# XO1305: xo.lock has no hash for a module version

Every module version the build selects must be recorded in xo.lock, so the content of a build is pinned and checked. A require line was added or changed by hand, or a dependency upgrade raised the version of a module further down the graph. `xo mod tidy` (or `xo get`) records the hashes; commit xo.lock with xo.mod. See core 4.3 and decision 0086.

## Example

```xo
// xo.mod edited by hand, xo.lock not updated
require github.com/acme/billing v1.5.0
```

## Fix

```xo
xo mod tidy   # writes the v1.5.0 hashes to xo.lock
```

Run `xo explain XO1305` for this text in a terminal, or see
[section 10.6 of the specification](../../spec/core/#106-diagnostic-codes).

