github / github/codeql

Update from Go 1.20 to 1.22 causes CodeQL to no longer detect that we built Go code

Open
#17,526 6 comments 0 reactions 1 assignee Claimed by @mbg View on GitHub
Go question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

We use CodeQL through GitHub Actions and had an issue with CodeQL no longer finding Go code when we updated Go from 1.20 to 1.22. Our build actually builds the Go toolset itself, so it's probably a little unusual.

Broken run with debug logs: https://github.com/microsoft/go/actions/runs/10920221364/job/30391782040

> CodeQL detected code written in Go but this run didn't build any of it

Example success with debug logs: https://github.com/microsoft/go/actions/runs/10934919945/job/30391982309

Both use:

```
"productName" : "CodeQL",
"vendor" : "GitHub",
"version" : "2.18.4",
"sha" : "9c5e434eb23805aa8a8574b87b24eae476ca8615",
"branches" : [
"codeql-cli-2.18.4"
],
```

The PR that triggered the broken run updated Go from 1.20.6 to 1.22.6. The example success *may* include some other changes, and I can produce a cleaner example if necessary, but I don't expect that anything important changed.

* Seemed related to this issue at first, but it was fixed and we still see this: https://github.com/github/codeql-action/issues/2467

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.