Repository navigation
Upgrade to Go 1.27.2 - #289
Merged
Merged
Conversation
rgarcia
approved these changes
Oct 9, 2026
rgarcia
marked this pull request as ready for review
October 9, 2026 14:56
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Go 1.25 and older are out of support now that Go 1.27 has shipped. This moves the repo to the latest patch release, Go 1.27.2.
go.modgo 1.25.0go 1.27.2Other places that pin the Go toolchain:
test,release,preview,fix-ci,vuln-remediation) readsgo-version-file: go.mod, so it follows this bumpAGENTS.md,DEVELOPMENT.md: required Go versionBreaking changes and GODEBUG review
Raising the
goline changes these defaults (none are overridden in this repo, viagodebugblocks,//go:debugorGODEBUGenv):urlstrictcolons=1(url.Parserejects extra colons in the host),cryptocustomrand=0(crypto ignores caller-suppliedrandreaders),tlssecpmlkem=1(SecP256r1MLKEM768/SecP384r1MLKEM1024 on by default)tracebacklabels=1(pprof goroutine labels are printed in tracebacks)Removed outright in 1.27 (new behavior regardless of the
goline):asynctimerchan,gotypesalias,tls10server,tlsrsakex,tls3des,tlsunsafeekm,x509keypairleaf. None are set here.Toolchain changes that apply as soon as 1.27 builds the code:
encoding/jsonruns on the v2 implementation (same behavior, different error text), HTTP/1Response.Body.Closedrains unread bodies,ServeMuxtrailing-slash redirects are 307 (1.26), Green Tea GC is on (1.26),go testruns thestdversionvet check, andgofmtalignment changed slightly.Repo-specific findings:
ed25519.GenerateKeyis called withcrypto/rand.Reader, socryptocustomrand=0changes nothing.url.Parse/url.ParseRequestURIcalls take vault and page URLs; only malformed hosts with stray colons (e.g.http://host:1:2) are newly rejected.Verification
cli:go build ./...pass,go vet ./...pass,go test -short ./...9 ok / 0 failed on 1.27.2 (baseline on the pre-upgrade toolchain: 9 ok / 0 failed)Notes
go.mod, so the next release ships with 1.27.2.Note
Low Risk
Version-only bump in go.mod and docs; runtime impact is limited to inherited Go 1.26/1.27 default semantics, with no repo-specific GODEBUG overrides.
Overview
Bumps the module toolchain from Go 1.25.0 to Go 1.27.2 in
go.mod, aligning docs inAGENTS.mdandDEVELOPMENT.mdwith the new minimum version.CI and release builds that use
go-version-file: go.modwill pick up 1.27.2 automatically; no workflow edits in this diff. Reviewers should be aware of standard Go 1.26/1.27 default behavior changes (e.g. stricterurl.Parsehosts, TLS/crypto defaults) now that thegoline is raised.Reviewed by Cursor Bugbot for commit 15bac21. Bugbot is set up for automated code reviews on this repo. Configure here.