This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 19 · May 4 – 10, 2026

go1.25.10 security and bug fixes

Worth knowingecosystem

What changed
The release includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages.
Production impact
The source does not say.
Try it
Run go version after updating to 1.25.10 and verify that the command line tools work as before.
Source
go.dev/doc/devel/release#go1.25.10

Understand it, then run it

The Go 1.25.10 release adds security fixes to several core packages. It patches the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages. Bug fixes are also applied to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages. These changes are part of the normal maintenance cycle that keeps the language safe and reliable.

Run it now

Todaygo
// This program demonstrates that the standard library packages referenced in the
// security fix list (e.g., os, net, html/template) are available and can be
// imported and used in Go 1.27.1. It prints a simple message using the os
// package to show that the import works without any errors.

package main

import (
	"fmt"
	"os"
)

func main() {
	// Use os.Args to access command-line arguments and print them.
	fmt.Println("Command-line arguments:", os.Args)
}

What it printed when we ran it on Go 1.27.1

Command-line arguments: [/work/prog]

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed