# XO1316: a dependency's escape hatch is not vouched for by this module

An escape hatch is code whose authority the checker cannot see: a `use c` line (C code) or a `use go` of a Go package that is not pure (anything but strconv, strings, bytes, unicode, unicode/utf8, unicode/utf16, math, math/bits, regexp, regexp/syntax, path, html, net/url, encoding/hex, encoding/base64, encoding/base32). In a module the build gets as a required version, each one needs a `vouch` line in the xo.mod of the consuming module (the main module, or a module of the active workspace): a dependency cannot vouch for itself, so its `use c ... uses none` counts only when you say so. The vouch names the exact version reviewed; an upgrade needs a new review. Without a vouch the `use c` binding performs `ffi` whatever its `uses` says. With one, it performs the vouch's `uses` (or `ffi` without it). There is no machine fix: a vouch is a human review of foreign code. See core 4.2 and decision 0156.

## Example

```xo
// github.com/acme/zip v1.2.0, a dependency:
use c "zlib.h" link "z" uses none
```

## Fix

```xo
// after reviewing the C code, in this module's xo.mod:
vouch github.com/acme/zip v1.2.0 c "zlib.h" uses none
```

Run `xo explain XO1316` for this text in a terminal, or see
[section 10.6 of the specification](../../spec/core/#106-diagnostic-codes).

