This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 33 · Aug 11 – 17, 2025from 6 items

The Go team accepted several proposals that extend tooling, cryptography, and the Windows syscall API, and released Go 1.25 with a number of new standard‑library packages and experimental features.

Worth knowingtooling

x/tools/go/analysis/structtag: stricter JSON tag checking

What changed
The structtag analyzer now checks for JSON tags that are a single dash ("-") or contain omitempty and reports them as errors.
Production impact
The source does not say.
Try it
Run go vet ./... on a project that has a struct field tagged with json:"-" to see the new error.
Source
github.com/golang/go/issues/74376
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the new structtag analyzer behavior.
// It defines a struct with a JSON tag that is a single dash ("-").
// When run with `go vet`, the analyzer will report an error for this tag.
// The program itself compiles and runs fine; the error is only in static analysis.

package main

import (
	"encoding/json"
	"fmt"
)

type Example struct {
	Secret string `json:"-"`
}

func main() {
	e := Example{Secret: "hidden"}
	b, _ := json.Marshal(e)
	fmt.Println(string(b)) // prints {}
}

What it printed when we ran it on Go 1.27.1

{}

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingecosystem

x/crypto/x509roots/fallback: export certificate bundle

What changed
A new golang.org/x/crypto/x509roots/fallback/bundle package was added that exposes the NSS trust store root certificates as a read‑only sequence of Root values.
Production impact
The source does not say.
Try it
Import the package and iterate over bundle.Roots() to list the DER‑encoded certificates.
Source
github.com/golang/go/issues/69898
Explain it

Understand it, then run it

The Go standard library can verify TLS certificates, but it needs a list of trusted root certificates. On Linux the list comes from the NSS trust store, and Go ships a copy of that list inside the x/crypto/x509roots package. Before this change that list was only used internally; you could not access it from your own code. Now a new golang.org/x/crypto/x509roots/fallback/bundle package exposes the bundle as a read‑only sequence of Root values, so you can read the DER bytes of each root certificate.

Worth knowingecosystem

x/crypto/ssh: add SSHSIG support

What changed
The proposal to support encoding and decoding the SSHSIG signature format was accepted and is now in the active proposal column.
Production impact
The source does not say.
Try it
Read the proposal and experiment with the suggested CreateBlob, Encode, and Decode functions in a local fork of x/crypto/ssh.
Source
github.com/golang/go/issues/68197

Worth knowingecosystem

syscall: add Open O_* flags for Windows FILE_FLAG_* flags

What changed
New constants such as O_FILE_FLAG_OPEN_NO_RECALL were added to golang.org/x/sys/windows, and syscall.Open on Windows now accepts them and rejects unknown bits.
Production impact
The source does not say.
Try it
On Windows, call syscall.Open with O_FILE_FLAG_OPEN_NO_RECALL and observe that the flag is passed to the OS.
Source
github.com/golang/go/issues/73676
Explain it

Understand it, then run it

On Windows, the syscall.Open function can now accept a set of flags that match the native FILE_FLAG_* options. These flags let you control how a file is opened, for example whether the file is opened for overlapped (asynchronous) I/O or whether the file should be deleted when the last handle is closed. The change adds constants such as O_FILE_FLAG_OPEN_NO_RECALL to the golang.org/x/sys/windows package, and syscall.Open will pass those flags straight to the operating system. If you try to pass a flag that the runtime does not understand, syscall.Open will return an error instead of silently ignoring the bit.

Worth knowingecosystem

go1.25.0 released

What changed
Go 1.25 was released, bringing container‑aware GOMAXPROCS, the testing/synctest package, experimental GC, experimental encoding/json/v2, and more.
Production impact
The source does not say.
Try it
Run go version to confirm you are on 1.25 and explore the new packages in the standard library.
Source
go.dev/doc/devel/release#go1.25.0
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the current GOMAXPROCS value.
// The new container‑aware behavior is not yet available in Go 1.27.1,
// so we simply print the value returned by runtime.GOMAXPROCS(0).
package main

import (
	"fmt"
	"runtime"
)

func main() {
	// runtime.GOMAXPROCS(0) returns the current maximum number of CPUs
	// that can execute simultaneously. In a container this is the
	// container's CPU quota if the feature is enabled.
	max := runtime.GOMAXPROCS(0)
	fmt.Printf("GOMAXPROCS: %d\n", max)
}

What it printed when we ran it on Go 1.27.1

GOMAXPROCS: 2

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Exercise

Exercise – Detect unsafe JSON tags

Write a small program that inspects the struct tags of a type and reports any field that has a JSON tag that is a single dash ("-") or contains the word omitempty. The program should print the field name and the offending tag.

Startergo
package main

import (
	"fmt"
	"reflect"
)

type Person struct {
	Name    string `json:"name"`
	Age     int    `json:"-"`
	Secret  string `json:"secret,omitempty"`
	Email   string `json:"email"`
	Password string
}

func main() {
	// TODO: Inspect the Person type and print any unsafe JSON tags
}
Show a solution
Solutiongo
package main

import (
	"fmt"
	"reflect"
	"strings"
)

type Person struct {
	Name     string `json:"name"`
	Age      int    `json:"-"`
	Secret   string `json:"secret,omitempty"`
	Email    string `json:"email"`
	Password string
}

func main() {
	t := reflect.TypeOf(Person{})
	for i := 0; i < t.NumField(); i++ {
		f := t.Field(i)
		tag := f.Tag.Get("json")
		if tag == "" {
			continue
		}
		// Split on comma to ignore options after the name
		parts := strings.Split(tag, ",")
		name := parts[0]
		if name == "-" || strings.Contains(tag, "omitempty") {
			fmt.Printf("Field %s has unsafe JSON tag: %q\n", f.Name, tag)
		}
	}
}

What it printed when we ran it on Go 1.27.1

Field Age has unsafe JSON tag: "-"
Field Secret has unsafe JSON tag: "secret,omitempty"

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

The 60-second version

This week the Go team added several new tools and libraries to help developers write safer and more reliable code. They tightened the static analysis of JSON struct tags, making it easier to catch accidental omissions or misconfigurations. A new package now lets you programmatically access the NSS trust store’s root certificates, giving you more control over TLS verification. The SSH package is expanding to support the SSHSIG signature format, and the Windows syscall package now accepts a richer set of file‑opening flags, improving interoperability with native APIs. Finally, Go 1.25 was released, bringing container‑aware scheduling, a new synctest package for testing concurrent code, experimental garbage collection, and a preview of a new JSON encoder. These changes are all available in the current release, and developers can start experimenting with them today.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed