127 wires and counting

$ follow Go

Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-26
stories 30

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

gopls fixes 2019-era import scan bug and a CVE lands in pkgsite's gRPC

By RepoJournal · Filed · About Go · Composed from the cited sources · methodology

Two long-lived bugs get closed today, one in gopls's import scanning that has discarded dependency module directories since a 2019 change, and one in pkgsite's gRPC dependency, which now carries CVE-2026-33186.

internal/imports: fix scanning of dependencies' module directories golang/tools

by Brad Fitzpatrick

Since CL 212857 in 2019, newModuleResolver added each dependency's module directory as a RootModuleCache root ahead of the module cache, but scanDirForPackage computed subdirs relative to that root, dropping the module@version component modCacheRegexp requires. Every such directory was discarded as an "invalid module cache path", so dependency packages were scanned unreliably for years; this re...

all: update google.golang.org/grpc and google.golang.org/api dependencies golang/pkgsite

by Hana Kim

google.golang.org/grpc moves up to remediate CVE-2026-33186 and GHSA-m425-mq94-257g, which forces google.golang.org/api up too: newer gRPC adds a field to credentials.DefaultCredentialsOptions and an unkeyed struct literal fails to compile. The api bump pulls cloud.google.com/go modules along via minimal version selection, so if you build against pkgsite's modules, bump both together.

simd: add missing ARM64 NEON 8-bit ConcatAddPairs intrinsics golang/go

by Alexander Musman

The 8-bit Int8x16 and Uint8x16 ConcatAddPairs variants were missed when the intrinsic landed, and NEON's VADDP handles the 16B arrangement natively. The element-size constraint relaxes to 8|16|32: amd64 is unchanged, arm64 gets VADDP.16B lowering.

gopls/internal/golang: refactor moving set computation golang/tools

by Hongxiang Jiang

The refactor collapses explicit and implicit dependency exploration into one plain BFS, but implicitDependencies now runs once per constant instead of once per iota group and rescans the enclosing block each time. Hongxiang Jiang's numbers for an n-constant iota block: 7.0µs to 333µs at n=100, 77µs to 28.9ms at n=1000.

unix/linux/Dockerfile: update to Go 1.26.8 golang/sys

by Ian Lance Taylor

The Linux builder moves to Go 1.26.8 for the fix behind golang/go#81112; several smaller cleanups also landed, including the removal of the SSA generator split phase, which produces no changes in generated output, and corrections to the simd tofrom_xxx variant path for arm64.

Quick answers

What shipped in Go on September 26, 2026?
Two long-lived bugs get closed today, one in gopls's import scanning that has discarded dependency module directories since a 2019 change, and one in pkgsite's gRPC dependency, which now carries CVE-2026-33186. In total, 30 commits landed.
Who contributed to Go on September 26, 2026?
10 developers shipped this update, including Daniel Morsing, Alexander Musman, David Chase, Hana Kim, Jonathan Amsterdam, Hongxiang Jiang, Brad Fitzpatrick, and hw, and 2 more.
What were the notable Go updates?
internal/imports: fix scanning of dependencies' module directories, all: update google.golang.org/grpc and google.golang.org/api dependencies, and simd: add missing ARM64 NEON 8-bit ConcatAddPairs intrinsics.