<feed xmlns='http://www.w3.org/2005/Atom'>
<title>guix/gnu/packages/golang.scm, branch master</title>
<subtitle>Transactional package manager, declarative GNU/Linux distribution, reproducible deployment tool, and more! https://guix.gnu.org</subtitle>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/'/>
<entry>
<title>gnu: go-1.27: Update to 1.27.0 and deprecate go-next in favor of it.</title>
<updated>2026-08-25T23:39:39+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-08-21T09:46:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=6c082f7d66c4cbce6ed856cc811ea00999c583c8'/>
<id>6c082f7d66c4cbce6ed856cc811ea00999c583c8</id>
<content type='text'>
* gnu/packages/golang.scm (go-1.27): Update to 1.27.0.
[name]: Change to "go".
(go-next): New variable.

Merges: guix/guix!10699
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* gnu/packages/golang.scm (go-1.27): Update to 1.27.0.
[name]: Change to "go".
(go-next): New variable.

Merges: guix/guix!10699
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: go-1.27: Update to 1.27rc3.</title>
<updated>2026-08-16T21:30:37+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-08-16T20:56:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=bec4036042824137d82bc052554d39021ef139c5'/>
<id>bec4036042824137d82bc052554d39021ef139c5</id>
<content type='text'>
* gnu/packages/golang.scm (go-1.27): Update to 1.27rc3.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* gnu/packages/golang.scm (go-1.27): Update to 1.27rc3.
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: go-1.26: Update to 1.26.6 [security-fixes].</title>
<updated>2026-08-16T21:30:36+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-08-16T21:11:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=277cdcc5b3fd48d52e680418822ac95bf05ab6ae'/>
<id>277cdcc5b3fd48d52e680418822ac95bf05ab6ae</id>
<content type='text'>
go1.26.6 (released 2026-08-13) includes security fixes to the go
command, and the crypto/tls, encoding/asn1, encoding/xml, html/template,
net, net/http, and net/url packages, as well as bug fixes to the
compiler, the linker, the runtime, and the crypto/tls and os packages.

See: &lt;https://github.com/golang/go/milestone/441&gt;,
&lt;https://groups.google.com/g/golang-announce/c/94pEornpRlI&gt;

Contains fixes for:
CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification
                bypass
CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in
                Lookup
CVE-2026-56859: encoding/xml: add recursion depth guard during decode
CVE-2026-56853: net/http: apply ReadHeaderTimeout when doing unencrypted
                HTTP/2 check
CVE-2026-56860: net/url: avoid quadratic complexity in resolvePath
CVE-2026-46600: golang.org/x/net/dns/dnsmessage: panic when parsing
                invalid SVCB record
CVE-2026-56862: crypto/tls: limit handshake messages we are willing to
                accept post-handshake
CVE-2026-56858: html/template: fix Javascript regexp context tracking
CVE-2026-39821: x/net/idna: failure to reject ASCII-only
                Punycode-encoded labels
CVE-2026-33818: encoding/asn1: enforce maximum recursion depth

* gnu/packages/golang.scm (go-1.26): Update to 1.26.6.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
go1.26.6 (released 2026-08-13) includes security fixes to the go
command, and the crypto/tls, encoding/asn1, encoding/xml, html/template,
net, net/http, and net/url packages, as well as bug fixes to the
compiler, the linker, the runtime, and the crypto/tls and os packages.

See: &lt;https://github.com/golang/go/milestone/441&gt;,
&lt;https://groups.google.com/g/golang-announce/c/94pEornpRlI&gt;

Contains fixes for:
CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification
                bypass
CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in
                Lookup
CVE-2026-56859: encoding/xml: add recursion depth guard during decode
CVE-2026-56853: net/http: apply ReadHeaderTimeout when doing unencrypted
                HTTP/2 check
CVE-2026-56860: net/url: avoid quadratic complexity in resolvePath
CVE-2026-46600: golang.org/x/net/dns/dnsmessage: panic when parsing
                invalid SVCB record
CVE-2026-56862: crypto/tls: limit handshake messages we are willing to
                accept post-handshake
CVE-2026-56858: html/template: fix Javascript regexp context tracking
CVE-2026-39821: x/net/idna: failure to reject ASCII-only
                Punycode-encoded labels
CVE-2026-33818: encoding/asn1: enforce maximum recursion depth

* gnu/packages/golang.scm (go-1.26): Update to 1.26.6.
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: go-1.27: Update to 1.27rc2.</title>
<updated>2026-07-23T20:15:03+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-07-17T08:37:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=d15e97fb3a5592a1afff2753a7c6af2fcaa836d9'/>
<id>d15e97fb3a5592a1afff2753a7c6af2fcaa836d9</id>
<content type='text'>
* gnu/packages/golang.scm (go-1.27): Update to 1.27rc2.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* gnu/packages/golang.scm (go-1.27): Update to 1.27rc2.
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: go-1.26: Update to 1.26.5 [security-fixes].</title>
<updated>2026-07-23T20:15:03+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-07-17T08:39:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=11b4a4ebd384aa015d5aaa102ac0e452fc7d13cc'/>
<id>11b4a4ebd384aa015d5aaa102ac0e452fc7d13cc</id>
<content type='text'>
go1.26.5 (released 2026-07-07) includes security fixes to the crypto/tls
and os packages, as well as bug fixes to the compiler, the runtime, the
go command, and the net, os, and syscall packages.

See: &lt;https://github.com/golang/go/milestone/439&gt;,
&lt;https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc&gt;.

Contains fixes for:
CVE-2026-39822: os: Root escape via symlink plus trailing slash
CVE-2026-42505: crypto/tls: Encrypted Client Hello privacy leak

* gnu/packages/golang.scm (go-1.26): Update to 1.26.5.
[phases]{remove-testscript-mod_get_fips140_issue73649.txt}: New phase,
remove test script file requiring connection to Internet.

Signed-off-by: Sharlatan Hellseher &lt;sharlatanus@gmail.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
go1.26.5 (released 2026-07-07) includes security fixes to the crypto/tls
and os packages, as well as bug fixes to the compiler, the runtime, the
go command, and the net, os, and syscall packages.

See: &lt;https://github.com/golang/go/milestone/439&gt;,
&lt;https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc&gt;.

Contains fixes for:
CVE-2026-39822: os: Root escape via symlink plus trailing slash
CVE-2026-42505: crypto/tls: Encrypted Client Hello privacy leak

* gnu/packages/golang.scm (go-1.26): Update to 1.26.5.
[phases]{remove-testscript-mod_get_fips140_issue73649.txt}: New phase,
remove test script file requiring connection to Internet.

Signed-off-by: Sharlatan Hellseher &lt;sharlatanus@gmail.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: go-1.25: Update to 1.25.12 [security-fixes].</title>
<updated>2026-07-23T20:15:03+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-07-17T08:45:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=bfed370071e0857b2ad31cc0641b2225a06ab488'/>
<id>bfed370071e0857b2ad31cc0641b2225a06ab488</id>
<content type='text'>
go1.25.12 (released 2026-07-07) includes security fixes to the
crypto/tls and os packages, as well as bug fixes to the compiler, the go
command, and the net and os packages.

See: &lt;https://github.com/golang/go/milestone/438&gt;,
&lt;https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc&gt;.

Contains fixes for:
CVE-2026-39822: os: Root escape via symlink plus trailing slash
CVE-2026-42505: crypto/tls: Encrypted Client Hello privacy leak

* gnu/packages/golang.scm (go-1.25): Update to 1.25.12.
[phases]{remove-testscript-mod_get_fips140_issue73649.txt}: New phase,
remove test script file requiring connection to Internet.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
go1.25.12 (released 2026-07-07) includes security fixes to the
crypto/tls and os packages, as well as bug fixes to the compiler, the go
command, and the net and os packages.

See: &lt;https://github.com/golang/go/milestone/438&gt;,
&lt;https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc&gt;.

Contains fixes for:
CVE-2026-39822: os: Root escape via symlink plus trailing slash
CVE-2026-42505: crypto/tls: Encrypted Client Hello privacy leak

* gnu/packages/golang.scm (go-1.25): Update to 1.25.12.
[phases]{remove-testscript-mod_get_fips140_issue73649.txt}: New phase,
remove test script file requiring connection to Internet.
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: go-1.25: Update to 1.25.11 [security-fixes]</title>
<updated>2026-07-23T20:14:48+00:00</updated>
<author>
<name>Ankit Gadiya</name>
<email>git@argp.in</email>
</author>
<published>2026-06-03T18:10:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=d88b175e9ddc31fcd1dde2494dc0db2bb6fd1fee'/>
<id>d88b175e9ddc31fcd1dde2494dc0db2bb6fd1fee</id>
<content type='text'>
go1.25.11 (released 2026-06-03) includes security fixes to the
mine, net/textproto, and crypto/x509 packages.
See: &lt;https://github.com/golang/go/milestone/436&gt;,
&lt;https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw&gt;.

