This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 44 · Oct 27 – Nov 2, 2025from 4 items

The Go team has accepted several proposals that will shape future releases. A key deprecation of the unsafe RSA‑PKCS#1 v1.5 encryption scheme is announced, and a set of legacy GODEBUG flags will be removed in Go 1.27. The standard library also gains a new `bytes.Buffer.Peek` method, and the Go blog highlights the experimental Green Tea GC that ships in Go 1.25.

Worth knowingstdlib

crypto/rsa: deprecate PKCS #1 v1.5 encryption

What changed
The proposal to deprecate PKCS #1 v1.5 encryption for RSA has been accepted and added to the active proposals list.
Production impact
The source does not say.
Try it
Review your code for calls to EncryptPKCS1v15 and consider migrating to RSA‑OAEP.
Source
github.com/golang/go/issues/75302
Explain it and run it

Understand it, then run it

The crypto/rsa package in Go used to provide a function called EncryptPKCS1v15 for encrypting data with RSA. That function used a padding scheme from PKCS #1 v1.5. The new change marks that function as *deprecated*. Deprecation means the function still works, but developers are warned that it is unsafe and should not be used. The recommendation is to switch to EncryptOAEP and DecryptOAEP, which use a safer padding scheme.

Run it now

Todaygo
// This program demonstrates the deprecation warning for RSA PKCS#1 v1.5 encryption.
// It uses the standard library only and runs in Go 1.27.1.
// The EncryptPKCS1v15 function still exists but is marked Deprecated.
// The compiler will emit a warning when this function is called.

package main

import (
	"crypto/rand"
	"crypto/rsa"
	"fmt"
)

func main() {
	// Generate a 2048‑bit RSA key for demonstration.
	priv, err := rsa.GenerateKey(rand.Reader, 2048)
	if err != nil {
		panic(err)
	}

	// Message to encrypt; must be shorter than the modulus minus 11 bytes.
	msg := []byte("Hello, RSA PKCS#1 v1.5")

	// Call the deprecated EncryptPKCS1v15 function.
	ciphertext, err := rsa.EncryptPKCS1v15(rand.Reader, &priv.PublicKey, msg)
	if err != nil {
		panic(err)
	}

	// Decrypt the ciphertext using the deprecated DecryptPKCS1v15 function.
	plain, err := rsa.DecryptPKCS1v15(rand.Reader, priv, ciphertext)
	if err != nil {
		panic(err)
	}

	fmt.Printf("Original: %s\nDecrypted: %s\n", msg, plain)
}

What it printed when we ran it on Go 1.27.1

Original: Hello, RSA PKCS#1 v1.5
Decrypted: Hello, RSA PKCS#1 v1.5

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingstdlib

crypto: remove in Go 1.27 GODEBUGs introduced in Go 1.23 and earlier

What changed
The Go team announced that the following GODEBUG flags will be removed in Go 1.27: tlsunsafeekm, tlsrsakex, tls10server, tls3des, and x509keypairleaf.
Production impact
The source does not say.
Try it
Run go test -run TestGODEBUG in a Go 1.27 environment to confirm the flags are no longer accepted.
Source
github.com/golang/go/issues/75316
Explain it and run it

Understand it, then run it

The Go team announced that five debug flags will disappear in Go 1.27. These flags are set with the environment variable GODEBUG and were added to let developers experiment with TLS and X.509 features. They were introduced in Go 1.22 and 1.23 and are now considered legacy. When you upgrade to Go 1.27, setting any of these flags will no longer have any effect.

Run it now

Todaygo
// This program demonstrates that the removed GODEBUG flags no longer work.
// In Go 1.27, setting them has no effect.  The program simply prints a message.
package main

import (
	"fmt"
	"os"
)

func main() {
	// Attempt to set a removed GODEBUG flag.
	os.Setenv("GODEBUG", "tlsunsafeekm=1")
	// In Go 1.27, this flag is ignored.
	fmt.Println("GODEBUG flags are now removed in Go 1.27; setting them has no effect.")
}

What it printed when we ran it on Go 1.27.1

GODEBUG flags are now removed in Go 1.27; setting them has no effect.

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Nice to knowstdlib

bytes: add Buffer.Peek

What changed
A new method Peek(n int) ([]byte, error) has been added to bytes.Buffer, allowing callers to inspect the next n bytes without consuming them.
Production impact
The source does not say.
Try it
Create a bytes.Buffer, write some data, and call Peek to see the slice returned.
Source
github.com/golang/go/issues/73794
Explain it and run it

Understand it, then run it

The bytes.Buffer type in Go lets you read and write byte slices. Until now, if you wanted to look at the next few bytes without actually consuming them, you had to copy the data or use a different type. A new method called Peek has been added. Peek(n int) returns the next n bytes as a slice and an error. The slice is valid only until the buffer is modified again.

Run it now

Todaygo
// This program demonstrates the new bytes.Buffer.Peek method.
// It is written for Go 1.27.1, where Peek is already available.
package main

import (
	"bytes"
	"fmt"
)

func main() {
	// Create a buffer with some data.
	var buf bytes.Buffer
	buf.WriteString("Hello, world!")

	// Peek at the first 5 bytes without consuming them.
	p, err := buf.Peek(5)
	if err != nil {
		fmt.Println("Peek error:", err)
		return
	}
	fmt.Println("Peeked bytes:", string(p)) // prints "Hello"

	// The buffer is still at the start; reading now returns the same data.
	b, _ := buf.ReadString(',')
	fmt.Println("Read after peek:", b) // prints "Hello,"
}

What it printed when we ran it on Go 1.27.1

Peeked bytes: Hello
Read after peek: Hello,

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Exercise

Create a bytes.Buffer, write the string "Hello, world!" into it, and use the new Peek method to read the first 5 bytes without consuming them. Print the peeked slice and the buffer’s length after the peek to verify that the buffer was not advanced.

Startergo
package main

import (
	"bytes"
	"fmt"
)

func main() {
	var buf bytes.Buffer
	buf.WriteString("Hello, world!")
	// TODO: peek the first 5 bytes and print the results
}
Show a solution
Solutiongo
package main

import (
	"bytes"
	"fmt"
)

func main() {
	var buf bytes.Buffer
	buf.WriteString("Hello, world!")
	peek, err := buf.Peek(5)
	if err != nil {
		fmt.Println("peek error:", err)
		return
	}
	fmt.Printf("peeked: %q\n", peek)
	fmt.Printf("buffer length after peek: %d\n", buf.Len())
}

What it printed when we ran it on Go 1.27.1

peeked: "Hello"
buffer length after peek: 13

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

The 60-second version

Good morning, everyone. This week the Go team has moved a few important items forward. First, they’ve officially deprecated the PKCS #1 v1.5 RSA encryption scheme, marking it as unsafe and encouraging developers to switch to the safer OAEP alternative. Second, a handful of legacy GODEBUG flags that were added in earlier releases will be removed in Go 1.27, so you’ll want to check your build environments for any references to those flags. Third, the standard library now includes a handy `Peek` method on `bytes.Buffer`, letting you look ahead without consuming data—useful for parsing streams. Finally, the Go blog highlighted the Green Tea garbage collector, an experimental collector that ships in Go 1.25. That’s all for this week’s radar—thanks for listening.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed