Go

SlowShield serves Go modules at https://slowshield.example.com/go as a GOPROXY, and passes the checksum database (sum.golang.org) through, so the go command needs no other route out.

Set it up

Go

command (writes go env)

go env -w GOPROXY=https://slowshield.example.com/go

private modules: fetched directly, not through SlowShield

go env -w GOPRIVATE=git.example.com/*

Or the GOPROXY line in your shell profile, with the other package managers (the Setup page has bash on macOS, zsh and fish too):

cat >> ~/.bashrc <<'EOF'
export PIP_INDEX_URL=https://slowshield.example.com/pypi/simple/
export UV_DEFAULT_INDEX=https://slowshield.example.com/pypi/simple/
export npm_config_registry=https://slowshield.example.com/npm/
export GOPROXY=https://slowshield.example.com/go
export PIP_UPLOADED_PRIOR_TO=P3D
export npm_config_min_release_age=3
EOF
source ~/.bashrc

What changes

The second layer

The go command has no release-age setting, so SlowShield is the only layer.

In Docker and CI

FROM golang:1.25 AS build
ARG GOPROXY=https://slowshield.example.com/go
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 go build -o /app .

The official images don't set GOPROXY, so the ARG is what the go command uses. Building images covers the base image too, and how to check that nothing in a build goes around SlowShield.

Limits

For agents: this page as Markdown · llms.txt · the SlowShield skill