Contains fixes for:
CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader
CVE-2026-42507: net/textproto: arbitrary input are included in errors
                without any escaping
CVE-2026-27145: crypto/x509: split candidate hostname only once

* gnu/packages/golang.scm (go-1.25): Update to 1.25.11.

Merges: guix/guix!9133
Change-Id: I9e179c511f6cdb942fdb8e65b166c6b87f128129
Signed-off-by: Sharlatan Hellseher &lt;sharlatanus@gmail.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
go1.25.11 (released 2026-06-03) includes security fixes to the
mine, net/textproto, and crypto/x509 packages.
See: &lt;https://github.com/golang/go/milestone/436&gt;,
&lt;https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw&gt;.

Contains fixes for:
CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader
CVE-2026-42507: net/textproto: arbitrary input are included in errors
                without any escaping
CVE-2026-27145: crypto/x509: split candidate hostname only once

* gnu/packages/golang.scm (go-1.25): Update to 1.25.11.

Merges: guix/guix!9133
Change-Id: I9e179c511f6cdb942fdb8e65b166c6b87f128129
Signed-off-by: Sharlatan Hellseher &lt;sharlatanus@gmail.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: Add go-next (go-1.27).</title>
<updated>2026-07-08T22:26:46+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-07-02T19:10:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=733be4b68b4521e86bd66cc2e35e250383e78175'/>
<id>733be4b68b4521e86bd66cc2e35e250383e78175</id>
<content type='text'>
* gnu/packages/golang.scm (go-1.27, go-std-1.27): New variables.

Merges: guix/guix!9666
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* gnu/packages/golang.scm (go-1.27, go-std-1.27): New variables.

Merges: guix/guix!9666
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: go-1.26: Update to 1.26.4 [security-fixes]</title>
<updated>2026-06-07T19:24:30+00:00</updated>
<author>
<name>Ankit Gadiya</name>
<email>git@argp.in</email>
</author>
<published>2026-06-03T18:16:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=11a3b576e0b2b717fc59bd50a3b16be0b1580c74'/>
<id>11a3b576e0b2b717fc59bd50a3b16be0b1580c74</id>
<content type='text'>
go1.26.4 (released 2026-06-03) includes security fixes to the mine,
net/textproto, and crypto/x509 packages.
See: &lt;https://github.com/golang/go/milestone/435&gt;,
&lt;https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw&gt;.

Contains fixes for:
CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader
CVE-2026-42507: net/textproto: arbitrary input are included in errors
                without any escaping
CVE-2026-27145: crypto/x509: split candidate hostname only once

* gnu/packages/golang.scm (go-1.26): Update to 1.26.4.

Merges: guix/guix!9081
Change-Id: I345f8829192e150590769bfa359c9e6ab06b421d
Signed-off-by: Sharlatan Hellseher &lt;sharlatanus@gmail.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
go1.26.4 (released 2026-06-03) includes security fixes to the mine,
net/textproto, and crypto/x509 packages.
See: &lt;https://github.com/golang/go/milestone/435&gt;,
&lt;https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw&gt;.

Contains fixes for:
CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader
CVE-2026-42507: net/textproto: arbitrary input are included in errors
                without any escaping
CVE-2026-27145: crypto/x509: split candidate hostname only once

* gnu/packages/golang.scm (go-1.26): Update to 1.26.4.

Merges: guix/guix!9081
Change-Id: I345f8829192e150590769bfa359c9e6ab06b421d
Signed-off-by: Sharlatan Hellseher &lt;sharlatanus@gmail.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>gnu: packages/golang: Add comment about boostrap versions.</title>
<updated>2026-06-03T20:00:34+00:00</updated>
<author>
<name>Sharlatan Hellseher</name>
<email>sharlatanus@gmail.com</email>
</author>
<published>2026-04-30T22:51:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=4bc98468ecc94a76513bb9ccced40ccf72ef8c67'/>
<id>4bc98468ecc94a76513bb9ccced40ccf72ef8c67</id>
<content type='text'>
* gnu/packages/golang.scm: Copy upstream explanation on the minimal
bootstrap version for Go.

Change-Id: Ic51e9316bdd5573c1a158b320343ae72a07eeebe
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* gnu/packages/golang.scm: Copy upstream explanation on the minimal
bootstrap version for Go.

Change-Id: Ic51e9316bdd5573c1a158b320343ae72a07eeebe
</pre>
</div>
</content>
</entry>
</feed>
