Skip to content

Version information missing from exe file #10601

Description

@2PintChristianN

Describe the bug

ProductVersion and FileVersion should be set in .exe at buildtime.
This affects version management and ability to find any vulnerable versions

Affected versions

Probably all, but verified with these gh --version
gh version 2.63.1 (2024-12-03)
https://github.com/cli/cli/releases/tag/v2.63.1
gh version 2.67.0 (2025-02-11)
https://github.com/cli/cli/releases/tag/v2.67.0
gh version 2.68.1 (2025-03-06)
https://github.com/cli/cli/releases/tag/v2.68.1

Steps to reproduce the behavior

Check details from explorer, or this in powershell:

[System.Diagnostics.FileVersionInfo]::GetVersionInfo("C:\Program Files\GitHub CLI\gh.exe")

Expected vs actual behavior

ProductVersion   FileVersion      FileName
--------------   -----------      --------
2.68.1 (2025-03-26)             2.68.1                     C:\Program Files\GitHub CLI\gh.exe

Actual:

ProductVersion   FileVersion      FileName
--------------   -----------      --------
                                  C:\Program Files\GitHub CLI\gh.exe

Image

Activity

  1. iamazeem commented on Mar 14, 2025

    @iamazeem
    Contributor

    Steps to reproduce on Linux (Ubuntu) with pwsh:

    # Build
    $ make clean && make GOOS=windows
    
    $ file bin/gh
    bin/gh: PE32+ executable (console) x86-64, for MS Windows
    
    
    # Check version info
    $ pwsh -c '[System.Diagnostics.FileVersionInfo]::GetVersionInfo("./bin/gh")'
    
    ProductVersion   FileVersion      FileName
    --------------   -----------      --------
                                      /path/to/cli/bin/gh
    
    $ pwsh -c '[System.Diagnostics.FileVersionInfo]::GetVersionInfo("./bin/gh").ToString()'
    File:             /path/to/cli/bin/gh
    InternalName:     
    OriginalFilename: 
    FileVersion:      
    FileDescription:  
    Product:          
    ProductVersion:   
    Debug:            False
    Patched:          False
    PreRelease:       False
    PrivateBuild:     False
    SpecialBuild:     False
    Language:         
  2. 2PintChristianN commented on Mar 14, 2025

    @2PintChristianN
    Author

    Out of curiosity i did some minor digging
    Setting version info in Go compiled binaries does require some extra work, and there seems to be more then one package to kind of do the same thing
    https://stackoverflow.com/questions/35126344/how-to-set-the-file-version-field-in-pe-header-of-exe-files

  3. iamazeem commented on Mar 14, 2025

    @iamazeem
    Contributor

    Tested https://github.com/tc-hib/go-winres with a sample program on Windows 10 and it works fine.

    Here's the complete list of commands for Powershell using go-winres simply (JSON file not required):

    > mkdir versioninfo
    > cd versioninfo
    
    > go mod init versioninfo
    > go install github.com/tc-hib/go-winres@latest
    
    > Set-Content -Path main.go -Encoding UTF8 -Value "
    >> package main
    >>
    >> //go:generate go-winres simply --product-version=1.0.0.1234 --file-version=1.0.0.1234
    >>
    >> func main() {}
    >> "
    
    > go generate
    2025/03/14 18:00:10 did not find icon  winres/icon.png
    
    > go build
    
    > [System.Diagnostics.FileVersionInfo]::GetVersionInfo("C:/Users/azeem/Downloads/versioninfo/versioninfo.exe")
    
    ProductVersion   FileVersion      FileName
    --------------   -----------      --------
    1.0.0.1234       1.0.0.1234       C:/Users/azeem/Downloads/versioninfo/versioninfo.exe
    
    > [System.Diagnostics.FileVersionInfo]::GetVersionInfo("C:/Users/azeem/Downloads/versioninfo/versioninfo.exe").ToString()
    File:             C:/Users/azeem/Downloads/versioninfo/versioninfo.exe
    InternalName:
    OriginalFilename:
    FileVersion:      1.0.0.1234
    FileDescription:
    Product:
    ProductVersion:   1.0.0.1234
    Debug:            False
    Patched:          False
    PreRelease:       False
    PrivateBuild:     False
    SpecialBuild:     False
    Language:         Language Neutral

    Image

    Looks like there'll be a hook for goreleaser to generate *.syso file to be used later by go build. 🤔

  4. added
    enhancementa request to improve CLI
    windowsRelated to Windows hosts or runners
    and removed
    bugSomething isn't working
    on May 5, 2025
  5. BagToad commented on May 5, 2025

    @BagToad
    Member

    👋 Hey everyone, I labelled this as an enhancement request because I don't think we ever intended to include version information in the Windows binary - I could be wrong about it, but that's my impression at the moment.

    That said, I think this seems like something that would make sense for us to do.

  6. 2PintChristianN commented on May 6, 2025

    @2PintChristianN
    Author

    👋 Hey everyone, I labelled this as an enhancement request because I don't think we ever intended to include version information in the Windows binary - I could be wrong about it, but that's my impression at the moment.

    That said, I think this seems like something that would make sense for us to do.

    How can you NOT include version information? That essentially means that we have no clue what is installed.
    Just as an example, When any vulnerability is found we wound have a safe way to know for sure what is there, should we keep generating checksums of the binary to track which version it is?

    This is a clear bug, even if you did intend to have this bug from the beginning, it shows a great deal of disregard for what Windows binaries should contain, and all it's users.

  7. BagToad commented on May 6, 2025

    @BagToad
    Member

    @caspChristian - thank you for the discussion.

    I think our team has different definitions of what a bug is, and I gather that is the cause of the frustration here. I want to emphasize that I did not dispute the value of this feature. In fact, I think you have made a compelling case for it with the security angle, alongside aligning with what is typically expected from Windows binaries 👍 Hearing this sort of feedback is very helpful to understand what users on particular platforms value. As far as I know, this has not been brought up previously.

    I want to assure you that labelling this as an enhancement does not affect prioritization or whether we would accept this work. Labels like enhancement are mostly for the core team and our processes, aligning with criteria we have established and what we feel best represents our intentions with the product.

  8. andyfeller commented on May 19, 2025

    @andyfeller
    Contributor

    Additional notes and increasing scope for other required information

    Following up as a related request and digging into this a bit, I think there are likely several of the following properties we would want to set within the .syso file for Windows users:

    • CompanyName: GitHub
    • FileDescription: GitHub CLI
    • FileVersion: Version being released; same as ProductVersion
    • InternalName: gh
    • OriginalFilename: gh.exe
    • ProductName: GitHub CLI
    • ProductVersion: Version being released; same as FileVersion

    References

    Here are some additional details I uncovered coming at this:

    • https://go.dev/wiki/GcToolchainTricks

      Go documentation explaining how go build works with .syso files

    • https://github.com/josephspurrier/goversioninfo

      Generates a .syso file like windres to be used with go build

    • rclone/rclone@6a2b7b9

      Example of project using goversioninfo tool to generate .syso file

    • VERSIONINFO resource

      This is the technical documentation behind the version info under discussion

      Property Description
      Comments Additional information that should be displayed for diagnostic purposes.
      CompanyName Company that produced the file—for example, Microsoft Corporation or Standard Microsystems Corporation, Inc. This string is required.
      FileDescription File description to be presented to users. This string may be displayed in a list box when the user is choosing files to install—for example, Keyboard Driver for AT-Style Keyboards. This string is required.
      FileVersion Version number of the file—for example, 3.10 or 5.00.RC2. This string is required.
      InternalName Internal name of the file, if one exists—for example, a module name if the file is a dynamic-link library. If the file has no internal name, this string should be the original filename, without extension. This string is required.
      LegalCopyright Copyright notices that apply to the file. This should include the full text of all notices, legal symbols, copyright dates, and so on. This string is optional.
      LegalTrademarks Trademarks and registered trademarks that apply to the file. This should include the full text of all notices, legal symbols, trademark numbers, and so on. This string is optional.
      OriginalFilename Original name of the file, not including a path. This information enables an application to determine whether a file has been renamed by a user. The format of the name depends on the file system for which the file was created. This string is required.
      PrivateBuild Information about a private version of the file—for example, Built by TESTER1 on \TESTBED. This string should be present only if VS_FF_PRIVATEBUILD is specified in the fileflags parameter of the root block.
      ProductName Name of the product with which the file is distributed. This string is required.
      ProductVersion Version of the product with which the file is distributed—for example, 3.10 or 5.00.RC2. This string is required.
      SpecialBuild Text that specifies how this version of the file differs from the standard version—for example, Private build for TESTER1 solving mouse problems on M250 and M250E computers. This string should be present only if VS_FF_SPECIALBUILD is specified in the fileflags parameter of the root block.
  9. self-assigned this
    on May 30, 2025
  10. babakks commented on May 30, 2025

    @babakks
    Member

    Thanks everyone for investigating this issue! 🙏

    The PR #11048 is up for review.

  11. babakks commented on Jul 9, 2025

    @babakks
    Member

    @caspChristian, @iamazeem, The Windows version info are now embedded in our latest release, v2.75.0. Feel free to try it out! 🍻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementa request to improve CLIneeds-investigationCLI team needs to investigatewindowsRelated to Windows hosts or runners

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions