Skip to content

fix(go): let the govulncheck install fetch the Go toolchain it needs - #506

Merged
catinspace-au merged 1 commit into
mainfrom
fix/go-tools-toolchain
Oct 3, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/go-tools-toolchain

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

On a hosted runner setup-go installs the project's go.mod version and pins GOTOOLCHAIN=local. govulncheck v1.8.0 needs Go 1.26, so any Go repo declaring an older go fails Quality at tool install (ci-test-go-app run 37084005822). ARC skips setup-go and carries a newer Go, so only the free-runner path hits it.

One line: GOTOOLCHAIN=auto on that single go install.

Rehearsed on hosted ubuntu-26.04 (ci-test-go-app run 37084850006): Setup Go tools now logs 'switching to go1.26.8' and the pin assert passes. Quality still fails there, on a real finding: the fixture's go 1.22 stdlib carries GO-2025-3750. That's fixed in the fixture (hyperi-io/ci-test-go-app#106), and I'll re-rehearse once it lands.

Refs #501

On hosted runners setup-go installs the project's go.mod version and pins GOTOOLCHAIN=local. govulncheck v1.8.0 needs Go 1.26, so on any repo declaring an older go the Quality job fails at tool install (ci-test-go-app run 37084005822, go 1.22). ARC runners skip setup-go and carry a newer Go, which is why it only shows on the free-runner path.

Refs #501
@catinspace-au

Copy link
Copy Markdown
Contributor Author

Internal-ref rehearsals on hosted ubuntu-26.04 (branch rehearse/go-tools-26, which points setup-go-tools at this change):

  • ci-test-go-app run 37084850006, go.mod still at 1.22: 'go: golang.org/x/vuln@v1.8.0 requires go >= 1.26.0; switching to go1.26.8', then 'ok govulncheck: v1.8.0'. The install that failed in run 37084005822 now works. Quality still failed there, on a real finding: go 1.22 stdlib advisories.
  • After hyperi-io/ci-test-go-app#107 (go 1.26, merged 5fc1975): run 37086445494 green end to end, 'Image: ubuntu-26.04', govulncheck passed.

The plain rehearsal of f609e09 that the gate asks for is running.

@catinspace-au

Copy link
Copy Markdown
Contributor Author

Gate re-run: ci-test-go-app proven (run 37086898498). The remaining line is the composite note, which the plain rehearsal can't satisfy. The internal-ref rehearsals above are the evidence for setup-go-tools: 37084850006 installs govulncheck via go1.26.8 on a go 1.22 project, and 37086445494 is green end to end on ubuntu-26.04. Merging on that, same basis as #502.

@catinspace-au
catinspace-au merged commit ab4ab90 into main Oct 3, 2026
20 of 22 checks passed
@catinspace-au
catinspace-au deleted the fix/go-tools-toolchain branch October 3, 2026 01:56
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Released in v2.12.10 -- https://github.com/hyperi-io/hyperi-ci/releases/tag/v2.12.10

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant