Go: `LoadGoModules` incorrectly still flags 1.23 as an invalid toolchain
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
The Go team had a change of heart in Go 1.23 and re-permitted `go 1.23` as an alias for `go 1.23.0`
The change in behaviour in 1.23 is referenced in this comment on this well-cited GH issue on the confusion around the go directive changes:

https://github.com/golang/go/issues/62278#issuecomment-2062002018
However, CodeQL is flagging this as invalid due to not using 1.N.P syntax:
> Invalid Go toolchain version
>
> As of Go 1.21, toolchain versions [must use the 1.N.P syntax](https://go.dev/doc/toolchain#version).
>
> 1.23 in go.mod does not match this syntax and there is no additional toolchain directive, which may cause some go commands to fail.
**Code samples or links to source code**
Reduced testcase pushed as a sample repo here with CodeQL scanning enabled:
https://github.com/dnwe/go-codeql
**URL to the alert on GitHub code scanning**
https://github.com/dnwe/go-codeql/security/code-scanning/tools/CodeQL/status/configurations/actions-FZTWS5DIOVRC653POJVWM3DPO5ZS6Y3PMRSXC3BNMFXGC3DZONUXGLTZNVWA/c1646cb64b746876ea230e833d950329e5308885d88be821300b330d9b9a7f83
貢獻指南
評估
這個 Issue 還沒有評估資料。