Improve toolchain handling#460
Conversation
|
Testing this action https://github.com/matthewhughes934/setup-go-test, see the workflow runs for details https://github.com/matthewhughes934/setup-go-test/actions |
switch off of `go-version-file` in the Github Actions, because it doesn't work great with the new `go mod tidy` format that go 1.22 does. See: * [Improve toolchain handling actions/setup-go#460](actions/setup-go#460) * [More specific handling/detection of Go toolchain versions actions/setup-go#457](actions/setup-go#457)
switch off of `go-version-file` in the Github Actions, because it doesn't work great with the new `go mod tidy` format that go 1.22 does. See: * [Improve toolchain handling actions/setup-go#460](actions/setup-go#460) * [More specific handling/detection of Go toolchain versions actions/setup-go#457](actions/setup-go#457)
switch off of `go-version-file` in the Github Actions, because it doesn't work great with the new `go mod tidy` format that go 1.22 does. See: * [Improve toolchain handling actions/setup-go#460](actions/setup-go#460) * [More specific handling/detection of Go toolchain versions actions/setup-go#457](actions/setup-go#457)
be5f1f1 to
145e58d
Compare
|
This PR effectively addresses and fixes #457. The implementation:
This change will prevent the unexpected behavior where specifying The breaking change is well-documented and justified - users who rely on automatic toolchain downloads will need to adjust their workflows, but this brings the action in line with official Go Docker images and provides more predictable behavior. |
|
Did you rebase already? GitHub doesn't allow me to see the parent commit. |
The vulnerability reported is also present on $ git checkout main
$ git rev-parse HEAD
8e57b58e57be52ac95949151e2777ffda8501267
$ npm audit --audit-level=high
# npm audit report
form-data >=4.0.0 <4.0.4 || <2.5.4
Severity: critical
form-data uses unsafe random function in form-data for choosing boundary - https://github.com/advisories/GHSA-fjxv-7rqg-78g4
form-data uses unsafe random function in form-data for choosing boundary - https://github.com/advisories/GHSA-fjxv-7rqg-78g4
fix available via `npm audit fix`
node_modules/@azure/core-http/node_modules/form-data
node_modules/@types/node-fetch/node_modules/form-data
node_modules/form-data
1 critical severity vulnerability
To address all issues, run:
npm audit fixThe vulnerability is two days old: GHSA-fjxv-7rqg-78g4, here's a separate PR for that #618 (though I'm not sure why |
|
Dependabot doesn't always work as you would expect, it's not resilient for example, a simple network error can disable updates. Here is your failed run from 2 days ago, only maintainers are allowed to read the logs: As long as AI reviews haven't been enabled, only manual maintainer work could speed-up reviews. |
145e58d to
c58ae12
Compare
|
I've dropped the commit that changed behaviour from install the Go version specified in the |
c58ae12 to
7d12308
Compare
|
I'm holding my breath based on #618 |
|
Thank you for your thoughtful work on this PR, After reviewing the code changes in detail, We wanted to highlight a specific scenario where the current implementation does not fully satisfy one of our core criteria: Scenario: When a workflow uses only a go.mod file that contains both a go directive and a toolchain directive (with the toolchain version being higher), and there is no explicit go-version or GOTOOLCHAIN=local set in the workflow. Current Code Behavior: The action installs and uses the Go version from the go directive, rather than the one specified in the toolchain directive. Expected Behavior (per our criteria and official Go documentation): In this situation, the action should detect the presence of the toolchain directive in go.mod and install or use the toolchain version (for example, go1.22.6). The toolchain directive is meant to indicate the intended Go toolchain for the project and should take precedence if no explicit workflow overrides are present.
Could you please update the logic so that when only a go.mod file is present and both directives exist, the action installs and uses the Go version from the toolchain directive unless overridden by the workflow or environment? You can also make use of implementing the go-version-directive option if required, which you have suggested as per your earlier comment. This adjustment will ensure that all scenarios are covered and that the action's behavior aligns with both our criteria and the expectations of Go users relying on toolchain directives. Additionally, please update the documentation to reflect any changes or new options you introduce, so users are aware of how the action now handles these scenarios and how to configure it for their needs. Once this is addressed, we can discuss progressing the PR further. Thank you again for your contribution ! |
7d12308 to
0348eaa
Compare
I've just rebased my changes on |
* CI workflows: upgrade setup-go action to v6 https://github.com/actions/setup-go/releases/tag/v6.0.0 to make use actions/setup-go#460 to specify Go version for development and CI pipelines in a single place (go.mod file). * Bumped Go toolchain from 1.24.4 to 1.24.7 for security fixes, eg grpc-ecosystem#267 (after a release)
This pull request is a hotfix for pulumi/pulumi-tls#888. In all other workflows, we allow for Mise to install the Go version but we decided to keep the legacy implementation where we allow for the setup-go job to install the version instead. Setup-go shipped a change actions/setup-go#460 where the gotoolchain is now installed using `local` not `auto` and this keeps the verify-release workflow from installing a Go version other than the one set in the tool version. This change makes it so the verify-release job uses at least Go v1.22.
