-
Notifications
You must be signed in to change notification settings - Fork 18
Description
Description
While reproducing the project, we found that the build process fails due to mismatched or unresolved dependencies.
The following error log was produced during the build process:
......
go: found github.com/stretchr/testify/assert in github.com/stretchr/testify v1.10.0
go: finding module for package github.com/ethereum/go-ethereum/crypto/sha3
go: github.com/Project-Arda/bgls/bgls/curves imports
github.com/ethereum/go-ethereum/crypto/sha3: module github.com/ethereum/go-ethereum@latest found (v1.14.12), but does not contain package github.com/ethereum/go-ethereum/crypto/sha3
Result
The build fails with errors related to missing or mismatched dependencies.
The error dependency is github.com/ethereum/go-ethereum.
The build process automatically pulls the latest dependency versions by default. However, the required package github.com/ethereum/go-ethereum/crypto/sha3 is not included in version v1.14.12.
Reason
This issue appears to be caused by the absence of precise version tracking in GOPATH, which leads to inconsistency in dependency resolution.
Proposed Solution
To resolve this issue, we analyzed the project and identified the correct versions of the required dependencies.
The analysis shows that the correct version for the dependency github.com/ethereum/go-ethereum is v1.8.18.
Consider adopting this suggested version to prevent other developers from encountering build failures when constructing the project.
This information can be documented in the README.md file or another relevant location.
Additional Suggestions
To ensure reproducible builds and align with the evolving trends of the Go programming language, it is recommended that the current project be migrated to the Go module mechanism.
Updating to the go module mechanism allows for managing third-party dependency versions through the go.mod file, which provides a centralized and consistent way to specify dependency constraints.
We have generated a go.mod file with the correct versions of the third-party dependencies needed for this project.
The suggested go.mod file is as follows:
module github.com/Project-Arda/bgls
go 1.23
require (
github.com/dchest/blake2b v1.0.0
github.com/dis2/bls12 v0.0.0-20210118063312-e2c12a28055c
github.com/ethereum/go-ethereum v1.8.18
github.com/stretchr/testify v1.10.0
golang.org/x/crypto v0.33.0
)
require (
github.com/davecgh/go-spew v1.1.1 // indirect
github.com/pmezard/go-difflib v1.0.0 // indirect
golang.org/x/sys v0.30.0 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
)
Here the +incompatible suffix in go.mod indicates that the module does not follow Go Modules' semantic versioning (SemVer) rules correctly. But Go can still build and run the project normally despite the +incompatible tag.
Additional Information:
This issue was identified as part of our research project focused on automating the analysis of GOPATH projects to provide accurate dependency versions for seamless migration to Go Modules. We value your feedback and would appreciate any comments or suggestions regarding this approach.