130 wires and counting

$ follow Go

Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-02
stories 46

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

html/template escapes JS context, gopls fixes inline call analysis

By RepoJournal · Filed · About Go · Composed from the cited sources · methodology

A CVE fix lands in html/template's JS context handling while gopls fixes a telemetry-distorting bug in ChangeSignature and the export-data decoupling experiment ripples through cmd/go and toolstash.

html/template: reset JS context for template expressions golang/go

by Neal Patel

Regular expressions at the start of each template expression now receive regular expression escaping, closing CVE-2026-94448. If you render untrusted data into JS contexts through html/template, this is the one to take.

cmd/compile/internal/pkginit: remove tconv alias golang/go

by Michael Matloob

The tconv alias, a shorter name for typecheck.ConvNop, is gone so that rf's inject can follow the call tree; that is groundwork for the refactoring work tracked under #19683.

gopls/internal/golang: call arguments mistreated in inlineAllCalls golang/tools

by Peter Weinberger

inlineAllCalls used to treat any directly enclosing ast.CallExpr as a call to the referenced function, so references passed as arguments (s.M(f), use(f)) were miscounted as call sites during ChangeSignature rewrites. The commit flags this as a telemetry bug.

cmd/toolstash: check -linkobj files to support early export golang/tools

by thepudds

cmd/go now passes a -linkobj flag with a separate archive: the -o file holds export data and -linkobj holds object code. toolstash -cmp previously missed changes in that file, so 'go build -toolexec "toolstash -cmp" -a std' could pass over real SSA differences; it now compares the -linkobj file.

cmd/go: split build_pgo test based on "go list -export" experiment golang/go

by Mark Freeman

The build_pgo test assumed build IDs from 'go list -export' and 'go build' match, which the export data decoupling experiment explicitly drops. The test is split and the failing portion removed for the duration; one of the two files goes away when the experiment concludes.

data/reports: add 2 reports golang/vulndb

by Ian Alexander

vulndb added GO-2026-6615 and GO-2026-6616, reviewed GO-2024-2584, and moved GO-2026-6551 into data/excluded.

Quick answers

What shipped in Go on October 2, 2026?
A CVE fix lands in html/template's JS context handling while gopls fixes a telemetry-distorting bug in ChangeSignature and the export-data decoupling experiment ripples through cmd/go and toolstash. In total, 46 commits landed.
Who contributed to Go on October 2, 2026?
8 developers shipped this update, including Neal Patel, Michael Matloob, Robert Griesemer, Mark Freeman, Ian Alexander, thepudds, Peter Weinberger, and Hongxiang Jiang.
What were the notable Go updates?
html/template: reset JS context for template expressions, cmd/compile/internal/pkginit: remove tconv alias, and gopls/internal/golang: call arguments mistreated in inlineAllCalls.