Archive · Week 3 · Jan 12 – 18, 2026from 3 items
The Go team released two security‑fix releases, 1.24.12 and 1.25.6, and accepted a proposal to expose “no return” analysis in the x/tools packages. The week was otherwise quiet.
Worth knowingecosystem
Security fixes in Go 1.24.12
- What changed
- The release includes security fixes to the go command, the archive/zip, crypto/tls, and net/url packages, and bug fixes to the compiler, runtime, crypto/tls, and os packages.
- Production impact
- The source does not say.
- Try it
- Run
go versionto confirm you are on 1.24.12 and test a simple program that usesnet/urlto ensure no regressions. - Source
- go.dev/doc/devel/release#go1.24.12
Explain it
Understand it, then run it
The Go 1.24.12 release adds security fixes to several core packages: the go command, archive/zip, crypto/tls, and net/url. It also includes bug fixes for the compiler, runtime, crypto/tls, and os. These changes are part of routine maintenance to keep the language and its libraries safe and reliable. The release does not introduce new language features or APIs, so existing code continues to compile unchanged.
Worth knowingecosystem
Expose “no return” API in x/tools/go
- What changed
- The proposal is accepted to expose the results of “no return” analysis from the x/tools CFG packages, adding APIs in cfg, ctrlflow, and ssa that allow callers to query or set the “no return” property.
- Production impact
- The source does not say.
- Try it
- Clone
golang.org/x/tools, importgolang.org/x/tools/go/cfg, and callcfg.NoReturn()on a CFG you build to see if the function can return. - Source
- github.com/golang/go/issues/76161
Explain it
Understand it, then run it
The Go tools can now tell you when a function will never return. Previously you had to dig into the internals of the tools to find this out. Now the packages cfg, ctrlflow, and ssa expose a simple method called NoReturn. You can ask a control‑flow graph if it can return, or tell the SSA builder that a named function never returns, and the tools will use that information automatically.
Exercise
Exercise Write a program that parses a list of URLs and prints the host part of each one. Use the net/url package (which received a security fix in this release) to do the parsing.
package main
import (
"fmt"
"net/url"
)
func main() {
urls := []string{
"https://golang.org",
"http://example.com:8080/path?query=1",
"ftp://ftp.example.com/resource",
"not-a-url",
}
for _, u := range urls {
// TODO: parse the URL and print its host
fmt.Println(u, "=>", "host placeholder")
}
}
Show a solution
package main
import (
"fmt"
"net/url"
)
func main() {
urls := []string{
"https://golang.org",
"http://example.com:8080/path?query=1",
"ftp://ftp.example.com/resource",
"not-a-url",
}
for _, u := range urls {
parsed, err := url.Parse(u)
if err != nil {
fmt.Printf("%s => error: %v\n", u, err)
continue
}
fmt.Printf("%s => host: %s\n", u, parsed.Host)
}
}
What it printed when we ran it on Go 1.27.1
https://golang.org => host: golang.org http://example.com:8080/path?query=1 => host: example.com:8080 ftp://ftp.example.com/resource => host: ftp.example.com not-a-url => host:
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
The 60-second version
Hello, this week the Go team rolled out two security‑fix releases, 1.24.12 and 1.25.6, tightening up the go command and several core packages like archive/zip, crypto/tls, and net/url. They also accepted a proposal that adds a new “no return” API to the x/tools analysis packages, letting developers query whether a function can ever return normally. These changes keep Go safer and give tooling better insight into program flow.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed