finds.dev← search

// the find

rsc/goversion

★ 271 · Go · BSD-3-Clause · updated Jul 2024

Print version used to build Go executables

A small CLI from Russ Cox that scans a directory tree (or tar/tgz archives) and prints the Go version embedded in each executable it finds, with optional module and crypto library reporting. Useful for ops/security people auditing a fleet of binaries for stale or vulnerable Go toolchains without needing source access.

Does exactly one thing and does it from the binary alone — no source, no build metadata needed, it reads the version stamp Go embeds in every executable. The -m/-mh flags surface the full module list with versions (and hashes with -mh), which is genuinely handy for checking what dependencies actually shipped in a binary, not just what go.mod says. Written by someone who worked on the Go toolchain itself, so the binary-parsing logic (version/exe.go, asm.go) is likely to track format changes correctly rather than reverse-engineering guesswork.

No test files visible in the tree at all, for a tool whose entire job is parsing binary formats that change across Go releases — regressions on new toolchain versions would be easy to miss. Archive scanning is explicitly non-recursive (a tgz inside a tgz is invisible) and symlinks are never followed, both of which will quietly skip real files in common deployment layouts like container image exports. Last push mid-2024 with no CHANGELOG or release tags means you can't tell from the repo whether it's been validated against the newest Go versions, and there's no mention of what happens on stripped or obfuscated binaries, which is exactly the case where you'd most want this tool to work.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →