github / github/codeql

Go: `LoadGoModules` incorrectly still flags 1.23 as an invalid toolchain

Open
#18,447 2 comments 0 reactions 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

The Go team had a change of heart in Go 1.23 and re-permitted `go 1.23` as an alias for `go 1.23.0`

The change in behaviour in 1.23 is referenced in this comment on this well-cited GH issue on the confusion around the go directive changes:

![image](https://github.com/user-attachments/assets/cd30e750-f034-4d88-896d-5d408d900b86)

https://github.com/golang/go/issues/62278#issuecomment-2062002018

However, CodeQL is flagging this as invalid due to not using 1.N.P syntax:

> Invalid Go toolchain version
>
> As of Go 1.21, toolchain versions [must use the 1.N.P syntax](https://go.dev/doc/toolchain#version).
>
> 1.23 in go.mod does not match this syntax and there is no additional toolchain directive, which may cause some go commands to fail.

**Code samples or links to source code**

Reduced testcase pushed as a sample repo here with CodeQL scanning enabled:

https://github.com/dnwe/go-codeql

**URL to the alert on GitHub code scanning**

https://github.com/dnwe/go-codeql/security/code-scanning/tools/CodeQL/status/configurations/actions-FZTWS5DIOVRC653POJVWM3DPO5ZS6Y3PMRSXC3BNMFXGC3DZONUXGLTZNVWA/c1646cb64b746876ea230e833d950329e5308885d88be821300b330d9b9a7f83

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.