Skip to content

Go: Analyze action fails when repo requires go 1.27.0 or greater #22394

Description

@silverwind

In a repo with go 1.27.0 in go.mod, the Analyze (Go) task fails because under GOTOOLCHAIN=local, Go can not dynamically switch its toolchain. Recommend to run with GOTOOLCHAIN=auto to let Go switch.

Example failure from this run:

[2026-08-20 08:27:16] [build-stderr] 2026/08/20 08:27:16 Error running go tooling: err: exit status 1: stderr: go: go.mod requires go >= 1.27 (running go 1.26.6; GOTOOLCHAIN=local)

Activity

  1. changed the title [-]CodeQL action fails when repo required go 1.27.0 or greater[/-] [+]CodeQL action fails when repo requires go 1.27.0 or greater[/+] on Aug 20, 2026
  2. changed the title [-]CodeQL action fails when repo requires go 1.27.0 or greater[/-] [+]Go: Analyze action fails when repo requires go 1.27.0 or greater[/+] on Aug 20, 2026
  3. jketema commented on Aug 20, 2026

    @jketema
    Contributor

    This is expected. We just merged the needed changes to make Go 1.27 available. These will be part of the next release, which should be released next week.

  4. SebTardif commented on Aug 24, 2026

    @SebTardif

    @jketema

    This is expected. We just merged the needed changes to make Go 1.27 available. These will be part of the next release, which should be released next week.

    Confirming the same failure is still live today on GitHub Code Quality's managed Analyze (go) job (CodeQL CLI 2.26.3, 2026-08-24).

    Public repro: https://github.com/attune-io/attune/actions/runs/32759507318/job/97534699260

    go: go.mod requires go >= 1.27.0 (running go 1.26.6; GOTOOLCHAIN=local)
    ...
    A fatal error occurred: Exit status 1 from command: [.../codeql/go/tools/autobuild.sh]
    

    That workflow is not editable (Code Quality default setup). Our own Security workflow already passes because it runs actions/setup-go from go.mod.

    On 2.26.3, maxGoVersion is still 1.26, so getVersionWhenGoModVersionTooHigh does not request a toolchain install when the runner already has 1.26.6. Then go list / the extractor inherit GOTOOLCHAIN=local from the hosted runner and die.

    #22042 should fix the next bundle (maxGoVersion = 1.27). Do you have an ETA for that CLI/bundle cut? Code Quality will stay red on every 1.27 repo until GitHub ships it.

    If useful, I can open a follow-up PR so the next Go release does not hard-fail the same way: when go.mod is above maxGoVersion, still call InstallVersion (you already do this for other "too high" cells) instead of returning no install when the env is already at max. Happy to wait if you would rather just ship 2.26.4.

  5. jketema commented on Aug 24, 2026

    @jketema
    Contributor

    Do you have an ETA for that CLI/bundle cut?

    As I wrote last week: These will be part of the next release, which should be released next week [so sometime before 29th of August].

  6. jketema commented on Aug 24, 2026

    @jketema
    Contributor

    10. when go.mod is above maxGoVersion, still call InstallVersion

    It's not clear that this is safe, and doesn't cause unexpected/silent failures, which would be bad.

    (you already do this for other "too high" cells) instead of returning no install when the env is already at max.

    I don't know what you mean by this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions