ci: derive Go version from go.mod instead of 'stable'
cron-checker / vulnerabilities (pull_request) Successful in 55s
cron-checker / test (pull_request) Successful in 1m2s
cron-checker / build (pull_request) Successful in 8m34s

actions/setup-go resolves 'stable' from the go-versions manifest, which lagged behind the go1.26.6 security release and installed the vulnerable go1.26.5. That both failed govulncheck and broke builds once go.mod required >= 1.26.6 (GOTOOLCHAIN=local).

Using go-version-file keeps CI on exactly the toolchain go.mod asks for, which Renovate already keeps current.
This commit is contained in:
2026-08-17 09:17:03 +02:00
parent 6258421a47
commit b8b75bcf2b
+2 -2
View File
@@ -14,7 +14,7 @@ jobs:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
go-version: 'stable'
go-version-file: go.mod
- name: Run tests
run: go test -race -coverprofile=coverage.txt ./...
@@ -24,7 +24,7 @@ jobs:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
go-version: 'stable'
go-version-file: go.mod
- name: Check vulnerabilities
run: |
go install golang.org/x/vuln/cmd/govulncheck@latest