That only works if no one is using your module as a dependency.
> So any url / GitHub repo works so no module can permanently own a name.
Only if go mod understands the source control mechanism, and only if the HTTP server in front of that speaks the survival go mod protocol. It's a horrible system that the go team doesn't use internally.
Go mod works by cloning the remote repository you import (unless the module it is working on has a replace directive). It does this via HTTPS or Git ssh or other source control mechanisms, based on the form of the import link and your GOPROXY and GOPRIVATE environment variables and their various flags and options. For each source control mechanism, it has some specific way to decide exactly what version to sync to (such as git tags to chose a specific commit).
It also depends on how you have configured your source control in your local environment, as that is what will ultimately download the code - if you want to download modules from repos that require various forms of authentication, it's up to every dev to configure credentials for each of these (or theoretically someone could mirror them to a single repo with common auth).
It's still important to note that replace directives are only used when building that particular module. Say module A depends on module B. Module B has a dependency on module github.com/proj/C, but locally adds a replace directive to replace github.com/proj/C with bitbucket.com/proj/C. When running go mod in B's folder, it will download the version of C from BitBucket. But, when building module A, it will download module C from GitHub. Replace directives are just for local builds, your dependents don't look at them.
Vendoring helps a bit, but it's still ugly.
Same problems exist in other languages, although "import numpy as np" doesn't explicitly say that you're importing a random head from someone's master.
import com.mysql.cj.jdbcYou don't import HEAD from master. Do you even understand how go.mod, go.sum and the checksum database work?
‘require “leftpad”’ may look safer, but is in fact not, and unless you happen to know what is in the standard library of Node.js off the top of your head, provides not so much as a clue that the library is even third party.
Golang has a pretty solid standard library and process to extend it. The 'x' packages are all reasonably vetted and close to official libraries: https://pkg.go.dev/golang.org/x You could easily make a decree in a codebase that you won't depend on random github code and only use stuff from trusted sources like standard library, x, etc.
Sure, python is just implicitly doing so, is that any better? Lets say you know nothing about python or numpy. You see "import numpy". What/who is numpy? How is it provisioned? Is there only one thing called numpy? How do you know it's installed locally/site-packages/editable/PYTHONPATH? You can answer these questions, but not immediately. Numpy is a poor example because it's so well know, but the other day I was trying to sort out "from pylab import *". Can't "pip install pylab". Turns out, matplotlib provides it, but for weird legacy reasons, pylab is a top level namespace.
The whole point is, if you don't trust "liyue201", then you can immediately know not to import that package. It's completely explicit in what it's doing, and no one is making you install libs from github.