Skip to content

Pin the Go version for release builds - #380

Merged
mbyczkowski merged 1 commit into
masterfrom
mbyczkowski/pin-release-go-version
Sep 30, 2026
Merged

mbyczkowski merged 1 commit into
masterfrom
mbyczkowski/pin-release-go-version

Conversation

@mbyczkowski

Copy link
Copy Markdown
Contributor

Why

The release workflow builds the binaries with go-version: stable. That means the Go version is whatever is newest on the day a tag is pushed. v1.18.0 got Go 1.26.2 and v1.18.1 got Go 1.27.1, and nothing in the repo shows or controls that choice.

The go 1.25.0 line in go.mod doesn't help here. It is only the oldest Go that can build certigo, not the compiler the release uses.

What

  • release.yaml builds the binaries with exactly Go 1.27.1, the version that built v1.18.1.
  • compilecheck.yaml uses the same version, so PRs are checked with the release toolchain.
  • Both jobs set GOTOOLCHAIN=local.

How

actions/setup-go v5.5.0 does not set GOTOOLCHAIN, and Go defaults to auto. With auto, a dependency bump can raise the go line in go.mod above the installed version. Go then downloads a newer toolchain and builds with it, so the pin alone would not hold.

GOTOOLCHAIN=local makes the build fail with a clear error instead. Compile Check shows that failure on the PR that caused it, before anything is tagged.

check-latest: true is gone because it does nothing for an exact version.

Risk

Low. Only CI changes. The release workflow runs only on tag pushes, so this PR can't exercise it; the next tag will.

The Compile Check job names change from (stable, …) to (1.27.1, …). They are not required checks. test.yaml and lint.yaml still use stable, so unit and integration tests keep running on the newest Go.

Testing

I ran the release build step locally with Go 1.27.1, GOTOOLCHAIN=local and CGO_ENABLED=0 for linux/amd64, darwin/arm64 and windows/amd64. All three built, and go version <binary> shows go1.27.1.

I checked the guard in a scratch copy with go.mod raised to go 1.28.0:

  • GOTOOLCHAIN=local go build . fails with go: go.mod requires go >= 1.28.0 (running go 1.27.1; GOTOOLCHAIN=local).
  • GOTOOLCHAIN=auto go build . tries to switch: go: downloading go1.28.0 (darwin/arm64).

actionlint v1.7.12 reports no issues in either file.

Bigger picture

The pin does not move on its own. Dependabot here only updates Go modules. Bump the version in both files when a Go release has fixes you want in the binaries. A PR that raises the go line above the pin must bump the pin too.

Generated with Claude Code

@mbyczkowski
mbyczkowski marked this pull request as ready for review September 28, 2026 20:12
@mbyczkowski
mbyczkowski requested a review from a team as a code owner September 28, 2026 20:12
@mbyczkowski
mbyczkowski force-pushed the mbyczkowski/pin-release-go-version branch from ef8ed56 to a078b95 Compare September 30, 2026 21:07
@mbyczkowski
mbyczkowski merged commit f59f296 into master Sep 30, 2026
23 checks passed
@mbyczkowski
mbyczkowski deleted the mbyczkowski/pin-release-go-version branch September 30, 2026 21:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants