Archive · Week 49 · Dec 1 – 7, 2025from 3 items
The Go team released two patch releases, 1.24.11 and 1.25.5, both addressing security issues in the crypto/x509 package and adding a handful of bug fixes. A proposal to relax the alias‑type‑parameter rule was accepted, but the change is not yet shipped.
Worth knowinglanguage
Alias type parameter restriction relaxed
- What changed
- The Go spec now allows a type parameter to appear on the right‑hand side of an alias type declaration, but only when the type parameter is declared in the same declaration.
- Production impact
- The source does not say.
- Try it
- Compile a package that declares
type T[T any] = []Tand observe that it is now accepted. - Source
- github.com/golang/go/issues/75885
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the relaxed alias rule.
// It defines a generic alias that uses a type parameter declared in the same statement.
package main
import "fmt"
// Generic alias: MySlice[T] is an alias for []T.
// The type parameter T is declared in the same line, which is now allowed.
type MySlice[T any] = []T
func main() {
// Create a MySlice[int] and populate it.
var nums MySlice[int] = MySlice[int]{1, 2, 3}
fmt.Println(nums) // Output: [1 2 3]
}
What it printed when we ran it on Go 1.27.1
[1 2 3]
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingtooling
go1.24.11 released
- What changed
- The release includes two security fixes to the crypto/x509 package and bug fixes to the runtime.
- Production impact
- The source does not say.
- Try it
- Run
go versionafter installing the new release and check thatgo1.24.11is reported. - Source
- go.dev/doc/devel/release#go1.24.11
Explain it
Understand it, then run it
Go 1.24.11 is a maintenance release that fixes two security issues in the crypto/x509 package and corrects some bugs in the runtime. The release does not add new language features or APIs. It simply improves the safety and stability of code that parses X.509 certificates and the Go runtime itself.
Worth knowingtooling
go1.25.5 released
- What changed
- The release includes two security fixes to the crypto/x509 package and bug fixes to the mime and os packages.
- Production impact
- The source does not say.
- Try it
- Run
go envafter installing the new release and verify that theGOROOTpoints to the 1.25.5 tree. - Source
- go.dev/doc/devel/release#go1.25.5
Explain it
Understand it, then run it
Go 1.25.5 adds two security fixes to the crypto/x509 package and bug fixes to the mime and os packages. If you use certificates or parse MIME data, the changes improve safety and reliability. No new APIs are introduced; the packages behave the same as before, just more securely. The update is a minor release, so upgrading is straightforward.
Exercise
Write a small program that declares a type alias using a type parameter and prints the resulting type name.
package main
import "fmt"
func main() {
// TODO: Declare an alias type that uses a type parameter
// and print its name.
}
Show a solution
package main
import "fmt"
type SliceOf[T any] = []T
func main() {
var s SliceOf[int]
fmt.Printf("Type of s: %T\n", s)
}
What it printed when we ran it on Go 1.27.1
Type of s: []int
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
The 60-second version
This week the Go team rolled out two patch releases, 1.24.11 and 1.25.5, both tightening security in the crypto/x509 package and squashing a handful of runtime, mime, and os bugs. In addition, a proposal to loosen the restriction on alias type declarations was accepted: you can now use a type parameter on the right‑hand side of an alias, but only if that parameter is declared in the same declaration. These changes are ready for you to test in your own code, but remember that the alias rule is still a future release feature, not yet available in the current stable toolchain.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed