If you go through old issues at https://github.com/Bill-Stewart/SyncthingWindowsSetup/issues, you will see that these kind of false positive detections are nothing new. This is common for executables which aren’t digitally signed and are produced by unknown entities (i.e. not well-known software companies).
This is, indeed, a false-positive. I have submitted the 1.27.2 setup exe to Microsoft as a false-positive. From past experience this will probably get fixed in the next 24 to 48 hours.
You can skip the setup file and just use the official release
Yes, but then you miss out on all the convenient automation from the Windows installer (which, incidentally, is the reason I built the installer in the first place )
The last few years there has been some news some botnet and other bad software is written in Golang. So those virus and malware scanner are probably false-positive detecting this.