Skip to content

CI: Add advanced CodeQL workflow that installs Go from go.mod - #4807

Closed
TomOnTime wants to merge 1 commit into
mainfrom
tlim_v5_codeql_go127
Closed

TomOnTime wants to merge 1 commit into
mainfrom
tlim_v5_codeql_go127

Conversation

@TomOnTime

@TomOnTime TomOnTime commented Aug 25, 2026 •

Copy link
Copy Markdown
Collaborator

Enable CodeQL advanced mode so that we can specify Go 1.27 before CodeQL updates their default.

CodeQL's managed "default setup" runs the Go extractor's autobuild with
the runner's pre-installed Go and GOTOOLCHAIN=local, which forbids
downloading a newer toolchain. Now that go.mod requires `go 1.27` but the
CodeQL runner only ships Go 1.26.x, extraction fails before compiling:

  go: go.mod requires go >= 1.27 (running go 1.26.7; GOTOOLCHAIN=local)
  Extraction failed for all discovered Go projects.
  CodeQL job status was configuration error.

Replace default setup with an advanced workflow that runs
actions/setup-go with go-version-file: go.mod before init/autobuild, so
the required toolchain is the "local" one and GOTOOLCHAIN=local is
satisfied.

NOTE: Default setup must be disabled in the repo settings
(Settings -> Code security -> CodeQL analysis: Default -> Advanced),
otherwise the two configurations conflict.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@TomOnTime TomOnTime closed this Aug 25, 2026
@TomOnTime
TomOnTime deleted the tlim_v5_codeql_go127 branch September 30, 2026 01:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant