds final bytes once; downstream channels must not rebuild them.

  • Recommend go install module/cmd/tool@version, not go get, for executable installation.

Source Notes

Guidance is transformed and paraphrased from Ricardo Gerardi,

Powerful Command-Line Applications in Go (Pragmatic Bookshelf, 2021),

especially Chapter 11. Examples are original adaptations.

Book: https://pragprog.com/titles/rggo/powerful-command-line-applications-in-go/

The source's Go 1.15-era build and install details are historical. Verify

current behavior against https://go.dev/doc/go-get-install-deprecation and the

current Go build documentation.

Portable directory, profile-matrix, and artifact-handoff guidance also

incorporates transformed material from Marian Montagnino, *Building Modern CLI

Applications in Go* (Packt, 2023), especially Chapters 7 and 12-14.

Embedded-schema and SQL-driver packaging guidance also incorporates transformed

material from Inanc Gumus, *Go by Example: Programmer's Guide to Idiomatic and

Testable Programs* (Manning, 2025), Chapter 10.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。