This pull request is a hotfix for pulumi/pulumi-tls#888. In all other workflows, we allow for Mise to install the Go version but we decided to keep the legacy implementation where we allow for the setup-go job to install the version instead. Setup-go shipped a change actions/setup-go#460 where the gotoolchain is now installed using `local` not `auto` and this keeps the verify-release workflow from installing a Go version other than the one set in the tool version. Update: It turns out that v1.22.x is not enough: https://github.com/pulumi/pulumi-gcp/actions/runs/19448883749/job/55655199413#step:17:54 > Error: exec: go: go.mod requires go >= 1.23.3 (running go 1.21.13; GOTOOLCHAIN=local) so rather than bumping the Go version, this pull request sets the go toolchain to `auto` so the workflow downloads it as before.
This pull request is a hotfix for pulumi/pulumi-tls#888. In all other workflows, we allow for Mise to install the Go version but we decided to keep the legacy implementation where we allow for the setup-go job to install the version instead. Setup-go shipped a change actions/setup-go#460 where the gotoolchain is now installed using `local` not `auto` and this keeps the verify-release workflow from installing a Go version other than the one set in the tool version. Update: It turns out that v1.22.x is not enough: https://github.com/pulumi/pulumi-gcp/actions/runs/19448883749/job/55655199413#step:17:54 > Error: exec: go: go.mod requires go >= 1.23.3 (running go 1.21.13; GOTOOLCHAIN=local) so rather than bumping the Go version, this pull request sets the go toolchain to `auto` so the workflow downloads it as before.
This pull request is a hotfix for pulumi/pulumi-tls#888. In all other workflows, we allow for Mise to install the Go version but we decided to keep the legacy implementation where we allow for the setup-go job to install the version instead. Setup-go shipped a change actions/setup-go#460 where the gotoolchain is now installed using `local` not `auto` and this keeps the verify-release workflow from installing a Go version other than the one set in the tool version. Update: It turns out that v1.22.x is not enough: https://github.com/pulumi/pulumi-gcp/actions/runs/19448883749/job/55655199413#step:17:54 > Error: exec: go: go.mod requires go >= 1.23.3 (running go 1.21.13; GOTOOLCHAIN=local) so rather than bumping the Go version, this pull request sets the go toolchain to `auto` so the workflow downloads it as before.
This pull request is a hotfix for pulumi/pulumi-tls#888. In all other workflows, we allow for Mise to install the Go version but we decided to keep the legacy implementation where we allow for the setup-go job to install the version instead. Setup-go shipped a change actions/setup-go#460 where the gotoolchain is now installed using `local` not `auto` and this keeps the verify-release workflow from installing a Go version other than the one set in the tool version. Update: It turns out that v1.22.x is not enough: https://github.com/pulumi/pulumi-gcp/actions/runs/19448883749/job/55655199413#step:17:54 > Error: exec: go: go.mod requires go >= 1.23.3 (running go 1.21.13; GOTOOLCHAIN=local) so rather than bumping the Go version, this pull request sets the go toolchain to `auto` so the workflow downloads it as before.
This pull request is a hotfix for pulumi/pulumi-tls#888. In all other workflows, we allow for Mise to install the Go version but we decided to keep the legacy implementation where we allow for the setup-go job to install the version instead. Setup-go shipped a change actions/setup-go#460 where the gotoolchain is now installed using `local` not `auto` and this keeps the verify-release workflow from installing a Go version other than the one set in the tool version. Update: It turns out that v1.22.x is not enough: https://github.com/pulumi/pulumi-gcp/actions/runs/19448883749/job/55655199413#step:17:54 > Error: exec: go: go.mod requires go >= 1.23.3 (running go 1.21.13; GOTOOLCHAIN=local) so rather than bumping the Go version, this pull request sets the go toolchain to `auto` so the workflow downloads it as before.
This pull request is a hotfix for pulumi/pulumi-tls#888. In all other workflows, we allow for Mise to install the Go version but we decided to keep the legacy implementation where we allow for the setup-go job to install the version instead. Setup-go shipped a change actions/setup-go#460 where the gotoolchain is now installed using `local` not `auto` and this keeps the verify-release workflow from installing a Go version other than the one set in the tool version. Update: It turns out that v1.22.x is not enough: https://github.com/pulumi/pulumi-gcp/actions/runs/19448883749/job/55655199413#step:17:54 > Error: exec: go: go.mod requires go >= 1.23.3 (running go 1.21.13; GOTOOLCHAIN=local) so rather than bumping the Go version, this pull request sets the go toolchain to `auto` so the workflow downloads it as before.
