Archive · Week 10 · Mar 2 – 8, 2026from 5 items
The Go team released two security‑patched point releases, 1.25.8 and 1.26.1, addressing several standard‑library packages. Several proposals were accepted, adding new fields to the analysis module API, iterator forms for regexp matching, and restoring the previous default go directive for `go mod init`.
Worth knowingstdlib
go1.26.1 security release
- What changed
- Security fixes to the crypto/x509, html/template, net/url, and os packages, plus bug fixes to the go command, the go fix command, the compiler, and the os and reflect packages.
- Production impact
- The source does not say.
- Try it
- Upgrade to go1.26.1 and run
go test ./...to confirm no regressions. - Source
- go.dev/doc/devel/release#go1.26.1
Explain it and run it
Understand it, then run it
Go 1.26.1 is a security patch release. It fixes vulnerabilities in the crypto/x509, html/template, net/url, and os packages. The release also corrects bugs in the go command, the go fix command, the compiler, and the os and reflect packages. No new language features or APIs were added.
Run it now
// This program demonstrates that html/template renders a string safely.
// The security fixes in Go 1.26.1 are already in effect in Go 1.27.1.
package main
import (
"html/template"
"os"
)
func main() {
// A simple template that includes user data.
tmpl, err := template.New("demo").Parse(`Hello, {{.Name}}!`)
if err != nil {
panic(err)
}
// Render the template with a sample data structure.
if err := tmpl.Execute(os.Stdout, map[string]string{"Name": "Alice"}); err != nil {
panic(err)
}
}
What it printed when we ran it on Go 1.27.1
Hello, Alice!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
go1.25.8 security release
- What changed
- Security fixes to the html/template, net/url, and os packages, plus bug fixes to the go command, the compiler, and the os package.
- Production impact
- The source does not say.
- Try it
- Upgrade to go1.25.8 and run
go test ./...to confirm no regressions. - Source
- go.dev/doc/devel/release#go1.25.8
Explain it and run it
Understand it, then run it
Go 1.25.8 adds security fixes to three packages: html/template, net/url, and os. The changes are internal; they do not add new functions or change existing ones. If you use html/template to render user‑supplied data, the package now guards against a wider class of injection attacks. The same applies to URL parsing and file system operations in net/url and os.
Run it now
// This program demonstrates that html/template still renders a template
// and that the security fixes are in place. It does not rely on any
// new API introduced in 1.25.8; the changes are internal to the package.
package main
import (
"html/template"
"os"
)
func main() {
// A simple template that prints a user‑supplied value.
tmpl, err := template.New("demo").Parse("Hello, {{.Name}}!")
if err != nil {
panic(err)
}
// Render the template with a sample data structure.
err = tmpl.Execute(os.Stdout, map[string]string{"Name": "World"})
if err != nil {
panic(err)
}
}
What it printed when we ran it on Go 1.27.1
Hello, World!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingtooling
cmd/go: change `go mod init` default go directive back to 1.N
- What changed
- The default go directive for
go mod initwill revert to using the running toolchain’s version (1.N.M) instead of the previous 1.(N‑1).0. - Production impact
- The source does not say.
- Try it
- Run
go mod init mymodwith a 1.26 toolchain and inspect the generatedgo.modto verify the go directive is 1.26. - Source
- github.com/golang/go/issues/77653
Nice to knowtooling
x/tools/go/analysis: add GoMod, … fields to Module
- What changed
- The analysis Module type now exposes all fields common to golang.org/x/tools/go/packages.Module and cmd/go/internal/modinfo.ModulePublic, including Path, Version, Replace, Time, Main, Indirect, Dir, GoMod, GoVersion, and Error.
- Production impact
- The source does not say.
- Try it
- Use the updated analysis API in a custom linter to inspect the GoMod field of modules.
- Source
- github.com/golang/go/issues/73878
Explain it
Understand it, then run it
The analysis.Module type is a small struct that describes a Go module. Until now it only had a few fields, like the module path and version. A new change adds several more fields that are already present in the packages.Module type: GoMod, GoVersion, Dir, Main, Indirect, Replace, Time, and Error. These fields let you know where the module’s go.mod file lives, what Go version it uses, and other metadata that can help tools understand a project’s dependencies.
Exercise
Create a Go program that uses the new iterator form of regexp matching (once it is merged) to print all matches and their submatches for a given string.
The 60-second version
This week the Go team shipped two security‑patched point releases, 1.25.8 and 1.26.1, tightening up several standard‑library packages. They also accepted a proposal to enrich the analysis module API with more fields, added iterator forms for regexp matching, and rolled back the default go directive for `go mod init` to match the toolchain’s version. These changes keep the language stable and secure while giving developers more tooling options and clearer module semantics.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed