$ the-wire · showcase
Go toolchain patches three CVEs in module and template verification
By RepoJournal · Filed · About Go · Composed from the cited sources · methodology
Three fixes land in cmd/go and html/template closing module-hash and toolchain-checksum verification gaps, plus a JSON v2 tag-parsing correction and a syntax-package cleanup.
cmd/go: always verify toolchain downloads with sumdb golang/go
Toolchain downloads now always go to the network to obtain the canonical checksum instead of accepting a matching entry that specifies golang.org/toolchain. If your builds relied on a local or bundled sum entry for the toolchain, go will now fail when it cannot reach sumdb.
cmd/go: bundle go.sum h1 hashes for golang.org/fips140 golang/go
Replaces the carve-out for the golang.org/fips module with the canonical go.sum h1 hash in the trusted fips140.sum file, and modfetch uses that trusted ziphash to populate the GOMODCACHE entry. Closes CVE-2026-94444.
html/template: recognize `yield` as regexp preceder keyword golang/go
html/template now treats `yield` as a regexp preceder keyword, applying regular expression escaping where it previously did not. Closes CVE-2026-97030; templates using `yield` before a regexp literal are the ones to re-check.
encoding/json/v2: keep the Go field name when a tag name stops early golang/go
parseFieldOptions adopted a field name before inspecting the leftover text after the tag name's first reserved character, so a tag like one"two could silently take the truncated name. The Go field name is now kept when the tag name stops early, which is a breaking change for struct tags that were parsing under the old behavior.
cmd/compile/internal/syntax: return string rather than []byte from source.segment golang/go
source.segment no longer returns []byte; the compiler's syntax parser now returns a string, and the one call site that avoided allocation by parsing keywords against the byte slice is gone because it converted to a string anyway. Internal to cmd/compile, no API surface change.
Resources-for-slog: add gslog golang/wiki
golang/wiki added gslog to the Resources-for-slog page. Meanwhile gopls 0.24.0 documentation is being finalized [ref-drop] and vscode-go picked up the v0.24.0-pre.1 settings, with the extension now delegating struct-tag prompting to gopls unless promptForTags is set.
Action items