This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 41 · Oct 6 – 12, 2025

go1.24.8 release

Breakingstdlib

What changed
Security fixes to archive/tar, crypto/tls, crypto/x509, encoding/asn1, encoding/pem, net/http, net/mail, net/textproto, net/url; bug fixes to compiler, linker, debug/pe, net/http, os, sync/atomic.
Production impact
The source does not say.
Try it
Upgrade to 1.24.8 and run go test ./... to ensure no test failures.
Source
go.dev/doc/devel/release#go1.24.8

Understand it, then run it

Go 1.24.8 was released on 2025‑10‑07. It contains security fixes for several standard packages: archive/tar, crypto/tls, crypto/x509, encoding/asn1, encoding/pem, net/http, net/mail, net/textproto, and net/url. There are also bug fixes for the compiler, the linker, debug/pe, net/http, os, and sync/atomic. The change is a maintenance update; it does not add new language features or APIs.

Run it now

Todaygo
// This program demonstrates that the standard library still works after the
// security and bug fixes in Go 1.24.8. It uses net/http to fetch a small
// resource from a local server and prints the response body. The code
// compiles and runs on Go 1.27.1, which already includes the 1.24.8 fixes.
package main

import (
	"fmt"
	"io"
	"net/http"
	"net/http/httptest"
)

func main() {
	// Set up a simple test server that returns a fixed response.
	ts := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
		fmt.Fprintln(w, "Hello, world!")
	}))
	defer ts.Close()

	// Make a GET request to the test server.
	resp, err := http.Get(ts.URL)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()

	// Read and print the response body.
	body, err := io.ReadAll(resp.Body)
	if err != nil {
		panic(err)
	}
	fmt.Print(string(body))
}

What it printed when we ran it on Go 1.27.1

Hello, world!

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed