This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 6 · Feb 2 – 8, 2026from 2 items

This week the Go team released two maintenance versions, 1.24.13 and 1.25.7, both containing security and bug fixes for the go command, the crypto/tls package, and the crypto/x509 package, with 1.25.7 also fixing compiler bugs.

Worth knowingecosystem

Go 1.24.13 released

What changed
Security fixes to the go command and the crypto/tls package, and bug fixes to the crypto/x509 package.
Production impact
The source does not say.
Try it
Run go version to verify you are using 1.24.13 or later.
Source
go.dev/doc/devel/release#go1.24.13
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates that the updated crypto/tls package compiles
// and can create a TLS configuration. It does not perform network I/O.
package main

import (
	"crypto/tls"
	"fmt"
)

func main() {
	// Create a TLS configuration that skips certificate verification
	// for demonstration purposes. In production, use InsecureSkipVerify: false.
	cfg := &tls.Config{InsecureSkipVerify: true}

	// Print the configuration to show it was constructed successfully.
	fmt.Printf("TLS config created: %+v\n", cfg)
}

What it printed when we ran it on Go 1.27.1

TLS config created: &{Rand:<nil> Time:<nil> Certificates:[] NameToCertificate:map[] GetCertificate:<nil> GetClientCertificate:<nil> GetConfigForClient:<nil> VerifyPeerCertificate:<nil> VerifyConnection:<nil> RootCAs:<nil> NextProtos:[] ServerName: ClientAuth:NoClientCert ClientCAs:<nil> InsecureSkipVerify:true CipherSuites:[] PreferServerCipherSuites:false SessionTicketsDisabled:false SessionTicketKey:[0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0] ClientSessionCache:<nil> UnwrapSession:<nil> WrapSession:<nil> MinVersion:0 MaxVersion:0 CurvePreferences:[] DynamicRecordSizingDisabled:false Renegotiation:0 KeyLogWriter:<nil> EncryptedClientHelloConfigList:[] EncryptedClientHelloRejectionVerify:<nil> GetEncryptedClientHelloKeys:<nil> EncryptedClientHelloKeys:[] mutex:{w:{_:{} mu:{state:0 sema:0}} writerSem:0 readerSem:0 readerCount:{_:{} v:0} readerWait:{_:{} v:0}} sessionTicketKeys:[] autoSessionTicketKeys:[]}

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingecosystem

Go 1.25.7 released

What changed
Security fixes to the go command and the crypto/tls package, bug fixes to the compiler and the crypto/x509 package.
Production impact
The source does not say.
Try it
Run go version to verify you are using 1.25.7 or later.
Source
go.dev/doc/devel/release#go1.25.7

Exercise

Write a small program that prints the Go version and the current time in UTC.

Startergo
package main

import (
	"fmt"
	"time"
)

func main() {
	// TODO: print the Go version and the current UTC time
}
Show a solution
Solutiongo
package main

import (
	"fmt"
	"runtime"
	"time"
)

func main() {
	fmt.Printf("Go version: %s\n", runtime.Version())
	fmt.Printf("Current UTC time: %s\n", time.Now().UTC().Format(time.RFC3339))
}

What it printed when we ran it on Go 1.27.1

Go version: go1.27.1
Current UTC time: 2026-10-01T07:33:55Z

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

The 60-second version

Good morning, everyone. This week the Go team rolled out two maintenance releases, 1.24.13 and 1.25.7. Both bring important security fixes to the go command and the crypto/tls package, and they also patch bugs in the crypto/x509 package. The newer 1.25.7 version additionally addresses compiler bugs. If you’re running an older Go version, it’s a good idea to upgrade to one of these releases to keep your tools and applications secure and reliable. Thank you.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed