Pimp My IDE / Garage dispatch
Back to garage
September 27, 2026 | Go modules / repository control

Your import path is a product address.

A repository host is replaceable. A module path printed through years of source code is much harder to move.

The take. Put public Go modules under a domain you control. Then treat the metadata response, tags, module declaration, and consumer test as one cutover contract.

The host name can leak into the API.

A Go module path is its canonical name. It prefixes every package path in that module. Many projects use the repository URL as that name because popular hosts already answer Go's discovery request.[2]

That convenience creates a migration cost. Iain Cambridge argues that a team which publishes github.com/company/tool has placed its hosting choice inside every consumer's imports. His proposed fix is a stable domain such as go.example.com/tool that points the Go command to the current repository.[1]

Keep the public address stable. Move the repository behind it.

The trick is ordinary HTTP.

When a module path has no version control qualifier, the Go command requests the path with ?go-get=1. The response must put a go-import meta tag near the start of the document. That tag names the root path, version control system, and repository URL.[2]

The garage checked Cambridge's live example on September 27. go.iain.rocks/boneclone?go-get=1 returned a meta tag that maps the stable path to a public GitHub repository. A normal browser request redirected to that repository. GitHub's API confirmed that the repository exists and is public.[3]

You have moved the dependency.

A custom path removes one hosting company from the import statement. It adds a domain, TLS certificate, HTTP route, and metadata document to the module's release machinery. Lose that route and a direct lookup cannot find the repository.

The route also cannot repair a bad migration. The destination still needs the same module declaration, version tags, and accessible commits. Existing proxy and module caches may hide a broken direct path during a shallow test.

Cut over with a consumer.

Test the metadata response as data. Confirm the exact root path and repository URL. Then fetch a released version in a clean module with the proxy path you expect consumers to use. Repeat with direct resolution if direct access is part of the support contract.

The transfer switch below creates that test card. It does not edit DNS, move a repository, or prove that any version resolves. Completion means the four requirements were selected. The named evidence fields still need real output.

Interactive makeover / repository migration

Import path transfer switch

A host logo is not a migration plan. Choose the old and new repository locations, close four test circuits, and copy a cutover card with the missing evidence left visible.

Route the repository

The transfer bus connects only through the first uninterrupted run of selected circuits.

Current host
Destination host
NameRecord the stable module path and domain owner.
MetadataCapture the exact go-import response after cutover.
VersionsCompare the module declaration, tags, and target commits.
ConsumerResolve a released version in a clean test module.

0 of 4 requirements selected. Route open at Name.

Cutover template0 REQUIREMENTS SELECTED

Copy the transfer card

Selections add fields to the card. They do not fill those fields or prove the migration works.

What completion means. Four migration requirements are present in the template. Domain control, response bytes, tags, commits, and consumer output still need evidence.

Sources and limits

Open the source log
  1. Iain Cambridge, "Don't couple your Go code to GitHub", published and read September 27, 2026. It argues for project-controlled Go module paths and supplies a concrete metadata configuration. The company example in the post is the author's account.
  2. Go Modules Reference, "Finding a repository for a module path", read September 27, 2026. It defines the ?go-get=1 lookup and the required go-import fields. It also explains how the Go command reaches version control after discovery.
  3. Live go.iain.rocks/boneclone discovery response and GitHub repository API record, fetched September 27, 2026. The response mapped the stable path to the public repository. The public module proxy returned an empty version list, so this check does not claim a tagged release resolves through that proxy.
  4. Hacker News discussion, item 49868404, fetched from the HN API and opened September 27, 2026. It surfaced the post. Discussion score is not technical evidence.

Source boundary. The lookup mechanism comes from Go's documentation. The portability advice is Cambridge's argument plus the garage's migration checklist. The live checks prove only what those endpoints returned during this pass.