The go binary job's `actions/setup-go@v5` runs on Node 20 — same deprecation as #173's checkout/cache/setup-node round but on an action that wasn't in the workflow at the time. Bump to `@v6` (Node 24 since v6.0.0, 2025-09-04). v6.0.0 also lists a breaking change in toolchain selection (actions/setup-go#460). Our usage is the simplest form — `go-version: '1.24'` plus `cache: true` — so the new toolchain-handling logic should be a no-op for us. CI on this PR confirms.
#172 (#176) Parallel to #168 (which bumped helm-ci.yaml). GitHub Actions deprecates Node 20 on **2026-06-02** (forced Node 24 default) and removes Node 20 entirely on 2026-09-16. release.yaml was still on the Node-20 pins: - actions/checkout@v4 → @v5 (93cb6efe..., Node 24) - actions/setup-go@v5 → @v6.4.0 (4a360112..., Node 24) setup-go@v6 introduces one breaking change beyond the runtime bump: "toolchain handling" (actions/setup-go#460) now honours go.mod's `toolchain` directive by default. We have: go 1.26.0 toolchain go1.26.3 and release.yaml passes `go-version: 1.26.3` via env.GO_VERSION — match with the toolchain directive, so no functional change. If we ever bump the toolchain ahead of GO_VERSION, v6 would auto-download the newer Go which is the desired behaviour anyway. Workflow only runs on `tags: ["v*"]`, so this PR can't smoke-test itself. Verification happens on the next pre-alpha tag push. Related: #172 (closes), #168 (helm-ci.yaml analog), ADR 0014.
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-go](https://github.com/actions/setup-go) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/setup-go (actions/setup-go)</summary> ### [`v6.4.0`](https://github.com/actions/setup-go/releases/tag/v6.4.0) [Compare Source](actions/setup-go@v6.3.0...v6.4.0) ##### What's Changed ##### Enhancement - Add go-download-base-url input for custom Go distributions by [@​gdams](https://github.com/gdams) in [#​721](actions/setup-go#721) ##### Dependency update - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​727](actions/setup-go#727) ##### Documentation update - Rearrange README.md, add advanced-usage.md by [@​priyagupta108](https://github.com/priyagupta108) in [#​724](actions/setup-go#724) - Fix Microsoft build of Go link by [@​gdams](https://github.com/gdams) in [#​734](actions/setup-go#734) ##### New Contributors - [@​gdams](https://github.com/gdams) made their first contribution in [#​721](actions/setup-go#721) **Full Changelog**: <actions/setup-go@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-go/releases/tag/v6.3.0) [Compare Source](actions/setup-go@v6.2.0...v6.3.0) ##### What's Changed - Update default Go module caching to use go.mod by [@​priyagupta108](https://github.com/priyagupta108) in [#​705](actions/setup-go#705) - Fix golang download url to go.dev by [@​178inaba](https://github.com/178inaba) in [#​469](actions/setup-go#469) **Full Changelog**: <actions/setup-go@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-go/releases/tag/v6.2.0) [Compare Source](actions/setup-go@v6.1.0...v6.2.0) ##### What's Changed ##### Enhancements - Example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​696](actions/setup-go#696) - Update Node.js version in action.yml by [@​ccoVeille](https://github.com/ccoVeille) in [#​691](actions/setup-go#691) - Documentation update of actions/checkout by [@​deining](https://github.com/deining) in [#​683](actions/setup-go#683) ##### Dependency updates - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot) in [#​682](actions/setup-go#682) - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5 by [@​salmanmkc](https://github.com/salmanmkc) in [#​695](actions/setup-go#695) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot) in [#​686](actions/setup-go#686) - Upgrade qs from 6.14.0 to 6.14.1 by [@​dependabot](https://github.com/dependabot) in [#​703](actions/setup-go#703) ##### New Contributors - [@​ccoVeille](https://github.com/ccoVeille) made their first contribution in [#​691](actions/setup-go#691) - [@​deining](https://github.com/deining) made their first contribution in [#​683](actions/setup-go#683) **Full Changelog**: <actions/setup-go@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-go/releases/tag/v6.1.0) [Compare Source](actions/setup-go@v6...v6.1.0) ##### What's Changed ##### Enhancements - Fall back to downloading from go.dev/dl instead of storage.googleapis.com/golang by [@​nicholasngai](https://github.com/nicholasngai) in [#​665](actions/setup-go#665) - Add support for .tool-versions file and update workflow by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​673](actions/setup-go#673) - Add comprehensive breaking changes documentation for v6 by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​674](actions/setup-go#674) ##### Dependency updates - Upgrade eslint-config-prettier from 10.0.1 to 10.1.8 and document breaking changes in v6 by [@​dependabot](https://github.com/dependabot) in [#​617](actions/setup-go#617) - Upgrade actions/publish-action from 0.3.0 to 0.4.0 by [@​dependabot](https://github.com/dependabot) in [#​641](actions/setup-go#641) - Upgrade semver and [@​types/semver](https://github.com/types/semver) by [@​dependabot](https://github.com/dependabot) in [#​652](actions/setup-go#652) ##### New Contributors - [@​nicholasngai](https://github.com/nicholasngai) made their first contribution in [#​665](actions/setup-go#665) - [@​priya-kinthali](https://github.com/priya-kinthali) made their first contribution in [#​673](actions/setup-go#673) - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​674](actions/setup-go#674) **Full Changelog**: <actions/setup-go@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/setup-go/releases/tag/v6.0.0) [Compare Source](actions/setup-go@v6...v6) ##### What's Changed ##### Breaking Changes - Improve toolchain handling to ensure more reliable and consistent toolchain selection and management by [@​matthewhughes934](https://github.com/matthewhughes934) in [#​460](actions/setup-go#460) - Upgrade Nodejs runtime from node20 to node 24 by [@​salmanmkc](https://github.com/salmanmkc) in [#​624](actions/setup-go#624) Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. [See Release Notes](https://github.com/actions/runner/releases/tag/v2.327.1) ##### Dependency Upgrades - Upgrade [@​types/jest](https://github.com/types/jest) from 29.5.12 to 29.5.14 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​589](actions/setup-go#589) - Upgrade [@​actions/tool-cache](https://github.com/actions/tool-cache) from 2.0.1 to 2.0.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​591](actions/setup-go#591) - Upgrade [@​typescript-eslint/parser](https://github.com/typescript-eslint/parser) from 8.31.1 to 8.35.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​590](actions/setup-go#590) - Upgrade undici from 5.28.5 to 5.29.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​594](actions/setup-go#594) - Upgrade typescript from 5.4.2 to 5.8.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​538](actions/setup-go#538) - Upgrade eslint-plugin-jest from 28.11.0 to 29.0.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​603](actions/setup-go#603) - Upgrade `form-data` to bring in fix for critical vulnerability by [@​matthewhughes934](https://github.com/matthewhughes934) in [#​618](actions/setup-go#618) - Upgrade actions/checkout from 4 to 5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​631](actions/setup-go#631) ##### New Contributors - [@​matthewhughes934](https://github.com/matthewhughes934) made their first contribution in [#​618](actions/setup-go#618) - [@​salmanmkc](https://github.com/salmanmkc) made their first contribution in [#​624](actions/setup-go#624) **Full Changelog**: <actions/setup-go@v5...v6.0.0> ### [`v6`](actions/setup-go@v5.6.0...v6) [Compare Source](actions/setup-go@v5.6.0...v6) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTcuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIxNy4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: hoodn <hood.noah@gmail.com> Reviewed-on: https://gitea.k3s.noah-hood.io/hoodn/certmanager-porkbun-webhook/pulls/7 Co-authored-by: renovate-bot <renovate-bot@example.local> Co-committed-by: renovate-bot <renovate-bot@example.local>
Configure environment to avoid toolchain installs
Force
goto always use the local toolchain (i.e. the one the one thatshipped with the go command being run) via setting the
GOTOOLCHAINenvironment variable to
local[1]:This is how things are setup in the official Docker images (e.g.[2], see
also the discussion around that change[3]). The motivation behind this
is to:
toolchain will be detected, the toolchain will be detected and then
another version of Go installed[4]
version (e.g.
1.21.0) but your go.mod contains atoolchainorgodirective for a newer version (e.g.
1.22.0) then, without any otherconfiguration/environment setup, any go commands will be run using go
1.22.0This will be a breaking change for some workflows. Given a
go.modlike:
Then running any
gocommand, e.g.go mod tidy, in an environmentwhere only go versions before
1.22.0were installed would previouslytrigger a toolchain download of Go
1.22.0and that version being usedto execute the command. With this change the above would error out with
something like:
Link: https://go.dev/doc/toolchain#select [1]
Link: https://github.com/docker-library/golang/blob/dae3405a325073e8ad7c8c378ebdf2540d8565c4/Dockerfile-linux.template#L163 [2]
Link: proposal: set GOTOOLCHAIN=local (or =path) in our image docker-library/golang#472 [3]
Link: Tar errors on cache restore after toolchain installation #424 [4]
Issue: More specific handling/detection of Go toolchain versions #457
Prefer installing version from
toolchaindirectivePrefer this over the version from the
godirective. Per the docs[1]It seems reasonable to use this, since running this action in a
directory containing a
go.mod(orgo.work) suggests the user iswishing to work with the module or workspace.
Link: https://go.dev/doc/toolchain#config [1]
Issue: More specific handling/detection of Go toolchain versions #457