📖 4 min read (~ 700 words).

August 2026

codescan still accounted for the largest share of the month’s roughly 600 load-bearing commits across seventeen active repositories, but its work has settled into steady iteration after July’s mono-repo rework. The month’s larger story is the emerging shape of go-openapi/v2: a new go-yaml repository — a fork of goccy/go-yaml — drew nearly as much activity as codescan while a rewritten streaming parser takes form; a new go-openapi/codegen cut its first v0.0.1 by externalizing go-swagger’s code-generation machinery; and the long-serving spec, analysis and validate libraries reached a feature freeze, their remaining known issues deferred to v2.

Themes

  • codescan, on three axes. Steady iteration rather than last month’s rework: a run of quirk fixes; new features — a standalone genspec command-line generator, an improved TUI that shares the CLI’s flags and configuration file, and automatic detection of standard-library types; and a performance push built on an internalized package loader that reads dependencies from source or compiled packages, leverages the build cache, and makes the toolchain dependency opt-in — cutting scan time and memory.
  • A new YAML foundation (go-yaml). A fork of goccy/go-yaml under intensive development — a streaming, arena-backed parser rewrite focused on throughput and allocation — aiming to become go-openapi’s reference YAML parsing and document-processing library.
  • Code generation externalized (codegen). A new go-openapi/codegen (v0.0.1) lifts go-swagger’s generation machinery into its own module: name mangling, a code-generation harness, and a toolchain-free Go formatter (gofumpt options, package-name resolution via go list, output confined to a root). These are go-openapi/v2 components; go-swagger v0.37.0 will begin consuming them next month.
  • spec, analysis and validate frozen. A final correctness pass: deterministic, reproducible schema expansion (sorted map walks) first, then $ref/URL normalization aligned with jsonreference, validate no longer rewriting the caller’s document, and a gob round-trip that no longer drops zero-valued fields. With this the three libraries have reached the limits of their exposed data model; they remain maintained, but their APIs are frozen and known issues are deferred to go-openapi/v2. The fixes were onboarded downstream into go-swagger.
  • testify v2.7.0. The headline is go1.27 generic forward methods — forwarded assertions now support generics, guarded so pre-1.27 builds are unaffected — alongside assertion correctness fixes (mixed-sign EqualValues, InDelta* reporting, rune/byte Contains, a new ErrorNotContains) and defensive recursion guards.
  • Security and CI. Control-character/escape handling in the codescan TUI; a template-injection autofix in go-swagger’s workflows; and a shared change-detection workflow in ci-workflows (replacing tj-actions/changed-files) that go-swagger adopted to simplify its own pipelines.

Repository highlights

RepositoryLatest releaseHighlights
codescanv0.36.4internalized package loader (large time/memory gains, opt-in toolchain independence); standalone genspec CLI; improved TUI; stdlib type auto-detection; quirk fixes
go-yaml—new fork of goccy/go-yaml; streaming, low-allocation parser rewrite toward a reference YAML library
codegenv0.0.1externalized go-swagger codegen: name mangling, generation harness, toolchain-free Go formatter; a go-openapi/v2 component
go-swaggerv0.36.5generator fixes and new CLI flags; discriminator allOf models; markdown CLI usage docs; template-injection autofix; workflows simplified onto shared CI
testifyv2.7.0go1.27 generic forward methods; assertion correctness fixes; recursion guards
validatev0.26.5no in-place mutation of the caller’s document while validating; message-stability tests (now frozen)
specv0.22.11deterministic, reproducible expansion; $ref/URL normalization aligned with jsonreference; gob zero-value round-trip fix (now frozen)
analysisv0.26.2flatten $refs under unmapped keywords; expose where each $ref is declared (now frozen)
ci-workflowsv0.6.1shared change-detection workflow (drops tj-actions/changed-files); go-test workflow options
loadsv0.25.2onboarded spec/analysis expansion fixes
swagv0.29.1dependency and normalization alignment
jsonreferencev1.0.1$ref canonicalization fixes
runtimev0.33.1maintenance release

Thanks to our contributors

Thanks to the external contributors who landed changes this month, all in go-swagger:

  • @pyrohedgehog — added generation of optional getters for all fields.
  • @RubenPari — a run of generator fixes and new CLI flags (--with-go-run, --no-default-omit-empty, enum const blocks, nil-pointer and import fixes).
  • @bobcallaway — guarded the generator against nil parameters.
  • @014-code — handled discriminator allOf models in the generator.
  • @sanmaxdev — replaced an obsolete middleware example in the docs.