RepoJournal
Go

@golang

Go and the standard library - backend infrastructure at scale

Keep up with Go in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Go Infrastructure Full archive →

The Wire · Showcase

VULNDB INGESTS 86 NEW VULNERABILITY REPORTS OVERNIGHT

By RepoJournal · Filed · About Go

The vulnerability database shipped 86 new security advisories in four separate CLs, covering first-party Go issues and third-party dependency vulnerabilities that your supply chain scanner needs to know about.

Vulndb landed four major report batches [1][2][3][4] registering everything from GO-2026-5932 through GO-2026-5916, plus two critical first-party issues that fix golang/go#4970 and golang/go#5856 [4]. This is the scale of intake you expect during a vulnerability disclosure season. Meanwhile, Go 1.27 RC2 landed in gopls tooling [5], meaning your LSP completion benchmarks already run against the release candidate. On the idna front, both golang/net and golang/text rejected a long-standing UTS 46 specification bug that incorrectly permitted Punycode labels encoding pure ASCII strings like "xn--example-.com" [6][7]. This closes golang/go#78760. In gopls internals, completion benchmarks now enforce empty-range semantics [8], and the nilness analyzer learned to skip cgo magic functions that clobber SSA assumptions [9].

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] data/reports: add 17 reports golang/vulndb
  2. [2] data/reports: add 23 reports golang/vulndb
  3. [3] data/reports: add 45 reports golang/vulndb
  4. [4] data/reports: add 2 first-party reports golang/vulndb
  5. [5] internal/stdlib: update stdlib index for Go 1.27 Release Candidate 2 golang/tools
  6. [6] idna: reject all-ASCII xn-- labels on all Go versions golang/net
  7. [7] internal/export/idna: always treat Punycode encoding pure ASCII as an error golang/text
  8. [8] gopls/internal/test: Completion benchmarks use empty range golang/tools
  9. [9] go/analysis/passes/nilness: skip magic cgo functions golang/tools

Quick answers

What shipped in Go on July 8, 2026?
The vulnerability database shipped 86 new security advisories in four separate CLs, covering first-party Go issues and third-party dependency vulnerabilities that your supply chain scanner needs to know about. In total, 16 commits landed.
What were the notable Go updates?
data/reports: add 17 reports, data/reports: add 23 reports, and data/reports: add 45 reports.

More from @golang

Daily updates, in your inbox

Follow Go

Keep up with Go in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?

We use privacy-friendly analytics (Google Analytics, IP-anonymized) to see which pages help readers. No ads, and we never sell your data. See our Privacy Policy.