Summary
Remove the vendor/ directory from Git tracking and rely solely on go.mod and go.sum for dependency management.
Background / Motivation
Currently, the vendor/ directory is tracked in Git, containing 6,000+ files from external dependencies. While vendoring ensures reproducible builds, it introduces significant overhead for this project:
- Bloated Pull Requests – Every dependency update results in massive diffs, making code review difficult and increasing the risk of missing actual code changes among vendor noise.
- Repository Size – The
vendor/ directory significantly inflates the repository clone size and history.
- Modern Go Best Practice – Since Go 1.13+ and the maturity of Go Modules, the community standard has shifted.
go.mod + go.sum already guarantees reproducible builds via cryptographic checksums.
Current State
go.mod and go.sum are already present and up-to-date.
- The project uses Go 1.21, which has excellent module proxy support.
- No local patches or
replace directives requiring a vendored source tree.
Proposed Changes
-
Remove vendor/ from Git tracking:
git rm -r --cached vendor/
-
Add vendor/ to .gitignore:
# Vendor directory should not be tracked in Git
# Dependencies are managed by go.mod/go.sum
vendor/
-
Update CI workflows (if needed) to ensure go mod download or go mod vendor is available during build. Builds can use either:
go build ./... (direct module mode, recommended)
go mod vendor && go build -mod=vendor ./... (if the project prefers keeping the vendor workflow locally)
Benefits
- Cleaner diffs and easier code reviews
- Smaller repository footprint
- Reduced merge conflict frequency
- Aligns with modern Go community conventions
Acceptance Criteria
Summary
Remove the
vendor/directory from Git tracking and rely solely ongo.modandgo.sumfor dependency management.Background / Motivation
Currently, the
vendor/directory is tracked in Git, containing 6,000+ files from external dependencies. While vendoring ensures reproducible builds, it introduces significant overhead for this project:vendor/directory significantly inflates the repository clone size and history.go.mod+go.sumalready guarantees reproducible builds via cryptographic checksums.Current State
go.modandgo.sumare already present and up-to-date.replacedirectives requiring a vendored source tree.Proposed Changes
Remove
vendor/from Git tracking:Add
vendor/to.gitignore:Update CI workflows (if needed) to ensure
go mod downloadorgo mod vendoris available during build. Builds can use either:go build ./...(direct module mode, recommended)go mod vendor && go build -mod=vendor ./...(if the project prefers keeping the vendor workflow locally)Benefits
Acceptance Criteria
vendor/directory removed from Git index.gitignoreupdated to excludevendor/