August 2026
codescan still accounted for the largest share of the month’s roughly 600 load-bearing commits across seventeen active repositories, but its work has settled into steady iteration after July’s mono-repo rework. The month’s larger story is the emerging shape of go-openapi/v2: a new go-yaml repository — a fork of goccy/go-yaml — drew nearly as much activity as codescan while a rewritten streaming parser takes form; a new go-openapi/codegen cut its first v0.0.1 by externalizing go-swagger’s code-generation machinery; and the long-serving spec, analysis and validate libraries reached a feature freeze, their remaining known issues deferred to v2.
Themes
- codescan, on three axes. Steady iteration rather than last month’s rework: a run of quirk fixes; new features — a standalone
genspeccommand-line generator, an improved TUI that shares the CLI’s flags and configuration file, and automatic detection of standard-library types; and a performance push built on an internalized package loader that reads dependencies from source or compiled packages, leverages the build cache, and makes the toolchain dependency opt-in — cutting scan time and memory. - A new YAML foundation (go-yaml). A fork of
goccy/go-yamlunder intensive development — a streaming, arena-backed parser rewrite focused on throughput and allocation — aiming to become go-openapi’s reference YAML parsing and document-processing library. - Code generation externalized (codegen). A new
go-openapi/codegen(v0.0.1) lifts go-swagger’s generation machinery into its own module: name mangling, a code-generation harness, and a toolchain-free Go formatter (gofumpt options, package-name resolution viago list, output confined to a root). These are go-openapi/v2 components; go-swagger v0.37.0 will begin consuming them next month. - spec, analysis and validate frozen. A final correctness pass: deterministic, reproducible schema expansion (sorted map walks) first, then
$ref/URL normalization aligned withjsonreference,validateno longer rewriting the caller’s document, and a gob round-trip that no longer drops zero-valued fields. With this the three libraries have reached the limits of their exposed data model; they remain maintained, but their APIs are frozen and known issues are deferred to go-openapi/v2. The fixes were onboarded downstream into go-swagger. - testify v2.7.0. The headline is go1.27 generic forward methods — forwarded assertions now support generics, guarded so pre-1.27 builds are unaffected — alongside assertion correctness fixes (mixed-sign
EqualValues,InDelta*reporting, rune/byteContains, a newErrorNotContains) and defensive recursion guards. - Security and CI. Control-character/escape handling in the codescan TUI; a template-injection autofix in go-swagger’s workflows; and a shared change-detection workflow in ci-workflows (replacing
tj-actions/changed-files) that go-swagger adopted to simplify its own pipelines.
Repository highlights
| Repository | Latest release | Highlights |
|---|---|---|
| codescan | v0.36.4 | internalized package loader (large time/memory gains, opt-in toolchain independence); standalone genspec CLI; improved TUI; stdlib type auto-detection; quirk fixes |
| go-yaml | — | new fork of goccy/go-yaml; streaming, low-allocation parser rewrite toward a reference YAML library |
| codegen | v0.0.1 | externalized go-swagger codegen: name mangling, generation harness, toolchain-free Go formatter; a go-openapi/v2 component |
| go-swagger | v0.36.5 | generator fixes and new CLI flags; discriminator allOf models; markdown CLI usage docs; template-injection autofix; workflows simplified onto shared CI |
| testify | v2.7.0 | go1.27 generic forward methods; assertion correctness fixes; recursion guards |
| validate | v0.26.5 | no in-place mutation of the caller’s document while validating; message-stability tests (now frozen) |
| spec | v0.22.11 | deterministic, reproducible expansion; $ref/URL normalization aligned with jsonreference; gob zero-value round-trip fix (now frozen) |
| analysis | v0.26.2 | flatten $refs under unmapped keywords; expose where each $ref is declared (now frozen) |
| ci-workflows | v0.6.1 | shared change-detection workflow (drops tj-actions/changed-files); go-test workflow options |
| loads | v0.25.2 | onboarded spec/analysis expansion fixes |
| swag | v0.29.1 | dependency and normalization alignment |
| jsonreference | v1.0.1 | $ref canonicalization fixes |
| runtime | v0.33.1 | maintenance release |
Thanks to our contributors
Thanks to the external contributors who landed changes this month, all in go-swagger:
- @pyrohedgehog — added generation of optional getters for all fields.
- @RubenPari — a run of generator fixes and new CLI flags (
--with-go-run,--no-default-omit-empty, enum const blocks, nil-pointer and import fixes). - @bobcallaway — guarded the generator against nil parameters.
- @014-code — handled discriminator
allOfmodels in the generator. - @sanmaxdev — replaced an obsolete middleware example in the docs.