Repository navigation
Go: Analyze action fails when repo requires go 1.27.0 or greater #22394
Description
Activity
- changed the title
[-]CodeQL action fails when repo required go 1.27.0 or greater[/-][+]CodeQL action fails when repo requires go 1.27.0 or greater[/+]on Aug 20, 2026 - changed the title
[-]CodeQL action fails when repo requires go 1.27.0 or greater[/-][+]Go: Analyze action fails when repo requires go 1.27.0 or greater[/+]on Aug 20, 2026 This is expected. We just merged the needed changes to make Go 1.27 available. These will be part of the next release, which should be released next week.
Reacted by silverwind- added a commit that references this issue
on Aug 23, 2026 - added a commit that references this issue
on Aug 24, 2026 This is expected. We just merged the needed changes to make Go 1.27 available. These will be part of the next release, which should be released next week.
Confirming the same failure is still live today on GitHub Code Quality's managed
Analyze (go)job (CodeQL CLI 2.26.3, 2026-08-24).Public repro: https://github.com/attune-io/attune/actions/runs/32759507318/job/97534699260
go: go.mod requires go >= 1.27.0 (running go 1.26.6; GOTOOLCHAIN=local) ... A fatal error occurred: Exit status 1 from command: [.../codeql/go/tools/autobuild.sh]That workflow is not editable (Code Quality default setup). Our own
Securityworkflow already passes because it runsactions/setup-gofromgo.mod.On 2.26.3,
maxGoVersionis still 1.26, sogetVersionWhenGoModVersionTooHighdoes not request a toolchain install when the runner already has 1.26.6. Thengo list/ the extractor inheritGOTOOLCHAIN=localfrom the hosted runner and die.#22042 should fix the next bundle (
maxGoVersion = 1.27). Do you have an ETA for that CLI/bundle cut? Code Quality will stay red on every 1.27 repo until GitHub ships it.If useful, I can open a follow-up PR so the next Go release does not hard-fail the same way: when
go.modis abovemaxGoVersion, still callInstallVersion(you already do this for other "too high" cells) instead of returning no install when the env is already at max. Happy to wait if you would rather just ship 2.26.4.Do you have an ETA for that CLI/bundle cut?
As I wrote last week: These will be part of the next release, which should be released next week [so sometime before 29th of August].
10. when
go.modis abovemaxGoVersion, still callInstallVersionIt's not clear that this is safe, and doesn't cause unexpected/silent failures, which would be bad.
(you already do this for other "too high" cells) instead of returning no install when the env is already at max.
I don't know what you mean by this.
In a repo with
go 1.27.0ingo.mod, theAnalyze (Go)task fails because underGOTOOLCHAIN=local, Go can not dynamically switch its toolchain. Recommend to run withGOTOOLCHAIN=autoto let Go switch.Example failure from this run: