version

package
v0.8.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

FIPS reporting, sourced from the runtime rather than from a build flag.

WHY THIS EXISTS: --version used to print the FIPS ldflag verbatim. That is a claim about how someone intended to build the binary, not a fact about the binary. `go build -ldflags "-X ...version.FIPS=true"` without GOFIPS140 set produces a binary that reports fips=true and contains no FIPS module at all. For a compliance product that is the worst possible failure: an auditor reads the claim off the box and it is false.

Everything here is read from the running binary. FIPS is the ldflag, kept as a cross-check: when the two disagree the binary says so instead of choosing the flattering answer.

Package version exposes build-time metadata for the openwatch binary.

All values are overridden via -ldflags at build time by the Makefile. The default values are used when building with bare `go build` (e.g., during local development or in IDE-driven builds).

Index

Constants

This section is empty.

Variables

View Source
var (
	// Version is the semver string (e.g., "0.1.0-dev").
	Version = "dev"

	// Commit is the abbreviated git commit hash.
	Commit = "unknown"

	// BuildTime is an ISO-8601 timestamp.
	BuildTime = "unknown"

	// FIPS is "true" when built with the microsoft/go FIPS toolchain (Day 12).
	FIPS = "false"
)

Build-time injected values. Default to placeholders that make it obvious when a binary was built without the Makefile.

Functions

func FIPSClaimMismatch added in v0.8.0

func FIPSClaimMismatch() bool

FIPSClaimMismatch reports whether the build-time FIPS ldflag disagrees with the runtime. True means the binary was labeled FIPS but has no active module, or the reverse. Callers surface this loudly: a mislabelled binary is worse than an unlabelled one, because it is trusted.

func FIPSEnabled added in v0.8.0

func FIPSEnabled() bool

FIPSEnabled reports whether the FIPS 140-3 module is active in this binary, as the crypto runtime sees it. This is the authoritative answer.

func FIPSMode added in v0.8.0

func FIPSMode() string

FIPSMode returns the active enforcement mode: "off", "on", or "only".

The distinction matters operationally, not just cosmetically. In "only" mode the Go crypto runtime refuses every algorithm outside the validated set, and golang.org/x/crypto/ssh cannot complete a handshake because its AES-GCM path uses arbitrary IVs. An OpenWatch reaching for maximum assurance by setting fips140=only loses the ability to scan any host, so the mode has to be visible rather than inferred.

A GODEBUG environment setting overrides the value baked in at build time, which is why both are consulted in that order.

func FIPSModule added in v0.8.0

func FIPSModule() string

FIPSModule returns the FIPS module build tag linked into the binary, for example "fips140v1.0", or "" when no module is linked. Read from build info, so it reflects what GOFIPS140 actually selected at link time.

func Go

func Go() string

Go returns the Go toolchain version the binary was built with, e.g. "go1.26.5". Sourced from the runtime, never hardcoded.

func Kensa

func Kensa() string

Kensa returns the version of the embedded Kensa engine module, read from the binary's build info (the version selected in go.mod at link time). Returns "unknown" when build info is unavailable (e.g. `go run` outside a module).

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL