September 2026
September moved on two fronts: a go1.26 upgrade applied across 13 repositories, and the
wave of releases it enabled — including the first v1.0.0 of analysis, spec and
validate, three libraries that have underpinned the stack for years. The month ran to
55 load-bearing commits across 17 active repositories (excluding bot and
release-automation authors). Away from the version bump, the concentrated work was in
go-swagger — a new init config command, case-insensitive enum code generation, and a
run of generator fixes — and testify, which gained options on assert.New and
require.New and shipped as v2.8.0. Panic fixes in jsonpointer and jsonreference
rounded out the correctness work.
Themes
- go1.26 across the stack, and the releases it cut. A
go1.26upgrade landed in 13 repositories (analysis, codescan, errors, inflect, jsonpointer, jsonreference, loads, runtime, spec, strfmt, swag, testify, ci-workflows). It cleared the way for a release wave: analysis, spec and validate each taggedv1.0.0, and jsonpointer, jsonreference and inflect reachedv1.0.x— the foundational modules declaring a stable API. runtime (v0.33.2), strfmt (v0.27.2), swag (v0.29.2), loads (v0.25.3), errors (v0.22.9) and codescan (v0.36.5) tagged alongside. - go-swagger CLI and code generation. A new
init configcommand generates a seed configuration file (#3497); a new flag turns all string enums case-insensitive in generated models (#3496);PreferServerCipherSuites, deprecated upstream, was removed from the generated server (#3490). Generator fixes: array-context validation continues past a zero-valued item (#3495), and generated parameters can now carry getters (#3491). CLI typo andinit-panic fixes and adoccommand fix landed too (#3498, #3492). Released asv0.36.6. - testify v2.8.0.
assert.Newandrequire.Newnow take options, the first beingWithHunkSizeto widen the context shown in a failing diff. Shipped with roadmap and documentation updates. - Panic and robustness fixes. jsonpointer fixes panics in
Pointer.Get,Pointer.Setand JSON name resolution (#158); jsonreference strips repeated default ports from a URL host in linear time (#123) and pulls in the jsonpointer fix as a security upgrade. - Docs and agent instructions. A
technical writing instructions for agentspass landed in errors, inflect, jsonpointer, strfmt and doc-site. doc-site also added a security advisories and alerts page with a neutral CVE posture, and published the Q3 newsletter and the August monthly report.
Repository highlights
| Repository | Latest release | Highlights |
|---|---|---|
| go-swagger | v0.36.6 | new init config command; case-insensitive string-enum codegen; removed deprecated PreferServerCipherSuites; array-context validation and parameter-getter generator fixes |
| testify | v2.8.0 | options on assert.New/require.New, starting with WithHunkSize; roadmap and docs |
| jsonpointer | v1.0.2 | fix panics in Pointer.Get, Pointer.Set and name resolution; linting config; reached v1.0 |
| jsonreference | v1.0.3 | strip repeated default ports from a URL host in linear time; jsonpointer security upgrade; reached v1.0 |
| analysis | v1.0.0 | dependency and Go version pass ahead of the v1.0.0 release |
| spec | v1.0.1 | go1.26 upgrade; stable API declared at v1.0.0 |
| validate | v1.0.0 | dependency update preparing the v1.0.0 release |
| doc-site | — | new security advisories and alerts page; Q3 newsletter; August monthly report; agent technical-writing instructions |
| ci-workflows | v0.6.2 | release workflow fix for multiple tags; go.work fixup; go1.26 |
Quarter note
September closes Q3. A quarterly report covering this period in more depth will follow.
Thanks to our contributors
Thanks to the external contributors who landed changes this month:
- @pyrohedgehog — in go-swagger, removed the deprecated
PreferServerCipherSuitesfrom the generated server (#3490) and added getters on generated parameters (#3491).