This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 10 · Mar 2 – 8, 2026from 5 items

The Go team released two security‑patched point releases, 1.25.8 and 1.26.1, addressing several standard‑library packages. Several proposals were accepted, adding new fields to the analysis module API, iterator forms for regexp matching, and restoring the previous default go directive for `go mod init`.

Worth knowingstdlib

go1.26.1 security release

What changed
Security fixes to the crypto/x509, html/template, net/url, and os packages, plus bug fixes to the go command, the go fix command, the compiler, and the os and reflect packages.
Production impact
The source does not say.
Try it
Upgrade to go1.26.1 and run go test ./... to confirm no regressions.
Source
go.dev/doc/devel/release#go1.26.1
Explain it and run it

Understand it, then run it

Go 1.26.1 is a security patch release. It fixes vulnerabilities in the crypto/x509, html/template, net/url, and os packages. The release also corrects bugs in the go command, the go fix command, the compiler, and the os and reflect packages. No new language features or APIs were added.

Run it now

Todaygo
// This program demonstrates that html/template renders a string safely.
// The security fixes in Go 1.26.1 are already in effect in Go 1.27.1.
package main

import (
	"html/template"
	"os"
)

func main() {
	// A simple template that includes user data.
	tmpl, err := template.New("demo").Parse(`Hello, {{.Name}}!`)
	if err != nil {
		panic(err)
	}
	// Render the template with a sample data structure.
	if err := tmpl.Execute(os.Stdout, map[string]string{"Name": "Alice"}); err != nil {
		panic(err)
	}
}

What it printed when we ran it on Go 1.27.1

Hello, Alice!

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingstdlib

go1.25.8 security release

What changed
Security fixes to the html/template, net/url, and os packages, plus bug fixes to the go command, the compiler, and the os package.
Production impact
The source does not say.
Try it
Upgrade to go1.25.8 and run go test ./... to confirm no regressions.
Source
go.dev/doc/devel/release#go1.25.8
Explain it and run it

Understand it, then run it

Go 1.25.8 adds security fixes to three packages: html/template, net/url, and os. The changes are internal; they do not add new functions or change existing ones. If you use html/template to render user‑supplied data, the package now guards against a wider class of injection attacks. The same applies to URL parsing and file system operations in net/url and os.

Run it now

Todaygo
// This program demonstrates that html/template still renders a template
// and that the security fixes are in place.  It does not rely on any
// new API introduced in 1.25.8; the changes are internal to the package.
package main

import (
	"html/template"
	"os"
)

func main() {
	// A simple template that prints a user‑supplied value.
	tmpl, err := template.New("demo").Parse("Hello, {{.Name}}!")
	if err != nil {
		panic(err)
	}

	// Render the template with a sample data structure.
	err = tmpl.Execute(os.Stdout, map[string]string{"Name": "World"})
	if err != nil {
		panic(err)
	}
}

What it printed when we ran it on Go 1.27.1

Hello, World!

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingtooling

cmd/go: change `go mod init` default go directive back to 1.N

What changed
The default go directive for go mod init will revert to using the running toolchain’s version (1.N.M) instead of the previous 1.(N‑1).0.
Production impact
The source does not say.
Try it
Run go mod init mymod with a 1.26 toolchain and inspect the generated go.mod to verify the go directive is 1.26.
Source
github.com/golang/go/issues/77653

Nice to knowtooling

x/tools/go/analysis: add GoMod, … fields to Module

What changed
The analysis Module type now exposes all fields common to golang.org/x/tools/go/packages.Module and cmd/go/internal/modinfo.ModulePublic, including Path, Version, Replace, Time, Main, Indirect, Dir, GoMod, GoVersion, and Error.
Production impact
The source does not say.
Try it
Use the updated analysis API in a custom linter to inspect the GoMod field of modules.
Source
github.com/golang/go/issues/73878
Explain it

Understand it, then run it

The analysis.Module type is a small struct that describes a Go module. Until now it only had a few fields, like the module path and version. A new change adds several more fields that are already present in the packages.Module type: GoMod, GoVersion, Dir, Main, Indirect, Replace, Time, and Error. These fields let you know where the module’s go.mod file lives, what Go version it uses, and other metadata that can help tools understand a project’s dependencies.

Exercise

Create a Go program that uses the new iterator form of regexp matching (once it is merged) to print all matches and their submatches for a given string.

The 60-second version

This week the Go team shipped two security‑patched point releases, 1.25.8 and 1.26.1, tightening up several standard‑library packages. They also accepted a proposal to enrich the analysis module API with more fields, added iterator forms for regexp matching, and rolled back the default go directive for `go mod init` to match the toolchain’s version. These changes keep the language stable and secure while giving developers more tooling options and clearer module semantics.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed