Xo is experimental. The source code is not public yet; it will be soon. Read the release notes
Menu · XO1313

Docs

XO1313: fetched module version disagrees with the checksum log

error · reported by the modules

With XO_SUMDB naming a checksum log (<name>+<key id>+<public key> [<URL>]), the first fetch of every module version (from git or a proxy) is checked against the log before it enters the module cache: the log’s record of the version must hold the same tree and xo.mod hashes, the record must be in the tree the log signed (an inclusion proof), the tree head must carry a valid signature by the configured key, and the tree must extend every tree this module cache saw from the log before (a consistency proof). Any failure means someone is serving different content for the same version (a moved tag, a tampered proxy or mirror) or the log itself forked or rewrote history. Nothing is cached or built. Find out which source changed before trusting it. A private module that the log can never see belongs in XO_NOSUMDB. See core 4.3 and decision 0124.

Example

XO_SUMDB="sum.example.com+1a2b3c4d+<key>" xo mod tidy
# github.com/acme/billing v1.4.0 was retagged after the log recorded it

Fix

# investigate the source; for a private module that never reaches the log:
XO_NOSUMDB=github.com/acme/private xo mod tidy

Run xo explain XO1313 for this text in a terminal, or see section 10.6 of the specification.