feat(go): move the Go track onto go-tools
Implements spec 0074 (D15). Unblocks phpbotscout spec 0013.
go-lint, go-test, go-security and goreleaser now default to go-tools:v0.1.0 rather than dev-tools:v0.3.4.
Why now, out of order
This is step 6 of the split, brought forward for the Go track while rust-tools is still unbuilt. Nothing about it depended on rust-tools — defaults were sequenced last because they are consumer-visible, not because of a dependency, and per-track is the natural granularity.
| size | gate-visible findings | |
|---|---|---|
dev-tools |
977 MB | 66 |
go-tools |
423 MB | 46 |
A Go repository no longer pulls a Rust toolchain it never invokes, nor that toolchain's share of the findings — not one of dev-tools' 66 came from Rust, which is the whole argument for splitting.
Validated by a consumer, not by inspection
phpbotscout's pkg/embed suite, run inside go-tools:v0.1.0 by the phpbotscout session:
go-tools:v0.1.0 38 pass, 0 skip, 0 fail
dev-tools:latest 38 pass, 0 skip, 0 fail (baseline)The zero skips are the number that matters: those tests skip silently without an ONNX runtime, so a suite can report green while exercising nothing. All four runtime-dependent tests ran, including TestTheGoldenVectorHasNotMoved — so the runtime digest carried across the split unchanged.
Also confirmed in the published artefact rather than a probe build: libonnxruntime.so → .so.1 → .so.1.28.0 plus libonnxruntime_providers_shared.so, all resolved by ldconfig, headers at /usr/local/include/onnxruntime.
It unblocks a real consumer
dev-tools:v0.3.4 was tagged 2026-08-14; the ONNX Runtime landed on dev-tools main on the 18th. So there is no dev-tools tag carrying the runtime, and phpbotscout's embed tests skip today however they are configured. The alternative was an override in phpbotscout against that repo's own stated convention of leaving toolchain images at component defaults.
Verified before changing anything
Every binary each component invokes, present in go-tools:v0.1.0:
go · golangci-lint · goreleaser · goreleaser-pro · syft · govulncheck
ONNXRUNTIME_LIB=/usr/local/lib/libonnxruntime.soTwo descriptions were sharpened rather than just renamed, where the new image genuinely differs: go-test now mentions the ONNX Runtime, and go-security records that govulncheck is built from source against the image's own Go — which is why it reports current (Go: go1.26.6) while the four prebuilt binaries carry whatever their maintainers used. That contrast is why scan:tools is advisory rather than a gate in the image repos.
Not breaking
dev-tools keeps publishing through the deprecation cycle, so a consumer pinning it explicitly is unaffected. This changes a default, not an availability.
The remaining dev-tools reference in go-lint.md is the Explanation page about the consolidated image, now labelled "the consolidated predecessor" — history, not a stale default.