# Build Confidently with Secure Go Module Management

Securely manage your [Go](https://go.dev/) applications and dependencies across your software supply chain with Sonatype’s integrated tools.

.png?width=1968&height=2893&name=Header-LR-Gray-(RIGHT).png)

.png?width=1467&height=2893&name=Header-LR-Gray-(LEFT).png)

## Why Go Matters and How Sonatype Fits

Go is a top choice for cloud-native services, CLI tools, and modern back-end systems. Since Go 1.11, Go Modules [manage dependencies](/content/solutions/dependency-management/index.html), allowing reproducible builds, explicit versioning, and caching. But the flexibility of Go Modules also introduces challenges like supply chain security, license compliance, transitive dependency risk, and private module governance. Sonatype offers a unified solution by integrating Go support into [our products](/content/products/nexus-one-platform/index.html), allowing you to embed policy, scanning, and control directly into your Go workflows.

## Supported Features

### Go Module Repository Support

Support proxy, hosted, and group repositories for easier Go module management.

### CI/CD Integration

Enforce open source governance from developer workstations to automated pipelines.

### Static Analysis

Scan go.mod and dependencies for security, license, and identity issues.

### Manifest Scanning

Evaluate go.sum / go.list to find exact dependencies and limit false positives.

### Firewall Policies

Automatically block risky modules from your artifact pool.

### SBOM Generation

Automatically generate SBOMs for Go applications for full visibility into component risks.

## What Sonatype Solutions Work with Go Modules

The [Sonatype platform](/content/products/nexus-one-platform/index.html) provides visibility, control, and security to Go projects at every stage of the SDLC. By integrating with your Go module workflows, Sonatype secures dependencies, automates compliance, and helps you deliver reliable software faster.

- #### Secure Every Dependency Before Production

Sonatype analyzes your Go Modules for vulnerabilities, license risks, and integrity issues before they enter your repositories or builds.

- #### Simplify and Accelerate Your Development Workflow

Proxying and caching Go modules gives teams fast, repeatable builds and less reliance on external networks.

- #### Gain Unified Governance Across All Languages

Sonatype provides consistent security and compliance across all ecosystems. Your teams get one governance model, one set of SBOMs, and one continuous view of open source risk, regardless of the developer language used.

## Resources

+

### Go Repositories + Sonatype Nexus Repository Support

[See Documentation](https://help.sonatype.com/en/go-repositories.html)

+.png?width=149&height=170&name=NexusLifecycle_Icon%20(1).png)

### Go Application Analysis in Sonatype Lifecycle

[See Documentation](https://help.sonatype.com/en/go-application-analysis.html)

### Documentation: Automated Pull Requests in Go

[See Documentation](https://help.sonatype.com/en/automated-pull-requests-in-go.html#go)

## Frequently Asked Questions

### Should I scan go.sum or go.list for scans?

Sonatype recommends using go.list to generate a pruned list of actual dependencies, rather than scanning the full go.sum, which may include unused or indirect modules.

### Can I use Sonatype to host internal/private Go modules (not publicly published)?

Yes. Sonatype tools can host private Go modules in a hosted repository and integrate with your access controls, enabling you to distribute private modules internally.

### Does Sonatype block modules with known vulnerabilities?

Yes. Through [Repository Firewall](/content/products/sonatype-repository-firewall/index.html) and [Lifecycle](/content/products/open-source-security-dependency-management/index.html) policy enforcement, you can automatically block or quarantine modules that do not meet your security and compliance requirements.
