Skip to content

Repository files navigation

gohawk logo: a hawk sheltering the Go gopher

gohawk

Go 1.26 Go 1.27 Coverage

gohawk is an industrial-grade static analyzer that finds resource management and concurrency issues in Go code. It has been used to find and fix bugs in Docker, Kubernetes, and Caddy.

gohawk is heavily inspired by Meta's Infer and its compositional summary model. It writes a summary of what each function does with its arguments and results, such as closing a file or waiting for a goroutine, and callers read that summary instead of analyzing the function again. This lets gohawk follow a resource through helpers and across packages.

Read the documentation

Quick Start

# Install.
go install github.com/kojah/gohawk@latest

# Run the conservative default set.
gohawk ./...

# See every analyzer with its tier and group.
gohawk list

# Inspect an analyzer or one of its checks.
gohawk doc lockorder
gohawk doc lockorder/missing-release

# Use it with go vet.
go vet -vettool="$(command -v gohawk)" ./...

# Run a selected analyzer, or exclude one from the defaults.
gohawk -enable=concurrentcapture ./...
gohawk -disable=concurrentcapture ./...

# Run complete analyzer groups with their default checks.
gohawk -enable-groups=concurrency,resources ./...

# Run one experimental check by its ID.
gohawk -enable-checks=producerlifecycle/unclosed-range ./...

# Remove groups from the ordinary run or from -enable-all.
gohawk -disable-groups=concurrency ./...

# Run every analyzer and check.
gohawk -enable-all ./...

How gohawk compares to other analyzers

gohawk aims to complement other Go analyzers, not replace them. Each tool looks for a different kind of problem, so running several together catches more than any one alone.

Deep, flow-based analysis of Go already covers several domains well. NilAway covers nil safety, gosec covers security and taint analysis, and Staticcheck covers a broad range of general bugs. Resource management and concurrency are among the last big gaps, and that is the domain gohawk focuses on.

golangci-lint integration

gohawk can run as a module plugin inside a custom golangci-lint binary. See the golangci-lint integration guide for build and configuration instructions.

Contributing

Contributions are welcome. See How to contribute for the development workflow, analyzer requirements, and verification steps.

AI policy

gohawk was developed with assistance from LLMs, and AI-assisted contributions are permitted. Contributors must disclose AI usage, and every contribution must meet the project's strict standards for quality, testing, analyzer precision, and human readability. See the full AI policy.

Sponsorship

If gohawk is useful to you or your organization, consider sponsoring its continued development. Sponsorship helps fund maintenance, new analyzers, and improvements to the documentation and developer experience. To discuss sponsorship, get in touch with @kojah.

License

Licensed under the MIT License.

About

Watch for bugs like a hawk! gohawk is a set of static analyzers for Go, focused on concurrency and resource-lifetime bugs.

Topics

Resources

Contributing

Stars

7 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages