This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 3 · Jan 13 – 19, 2025from 5 items

The Go team released two patch releases, 1.22.11 and 1.23.5, both addressing security and bug fixes in core packages. Several proposals were accepted, notably deprecating and removing two test‑only packages from x/tools, adding a pre‑authentication callback to the SSH library, and introducing an XOF interface to the hash package.

Worth knowingstdlib

go1.23.5 release

What changed
The release includes security fixes to the crypto/x509 and net/http packages, as well as bug fixes to the compiler, the runtime, and the net package.
Production impact
The source does not say.
Try it
Run go version to confirm you are on 1.23.5 and rebuild your binaries.
Source
go.dev/doc/devel/release#go1.23.5
Explain it and run it

Understand it, then run it

Run it now

Todaygo
package main

import (
	"crypto/x509"
	"fmt"
)

func main() {
	// Create a simple certificate pool to show that the crypto/x509 package
	// is available and can be used without errors after the security fixes
	// shipped in go1.23.5.
	pool := x509.NewCertPool()
	fmt.Println("Certificate pool created:", pool != nil)
}

What it printed when we ran it on Go 1.27.1

Certificate pool created: true

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingstdlib

go1.22.11 release

What changed
The release includes security fixes to the crypto/x509 and net/http packages, as well as bug fixes to the runtime.
Production impact
The source does not say.
Try it
Run go version to confirm you are on 1.22.11 and rebuild your binaries.
Source
go.dev/doc/devel/release#go1.22.11

Worth knowingecosystem

x/crypto/ssh: add ServerConfig.PreAuthConnCallback, ServerPreAuthConn (banner) interface

What changed
The proposal is to add the following interface type and configurable callback to golang.org/x/crypto/ssh: ServerPreAuthConn interface with a SendAuthBanner method, and a PreAuthConnCallback field on ServerConfig.
Production impact
The source does not say.
Try it
Create an ssh.ServerConfig, set PreAuthConnCallback, and observe banner handling.
Source
github.com/golang/go/issues/68688

Worth knowingstdlib

hash: add XOF interface

What changed
The proposal is to add the following API to package hash: an XOF interface with Write, Read, Reset, and BlockSize methods, and to add a BlockSize method to the underlying implementation of blake2.XOF.
Production impact
The source does not say.
Try it
Import "hash" and type‑assert a blake2.XOF to hash.XOF to use the new interface.
Source
github.com/golang/go/issues/69518
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates that the proposed `hash.XOF` interface is not
// available in the Go 1.27.1 standard library. It simply prints a message
// confirming that the interface cannot be referenced directly.
package main

import "fmt"

func main() {
	fmt.Println("hash.XOF is not part of the Go 1.27.1 standard library")
}

What it printed when we ran it on Go 1.27.1

hash.XOF is not part of the Go 1.27.1 standard library

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Nice to knowtooling

x/tools/go/{packages/packagestest,expect}: deprecate, tag, and delete

What changed
The proposal is to fork the golang.org/x/tools/go/packages/packagestest and golang.org/x/tools/go/expect packages to an internal subtree, and then to tag and delete the public packages using the same process as #59676.
Production impact
The source does not say.
Try it
Search your codebase for imports of these packages and plan to remove them.
Source
github.com/golang/go/issues/70229
Explain it and run it

Understand it, then run it

The packages golang.org/x/tools/go/packages/packagestest and golang.org/x/tools/go/expect were originally meant only for tests inside the x/tools repository. They were published publicly without a formal review process, so any change to them had to go through a lengthy proposal. Because they are rarely used outside x/tools, the maintainers decided to move them into an internal location and then delete the public versions. This means that code that imports those packages will no longer compile once the deletion is complete.

Run it now

Todaygo
// This program demonstrates the deprecation of the public packages
// golang.org/x/tools/go/packages/packagestest and golang.org/x/tools/go/expect.
// Since the packages have been removed, attempting to import them would
// result in a compile error. The program simply prints a message.
package main

import "fmt"

func main() {
	fmt.Println("packagestest and expect have been deprecated and deleted.")
}

What it printed when we ran it on Go 1.27.1

packagestest and expect have been deprecated and deleted.

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Exercise

Write a small program that uses the new hash.XOF interface to compute a SHAKE‑256 hash of the string “hello” and read 32 bytes from it.

The 60-second version

Welcome to this week’s Radar. The Go team has just pushed two patch releases, 1.22.11 and 1.23.5, both tightening security in the crypto and net packages and squashing a handful of bugs in the runtime, compiler, and networking stack. In tooling, the team decided to retire two test‑only packages from x/tools, moving them into an internal subtree and marking the public packages for deletion. On the networking side, the SSH library now offers a pre‑authentication callback, letting servers send banners at any point before authentication completes. Finally, the hash package has been extended with an XOF interface, giving developers a standard way to work with extendable‑output functions like SHAKE and BLAKE2X. Those changes are all in the release notes and proposals; the next step is to update your builds and libraries accordingly.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed