Read --version from Go build info - #372
Merged
Merged
Conversation
mbyczkowski
marked this pull request as ready for review
September 23, 2026 20:11
mbyczkowski
enabled auto-merge
September 23, 2026 20:11
randradesq
approved these changes
Sep 28, 2026
mbyczkowski
disabled auto-merge
September 28, 2026 19:04
mbyczkowski
enabled auto-merge
September 28, 2026 19:05
mbyczkowski
force-pushed
the
mbyczkowski/version-from-build-info
branch
from
September 28, 2026 19:05
3992878 to
be49d2d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
certigo --versionprints a string that is hard-coded incli/cli.go. Someone has to edit it before each release, and the edit is easy to miss. It was wrong in 3 of the last 6 releases:--versionprintsGo already records the module version in every binary it builds.
go version -mon the v1.18.0 release binary showsv1.18.0, but the binary prints 1.17.1.What
--versionnow prints the version that Go records at build time, so a release needs no version edit. Builds without git metadata can still set the version with-ldflags -X.How
appVersion()returns the first of these that is set:-Xoverride:-ldflags "-X github.com/square/certigo/cli.version=1.18.1".debug.ReadBuildInfo().Main.Version, minus the leadingv. This keeps today's format:1.18.1, notv1.18.1.(devel).What each kind of build prints:
--versionv1.18.11.18.1go install github.com/square/certigo@v1.18.11.18.1go buildat an untagged commit1.18.1-0.20260923190547-3992878d286cgo buildwith uncommitted changes+dirtygo run,-buildvcs=false(devel)goline ingo.modis1.25.0, so every toolchain that can build certigo does this.--help-manputs the version in the man page header, so the man page follows the same rules.Risk
Low for
go installusers and release downloads. They get the right version with no other change.Homebrew builds from the GitHub source tarball, which has no git metadata. Until the formula passes the version in, Homebrew builds print
(devel). Today they print the stale1.17.1. See Bigger picture for the formula fix.Testing
All builds used go1.27.1 on darwin/arm64:
v1.18.1tag on this commit:go build -o certigo . && ./certigo --versionprints1.18.1.actions/checkoutdoes on a tag push:git clone --depth=1 --no-tags, thengit fetch --depth=1 origin +refs/tags/v1.18.1:refs/tags/v1.18.1. The build prints1.18.1.git archivetarball of that tag, built with./build: prints(devel).GOFLAGS=-ldflags=-X=github.com/square/certigo/cli.version=1.18.1 ./build: prints1.18.1, andman/certigo.1starts with.TH certigo 1 1.18.1.go install github.com/square/certigo@3992878d286c8ef8b073fddba1bad3656deaaea2prints1.18.1-0.20260923190547-3992878d286c.go version -mon the v1.18.0 release asset showsmod github.com/square/certigo v1.18.0. The release workflow already builds with the tag in place.Bigger picture
./build: setENV["GOFLAGS"] = "-ldflags=-X=github.com/square/certigo/cli.version=#{version}"beforesystem "./build". I tested thatGOFLAGSform with./build, but not inside Homebrew.Generated with Claude Code