Packages
zlow install reads go.mod and go.sum and fills vendor. Compiling stays on the Go page.
How it fits
zlow does two different jobs for Go. The compiler turns .go files into a native binary with zlow native. That command does not read go.mod. The package manager downloads the modules named in go.mod and writes their .go files under vendor.
Installing zlow itself is npm install @zlow/cli. After that command exists, zlow install inside a directory with go.mod installs that module’s requirements. zlow install does not compile. When you want a binary, run zlow native ..
Install dependencies
Name each module with an exact version. A version starts with v and contains a dot. A pseudo-version is exact.
module example.com/app
go 1.25.3
require example.com/leaf v1.2.3
zlow install
zlow install --offlineThe first successful install writes zlow.lock next to go.mod. Commit that file. Later installs repeat it and do not fetch the module again. The lock’s language is go. Each requirement’s version in the lock is the exact version from go.mod.
Downloads come from https://proxy.golang.org. Pass --registry to use another module proxy for this one command. A file: URL reads a directory on disk. zlow fetches .mod and .zip, and checks each against the h1: line in go.sum. It does not rewrite go.sum. The zip is cached at ~/.cache/zlow/gomod, or under $XDG_CACHE_HOME/zlow/gomod when that variable is set. .go files from the zip are written to vendor/<module>/. zlow native skips vendor.
Install again
A second zlow install reads zlow.lock. When go.mod is unchanged, zlow uses the copies already in the cache. --offline does the same and does not open a proxy connection. Changing go.mod after a lock exists stops with error[pm.lock_stale].
Limits
These are refused before a module is kept:
- A version that is not exact (
latest,v1, a range). That ispm.version_range. - A
replacedirective (pm.replace_directive), anexcludedirective (pm.exclude_directive), or aretractline in the downloaded.mod(pm.retract_directive). - A missing
go.sumline (pm.integrity_missing) or bytes that do not match it (pm.integrity_mismatch). - A version the proxy does not have (
pm.version_unsatisfied). - A private
GOPROXYwith a user and password, orZLOW_GOPROXY_TOKEN(pm.goproxy_auth). GOFLAGScontaining-mod=mod(pm.goflags_mod).- A zip entry whose path contains
..(pm.path_escape). A zip that is not readable (pm.archive_unreadable). zlow run,zlow exec,zlow add,zlow remove, andzlow publish(pm.usage). Go packages have no scripts.
The message looks like error[pm.version_range]. The name after pm. says which limit you hit. Python, Rust, and C++ stay compilers. A Go project with zlow.json and no go.mod stops with error[pm.not_a_package].