Radar · Go · Archive · Week 32 · Aug 4 – 10, 2025
go1.24.6 released
Worth knowingstdlib
- What changed
- The release includes security fixes to the
database/sqlandos/execpackages, as well as bug fixes to the runtime. - Production impact
- The source does not say.
- Try it
- Upgrade to Go 1.24.6 and run
go test ./...to ensure your code compiles. - Source
- go.dev/doc/devel/release#go1.24.6
Understand it, then run it
Go 1.24.6 was released on 2025‑08‑06. The update fixes security issues in the database/sql and os/exec packages and patches the runtime. Nothing new is added to the language; the change is purely a bug fix. If you run Go code that uses os/exec or database/sql, the behaviour you expect will now be safe from the vulnerabilities that were fixed.
Run it now
// This program demonstrates that os/exec works normally after the 1.24.6 security patch.
// It runs the "echo" command and prints its output.
package main
import (
"bytes"
"fmt"
"os/exec"
)
func main() {
// Prepare the command: echo "Hello, world!"
cmd := exec.Command("echo", "Hello, world!")
var out bytes.Buffer
cmd.Stdout = &out
if err := cmd.Run(); err != nil {
fmt.Println("command failed:", err)
return
}
fmt.Print(out.String())
}
What it printed when we ran it on Go 1.27.1
Hello, world!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed