gohawk is an industrial-grade static analyzer that finds resource management and concurrency issues in Go code. It has been used to find and fix bugs in Docker, Kubernetes, and Caddy.
gohawk is heavily inspired by Meta's Infer and its compositional summary model. It writes a summary of what each function does with its arguments and results, such as closing a file or waiting for a goroutine, and callers read that summary instead of analyzing the function again. This lets gohawk follow a resource through helpers and across packages.
# Install.
go install github.com/kojah/gohawk@latest
# Run the conservative default set.
gohawk ./...
# See every analyzer with its tier and group.
gohawk list
# Inspect an analyzer or one of its checks.
gohawk doc lockorder
gohawk doc lockorder/missing-release
# Use it with go vet.
go vet -vettool="$(command -v gohawk)" ./...
# Run a selected analyzer, or exclude one from the defaults.
gohawk -enable=concurrentcapture ./...
gohawk -disable=concurrentcapture ./...
# Run complete analyzer groups with their default checks.
gohawk -enable-groups=concurrency,resources ./...
# Run one experimental check by its ID.
gohawk -enable-checks=producerlifecycle/unclosed-range ./...
# Remove groups from the ordinary run or from -enable-all.
gohawk -disable-groups=concurrency ./...
# Run every analyzer and check.
gohawk -enable-all ./...gohawk aims to complement other Go analyzers, not replace them. Each tool looks for a different kind of problem, so running several together catches more than any one alone.
Deep, flow-based analysis of Go already covers several domains well. NilAway covers nil safety, gosec covers security and taint analysis, and Staticcheck covers a broad range of general bugs. Resource management and concurrency are among the last big gaps, and that is the domain gohawk focuses on.
gohawk can run as a module plugin inside a custom golangci-lint binary. See the golangci-lint integration guide for build and configuration instructions.
Contributions are welcome. See How to contribute for the development workflow, analyzer requirements, and verification steps.
gohawk was developed with assistance from LLMs, and AI-assisted contributions are permitted. Contributors must disclose AI usage, and every contribution must meet the project's strict standards for quality, testing, analyzer precision, and human readability. See the full AI policy.
If gohawk is useful to you or your organization, consider sponsoring its continued development. Sponsorship helps fund maintenance, new analyzers, and improvements to the documentation and developer experience. To discuss sponsorship, get in touch with @kojah.
Licensed under the MIT License.
