We support tracking Golang dependencies using the Go Modules dependency management system and its associated file go.mod.

We also support the legacy dependency management system (dep (opens new window)) and its lock file Gopkg.lock.

By keeping one of these file committed to your repository, we will automatically scan it for dependencies when you have done any of our integrations to your CI/CD pipeline.

Go tip

Run go mod tidy before pushing the go.mod files, which cleans up unused modules. This makes the results from our service even better.

We also support Golang projects using Bazel, see here for more information.