From 59bad58a5edce47e322227689552d292560c0fcc Mon Sep 17 00:00:00 2001 From: Tom Limoncelli Date: Tue, 25 Aug 2026 16:38:04 -0400 Subject: [PATCH] CI: Add advanced CodeQL workflow that installs Go from go.mod CodeQL's managed "default setup" runs the Go extractor's autobuild with the runner's pre-installed Go and GOTOOLCHAIN=local, which forbids downloading a newer toolchain. Now that go.mod requires `go 1.27` but the CodeQL runner only ships Go 1.26.x, extraction fails before compiling: go: go.mod requires go >= 1.27 (running go 1.26.7; GOTOOLCHAIN=local) Extraction failed for all discovered Go projects. CodeQL job status was configuration error. Replace default setup with an advanced workflow that runs actions/setup-go with go-version-file: go.mod before init/autobuild, so the required toolchain is the "local" one and GOTOOLCHAIN=local is satisfied. NOTE: Default setup must be disabled in the repo settings (Settings -> Code security -> CodeQL analysis: Default -> Advanced), otherwise the two configurations conflict. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/codeql.yml | 59 ++++++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000000..fab2960a3b --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,59 @@ +name: "CodeQL" + +# Advanced CodeQL setup. +# +# This replaces GitHub's "default setup" for CodeQL. The default setup runs the +# Go extractor's autobuild with whatever Go is pre-installed on the runner and +# with GOTOOLCHAIN=local, which forbids downloading a newer toolchain. When +# go.mod requires a Go version newer than the runner's (e.g. `go 1.27` while the +# runner only has 1.26.x), extraction fails with: +# +# go: go.mod requires go >= 1.27 (running go 1.26.x; GOTOOLCHAIN=local) +# +# Installing Go from go.mod before the extractor runs makes the required +# toolchain the "local" one, so autobuild succeeds. +# +# NOTE: An advanced workflow and the repository's "default setup" cannot both be +# active. Disable default setup under +# Settings -> Code security -> CodeQL analysis (switch Default -> Advanced). + +on: + push: + branches: [main, master, release_candidate_v5] + pull_request: + branches: [main, master, release_candidate_v5] + schedule: + - cron: "0 0 * * 1" + +concurrency: + group: codeql-${{ github.ref }} + cancel-in-progress: true + +jobs: + analyze: + name: Analyze (go) + runs-on: ubuntu-latest + permissions: + security-events: write + actions: read + contents: read + + steps: + - name: Checkout repository + uses: actions/checkout@v7 + + - name: Set up Go + uses: actions/setup-go@v7 + with: + go-version-file: go.mod + + - name: Initialize CodeQL + uses: github/codeql-action/init@v4 + with: + languages: go + build-mode: autobuild + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v4 + with: + category: "/language:go"