Archive · Week 33 · Aug 10 – 16, 2026from 5 items
The Go team pushed three new releases: the 1.27 release candidate, and the 1.25.13 and 1.26.6 point releases. 1.25.13 and 1.26.6 bring a set of security fixes to several core packages and bug fixes to the compiler, runtime, and linker. No new language features were introduced this week.
Worth knowingtooling
1.27 Release Candidate 3
- What changed
- The Go 1.27 release candidate 3 was published.
- Production impact
- The source does not say.
- Try it
- Run
go versionto verify you are on a 1.27rc3 build. - Source
- github.com/golang/go/releases/tag/go1.27rc3
Explain it
Understand it, then run it
The Go 1.27 release candidate 3 was published. This is a standard release cycle event: a new candidate version is made available for testing before the final 1.27 release. No new language features or API changes are introduced in this candidate. The main impact is that developers can run their code against the candidate to catch any regressions.
Worth knowingecosystem
1.25.13 Security and Bug Fixes
- What changed
- Security fixes to the go command, crypto/tls, encoding/asn1, encoding/xml, html/template, net/http, and net/url packages, plus bug fixes to the compiler, runtime, crypto/tls, and os packages.
- Production impact
- The source does not say.
- Try it
- Build a small program that imports
net/httpand run it with Go 1.25.13 to ensure no crashes. - Source
- go.dev/doc/devel/release#go1.25.13
Explain it and run it
Understand it, then run it
The Go 1.25.13 release brings security fixes to several core packages. If you run go run or build a program that uses net/http, html/template, or crypto/tls, the updated code will be more resistant to known vulnerabilities. The compiler and runtime also received bug fixes that improve stability. No new language features or APIs were added in this release.
Run it now
// This program demonstrates that the standard library packages
// compile and run after the 1.25.13 security fixes. It does not
// perform network I/O because the sandbox has no network access.
package main
import (
"html/template"
"log"
"os"
)
func main() {
// Render a simple template to stdout.
tmpl, err := template.New("hello").Parse("Hello, {{.Name}}!")
if err != nil {
log.Fatalf("template parse error: %v", err)
}
if err := tmpl.Execute(os.Stdout, struct{ Name string }{Name: "world"}); err != nil {
log.Fatalf("template execute error: %v", err)
}
}
What it printed when we ran it on Go 1.27.1
Hello, world!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingecosystem
1.26.6 Security and Bug Fixes
- What changed
- Security fixes to the go command, crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages, plus bug fixes to the compiler, linker, runtime, crypto/tls, and os packages.
- Production impact
- The source does not say.
- Try it
- Run
go test ./...on a repository that usesnet/urlto confirm stability. - Source
- go.dev/doc/devel/release#go1.26.6
Explain it and run it
Understand it, then run it
The Go 1.26.6 release contains security fixes for several core packages, including crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url. It also includes bug fixes for the compiler, linker, runtime, and the os package. The changes do not add new language features or modify existing APIs; they simply patch vulnerabilities and improve stability.
Run it now
// This program demonstrates that Go 1.26.6 contains no new API changes.
// It simply prints a message confirming that the language itself is unchanged.
package main
import "fmt"
func main() {
fmt.Println("Go 1.26.6 does not introduce new language features.")
}
What it printed when we ran it on Go 1.27.1
Go 1.26.6 does not introduce new language features.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Exercise
Write a Go program that prints the current Go runtime version and tells the user whether the program is running on a release that is at least the 1.27.1 patch (the first stable release after the 1.27 release‑candidate 3). The program should parse the version string returned by runtime.Version() and compare it numerically.
package main
import (
"fmt"
"runtime"
)
func main() {
// TODO: Determine if the runtime version is at least 1.27.1
// and print the result.
fmt.Println("Go version:", runtime.Version())
}
Show a solution
package main
import (
"fmt"
"runtime"
"strconv"
"strings"
)
func main() {
version := runtime.Version()
fmt.Println("Go version:", version)
// Strip the leading "go" and any suffix (e.g., "rc3" or "beta").
ver := strings.TrimPrefix(version, "go")
if idx := strings.IndexAny(ver, "-+"); idx != -1 {
ver = ver[:idx]
}
parts := strings.Split(ver, ".")
if len(parts) < 3 {
fmt.Println("Unable to parse version")
return
}
major, _ := strconv.Atoi(parts[0])
minor, _ := strconv.Atoi(parts[1])
patch, _ := strconv.Atoi(parts[2])
if major > 1 || (major == 1 && minor > 27) || (major == 1 && minor == 27 && patch >= 1) {
fmt.Println("Running on Go 1.27.1 or newer")
} else {
fmt.Println("Running on an older Go version")
}
}
What it printed when we ran it on Go 1.27.1
Go version: go1.27.1 Running on Go 1.27.1 or newer
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
The 60-second version
Welcome to this week’s Go Radar. The Go team has just released three new builds. First, the 1.27 release candidate 3 is now available, giving you a preview of the upcoming 1.27 features. Second, the 1.25.13 point release brings a series of security patches to the go command and several core packages, along with compiler and runtime bug fixes. Third, the 1.26.6 point release also includes security fixes for the go command and key standard libraries, plus fixes to the compiler, linker, and runtime. These updates are important for anyone running Go in production, as they address known vulnerabilities and improve stability. Be sure to upgrade to the latest point release for your Go version to keep your services secure and reliable.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed