Pacmon

Dependency notes for Go

go.mod records which modules a build requires and at which version. It does not record why a module was chosen, which of its APIs the code is built around, or what to run before moving it — and go get -u ./... moves everything at once.

Pacmon keeps a note for each module in .pacmon/go/DEPENDENCY-NOTES.md, beside go.mod, and shows it on the module's require line.

What Pacmon reads

Pacmon reads module paths in require directives of go.mod, including // indirect ones, shown with their own scope. A tool directive points at the required module that provides it. replace, exclude, retract, go.work and vendor/ are not read as dependencies.

Pacmon never runs the go command, so it needs no Go toolchain.

Example

module example.com/billing

go 1.24

require (
	github.com/jackc/pgx/v5 v5.7.1
	github.com/spf13/cobra v1.8.1
	golang.org/x/sync v0.10.0 // indirect
)

.pacmon/go/DEPENDENCY-NOTES.md:

## github.com/jackc/pgx/v5

Postgres driver. Use it through internal/db only.

### Agent notes

- purpose: PostgreSQL driver and connection pool for the billing service
- usage: only through internal/db, which wraps the pool and the transaction helpers
- verify: `go test ./internal/db/...` against the Postgres in docker-compose.yml
- verified: v5.7.1

The heading is the module path as require spells it, major-version suffix included. A new major version of a Go module is a new module path, so moving from /v5 to /v6 starts a new section, and the old one stays with - status: removed <YYYY-MM> — <reason>.

For AI coding agents

An agent reads a module's section before it adds, upgrades or removes the module, runs what verify: says, and records the version it checked in verified:. See the rules agents follow.