This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 20 · May 12 – 18, 2025from 4 items

The Go team accepted four proposals that touch the compiler, standard library, and crypto packages. No new releases or bug advisories were published this week.

Breakingstdlib

crypto/tls: disable SHA-1 signature algorithms in TLS 1.2

What changed
Support for the SHA‑1 signature algorithms rsa_pkcs1_sha1 and ecdsa_sha1 is removed from TLS 1.2. A GODEBUG=tlssha1=1 flag can restore the old behavior.
Production impact
Any service that relies on TLS 1.2 with SHA‑1 signatures will fail to negotiate a connection unless the flag is set.
Try it
Run a TLS client with GODEBUG=tlssha1=1 and observe that SHA‑1 signatures are accepted again.
Source
github.com/golang/go/issues/72883
Explain it

Understand it, then run it

TLS 1.2 still allowed certificates signed with the old SHA‑1 hash. The change removes that support. Now a TLS 1.2 connection will refuse to use a certificate that was signed with SHA‑1. If a server still uses such a certificate, clients will fail to connect unless the special GODEBUG=tlssha1=1 flag is set to re‑enable the old behaviour.

Worth knowingstdlib

go/ast: add PreorderStack, a wrapper around ast.Inspect that maintains a stack

What changed
A new helper PreorderStack traverses an AST and supplies a correctly maintained stack of ancestor nodes to the callback.
Production impact
The source does not say.
Try it
Use ast.PreorderStack to walk a parsed file and print each node’s depth.
Source
github.com/golang/go/issues/73319

Nice to knowstdlib

crypto/ecdsa: add NewPublicKey and PublicKey.Bytes

What changed
The ecdsa package now supports parsing and encoding uncompressed public keys via ParseUncompressedPublicKey and PublicKey.Bytes.
Production impact
The source does not say.
Try it
Parse a known uncompressed key with ParseUncompressedPublicKey and then round‑trip it with PublicKey.Bytes.
Source
github.com/golang/go/issues/63963

Exercise

Task Use the new ast.PreorderStack helper to walk a Go source file and print each node’s type together with the depth of its ancestor stack. Replace the manual stack logic in the starter with a call to ast.PreorderStack.

Startergo
package main

import (
	"fmt"
	"go/ast"
	"go/parser"
	"go/token"
)

func main() {
	src := `package main
func foo() {
	bar()
}`
	fset := token.NewFileSet()
	file, _ := parser.ParseFile(fset, "example.go", src, 0)

	// Manual stack traversal (incorrect if a node returns false).
	var stack []ast.Node
	ast.Inspect(file, func(n ast.Node) bool {
		if n != nil {
			stack = append(stack, n) // push
		} else {
			stack = stack[:len(stack)-1] // pop
		}
		if n != nil {
			fmt.Printf("Node: %T, depth: %d\n", n, len(stack))
		}
		return true
	})
}
Show a solution
Solutiongo
package main

import (
	"fmt"
	"go/ast"
	"go/parser"
	"go/token"
)

func main() {
	src := `package main
func foo() {
	bar()
}`
	fset := token.NewFileSet()
	file, _ := parser.ParseFile(fset, "example.go", src, 0)

	// Correct stack traversal using PreorderStack.
	ast.PreorderStack(file, nil, func(n ast.Node, stack []ast.Node) bool {
		if n != nil {
			fmt.Printf("Node: %T, depth: %d\n", n, len(stack))
		}
		return true
	})
}

What it printed when we ran it on Go 1.27.1

Node: *ast.File, depth: 0
Node: *ast.Ident, depth: 1
Node: *ast.FuncDecl, depth: 1
Node: *ast.Ident, depth: 2
Node: *ast.FuncType, depth: 2
Node: *ast.FieldList, depth: 3
Node: *ast.BlockStmt, depth: 2
Node: *ast.ExprStmt, depth: 3
Node: *ast.CallExpr, depth: 4
Node: *ast.Ident, depth: 5

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

The 60-second version

Hello, I’m here to give you a quick rundown of what the Go team delivered this week. First, the token package now has a new method that lets you add files to a FileSet in any order, which can simplify long‑running tools that process many Go source files. Next, the AST package added a helper that walks a syntax tree while keeping a correct stack of ancestor nodes; this fixes a subtle bug that could misalign the stack when you skip subtrees. In the crypto world, the TLS package has removed support for SHA‑1 signature algorithms in TLS 1.2, following the latest RFC, and you can still opt back in with a debug flag if you need to. Finally, the ecdsa package now supports parsing and emitting uncompressed public keys, giving you a more complete set of key handling utilities. Those are the highlights for this week.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed