130 wires and counting

$ follow Go

Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-10-03
stories 29

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

Go toolchain patches three CVEs in module and template verification

By RepoJournal · Filed · About Go · Composed from the cited sources · methodology

Three fixes land in cmd/go and html/template closing module-hash and toolchain-checksum verification gaps, plus a JSON v2 tag-parsing correction and a syntax-package cleanup.

cmd/go: always verify toolchain downloads with sumdb golang/go

by Neal Patel

Toolchain downloads now always go to the network to obtain the canonical checksum instead of accepting a matching entry that specifies golang.org/toolchain. If your builds relied on a local or bundled sum entry for the toolchain, go will now fail when it cannot reach sumdb.

cmd/go: bundle go.sum h1 hashes for golang.org/fips140 golang/go

by Neal Patel

Replaces the carve-out for the golang.org/fips module with the canonical go.sum h1 hash in the trusted fips140.sum file, and modfetch uses that trusted ziphash to populate the GOMODCACHE entry. Closes CVE-2026-94444.

html/template: recognize `yield` as regexp preceder keyword golang/go

by Neal Patel

html/template now treats `yield` as a regexp preceder keyword, applying regular expression escaping where it previously did not. Closes CVE-2026-97030; templates using `yield` before a regexp literal are the ones to re-check.

encoding/json/v2: keep the Go field name when a tag name stops early golang/go

by Ahmed Mohamed

parseFieldOptions adopted a field name before inspecting the leftover text after the tag name's first reserved character, so a tag like one"two could silently take the truncated name. The Go field name is now kept when the tag name stops early, which is a breaking change for struct tags that were parsing under the old behavior.

cmd/compile/internal/syntax: return string rather than []byte from source.segment golang/go

by Robert Griesemer

source.segment no longer returns []byte; the compiler's syntax parser now returns a string, and the one call site that avoided allocation by parsing keywords against the byte slice is gone because it converted to a string anyway. Internal to cmd/compile, no API surface change.

Resources-for-slog: add gslog golang/wiki

by Alan D. Cabrera

golang/wiki added gslog to the Resources-for-slog page. Meanwhile gopls 0.24.0 documentation is being finalized [ref-drop] and vscode-go picked up the v0.24.0-pre.1 settings, with the extension now delegating struct-tag prompting to gopls unless promptForTags is set.

Quick answers

What shipped in Go on October 3, 2026?
Three fixes land in cmd/go and html/template closing module-hash and toolchain-checksum verification gaps, plus a JSON v2 tag-parsing correction and a syntax-package cleanup. In total, 29 commits landed.
Who contributed to Go on October 3, 2026?
8 developers shipped this update, including Neal Patel, Robert Griesemer, Ahmed Mohamed, Alan D. Cabrera, Alan Donovan, Hongxiang Jiang, Gopher Robot, and Junyang Shao.
What were the notable Go updates?
cmd/go: always verify toolchain downloads with sumdb, cmd/go: bundle go.sum h1 hashes for golang.org/fips140, and html/template: recognize `yield` as regexp preceder keyword.