This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Quiet Pager · Radar

What changed in Go, Rust and Solidity this week.

What changed this week, from each project's own release notes, proposals and issues, with an exercise you can run for each change.

Written by a model · reviewed by a person · published Mondays · Atom feed

Archive · Week 19 · May 4 – 10, 2026from 6 items

This week the Go team released two security‑focused point releases, 1.25.10 and 1.26.3, and accepted several proposals that extend cryptographic support and clarify API documentation. The releases address vulnerabilities in core tools and packages, while the proposals add ML‑DSA and MLKEM support to the TLS stack and expose raw signature algorithm data in X.509 certificates.

Worth knowingecosystem

go1.25.10 security and bug fixes

What changed
The release includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages.
Production impact
The source does not say.
Try it
Run go version after updating to 1.25.10 and verify that the command line tools work as before.
Source
go.dev/doc/devel/release#go1.25.10
Explain it and run it

Understand it, then run it

The Go 1.25.10 release adds security fixes to several core packages. It patches the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages. Bug fixes are also applied to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages. These changes are part of the normal maintenance cycle that keeps the language safe and reliable.

Run it now

Todaygo
// This program demonstrates that the standard library packages referenced in the
// security fix list (e.g., os, net, html/template) are available and can be
// imported and used in Go 1.27.1. It prints a simple message using the os
// package to show that the import works without any errors.

package main

import (
	"fmt"
	"os"
)

func main() {
	// Use os.Args to access command-line arguments and print them.
	fmt.Println("Command-line arguments:", os.Args)
}

What it printed when we ran it on Go 1.27.1

Command-line arguments: [/work/prog]

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Worth knowingecosystem

go1.26.3 security and bug fixes

What changed
The release includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the crypto/fips140, crypto/tls, go/types, and os packages.
Production impact
The source does not say.
Try it
Update a Go 1.26.x installation to 1.26.3 and run go test ./... to confirm that existing tests still pass.
Source
go.dev/doc/devel/release#go1.26.3
Explain it and run it

Understand it, then run it

The Go 1.26.3 release brings a set of security fixes that affect several core packages. The changes are limited to bug patches, not new language features, so the syntax you use stays the same. The packages touched include html/template, net, net/http, net/http/httputil, net/mail, and syscall, as well as tools like the go command and the pack tool. The fixes also touch the runtime, compiler, and linker, but those are internal and invisible to most developers.

Run it now

Todaygo
package main

// This program demonstrates that Go 1.26.3 has been released with security fixes
// to several core packages. The program itself does not use any new features
// and simply prints a confirmation message. The changes are internal and
// do not affect the code shown here.

import "fmt"

func main() {
    fmt.Println("Go 1.26.3 is installed and running.")
}

What it printed when we ran it on Go 1.27.1

Go 1.26.3 is installed and running.

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Nice to knowecosystem

crypto/x509: add Certificate.RawSignatureAlgorithm

What changed
The proposal adds a RawSignatureAlgorithm []byte field to crypto/x509.Certificate, CertificateRequest, and RevocationList.
Production impact
The source does not say.
Try it
Parse an X.509 certificate with an unknown signature algorithm and inspect the RawSignatureAlgorithm field.
Source
github.com/golang/go/issues/76133
Explain it and run it

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the new RawSignatureAlgorithm field in
// crypto/x509.Certificate. It is not yet available in Go 1.27.1, so the
// program simply shows how the field would be used once the change ships.
package main

import (
	"crypto/x509"
	"fmt"
)

func main() {
	// A DER-encoded AlgorithmIdentifier for a hypothetical signature algorithm.
	// In practice this would come from parsing a real certificate.
	alg := []byte{0x30, 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b}

	// Create a Certificate with the raw algorithm bytes set.
	cert := &x509.Certificate{
		RawSignatureAlgorithm: alg,
	}

	// Print the raw algorithm bytes to confirm the field is populated.
	fmt.Printf("RawSignatureAlgorithm: %x\n", cert.RawSignatureAlgorithm)
}

What it printed when we ran it on Go 1.27.1

RawSignatureAlgorithm: 300a06082a864886f70d01010b

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Nice to knowecosystem

go/importer: clarification of ForCompiler lookup parameter

What changed
Documentation of the lookup parameter of ForCompiler can be clarified to correct a parsing bug that caused unintended deprecation.
Production impact
The source does not say.
Try it
Run go doc go/importer.ForCompiler and verify that the documentation now reflects the intended behavior.
Source
github.com/golang/go/issues/79139
Explain it

Understand it, then run it

The ForCompiler function in the go/importer package lets you load Go packages by name, using the compiler’s view of the source tree. A recent change clarified the documentation for its lookup argument. Previously the docs were ambiguous and a parsing bug caused the function to be marked as deprecated in Go 1.16, even though it was still fully usable. The clarification removes that confusion and restores the function’s normal status.

Exercise

Write a small program that parses an X.509 certificate from a PEM file and prints the raw signature algorithm bytes.

The 60-second version

Hello, and welcome to this week’s Go Radar. The Go team has just released two point releases, 1.25.10 and 1.26.3, both of which focus on tightening security across core tools and packages. They patch vulnerabilities in the go command, the pack tool, and several standard library packages, and they also fix bugs in the compiler, linker, runtime, and cryptographic libraries. In addition, the team has accepted several proposals that broaden cryptographic support. One adds ML‑DSA signatures to the TLS and X.509 packages, another introduces a new key‑exchange algorithm, MLKEM1024, into TLS, and a third exposes the raw signature algorithm bytes in parsed certificates. There’s also a small but useful clarification to the importer’s ForCompiler function documentation. These changes mean that your builds and services should stay up to date with the latest security patches, and that you’ll soon be able to work with newer post‑quantum cryptography primitives in Go’s standard library.

Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed