Skip to content

Upgrade to Go 1.27.2 - #289

Merged
rgarcia merged 2 commits into
mainfrom
hypeship/go-1.27
Oct 9, 2026
Merged

rgarcia merged 2 commits into
mainfrom
hypeship/go-1.27

Conversation

@tnsardesai

@tnsardesai tnsardesai commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Go 1.25 and older are out of support now that Go 1.27 has shipped. This moves the repo to the latest patch release, Go 1.27.2.

module before after
go.mod go 1.25.0 go 1.27.2

Other places that pin the Go toolchain:

  • CI (test, release, preview, fix-ci, vuln-remediation) reads go-version-file: go.mod, so it follows this bump
  • AGENTS.md, DEVELOPMENT.md: required Go version

Breaking changes and GODEBUG review

Raising the go line changes these defaults (none are overridden in this repo, via godebug blocks, //go:debug or GODEBUG env):

  • Go 1.26: urlstrictcolons=1 (url.Parse rejects extra colons in the host), cryptocustomrand=0 (crypto ignores caller-supplied rand readers), tlssecpmlkem=1 (SecP256r1MLKEM768/SecP384r1MLKEM1024 on by default)
  • Go 1.27: tracebacklabels=1 (pprof goroutine labels are printed in tracebacks)

Removed outright in 1.27 (new behavior regardless of the go line): asynctimerchan, gotypesalias, tls10server, tlsrsakex, tls3des, tlsunsafeekm, x509keypairleaf. None are set here.

Toolchain changes that apply as soon as 1.27 builds the code: encoding/json runs on the v2 implementation (same behavior, different error text), HTTP/1 Response.Body.Close drains unread bodies, ServeMux trailing-slash redirects are 307 (1.26), Green Tea GC is on (1.26), go test runs the stdversion vet check, and gofmt alignment changed slightly.

Repo-specific findings:

  • ed25519.GenerateKey is called with crypto/rand.Reader, so cryptocustomrand=0 changes nothing.
  • url.Parse / url.ParseRequestURI calls take vault and page URLs; only malformed hosts with stray colons (e.g. http://host:1:2) are newly rejected.

Verification

  • cli: go build ./... pass, go vet ./... pass, go test -short ./... 9 ok / 0 failed on 1.27.2 (baseline on the pre-upgrade toolchain: 9 ok / 0 failed)

Notes

  • Release binaries are built by GoReleaser with the version from go.mod, so the next release ships with 1.27.2.

Note

Low Risk
Version-only bump in go.mod and docs; runtime impact is limited to inherited Go 1.26/1.27 default semantics, with no repo-specific GODEBUG overrides.

Overview
Bumps the module toolchain from Go 1.25.0 to Go 1.27.2 in go.mod, aligning docs in AGENTS.md and DEVELOPMENT.md with the new minimum version.

CI and release builds that use go-version-file: go.mod will pick up 1.27.2 automatically; no workflow edits in this diff. Reviewers should be aware of standard Go 1.26/1.27 default behavior changes (e.g. stricter url.Parse hosts, TLS/crypto defaults) now that the go line is raised.

Reviewed by Cursor Bugbot for commit 15bac21. Bugbot is set up for automated code reviews on this repo. Configure here.

@rgarcia
rgarcia marked this pull request as ready for review October 9, 2026 14:56
@rgarcia
rgarcia merged commit 8772650 into main Oct 9, 2026
8 checks passed
@rgarcia
rgarcia deleted the hypeship/go-1.27 branch October 9, 2026 14:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants