NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #274 by repository stars
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 1 weeks
Rarely documented
notes for 14 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
940 releases · first in 2020
One column per quarter.
run unit tests on windows and fix the handle leaks it surfaced [PR #3766 @wagoodman ]
9 dependency changes (9 updated).
Updated (9 packages)v0.2.1 → v0.2.2v0.3.3 → v0.3.4v1.54.0 → v1.54.1v29.8.1+incompatible → v29.8.2+incompatiblev1.20.0 → v1.20.1v0.11.0 → v0.11.1v0.5.1 → v0.5.2v1.10.8 → v1.10.11v2.24.1 → v2.24.2Latest
Latest
Compare
Nothing published for this version
Nothing published for this version
88 dependency changes (59 updated, 27 added, 2 removed). 2 vulnerabilities remediated.
match.dpkg.using-cpes (and match.rpm.using-cpes) is accepted but has no effect [Issue #3746] [PR #3747 @amitschendel]match.rpm.using-cpes has no effect [Issue #3752] [PR #3753 @amitschendel]88 dependency changes (59 updated, 27 added, 2 removed). 2 vulnerabilities remediated.
🟢 Remediated (2)
Toolchains (1)
1.26.3 → 1.26.8v0.15.0-rc.1 → v0.15.0-rc.4v0.2.1 → v0.2.2v0.1.1 → v0.2.0v0.2.0 → v0.2.1v0.3.2 → v0.3.3v1.52.0 → v1.54.0v4.10.0 → v4.10.2v1.11.1 → v1.12.0v2.3.5 → v2.4.1 (🟢 remediated GHSA-pg57-6jwg-q645)v0.1.0 → v0.2.0v1.2.8 → v1.2.9v2.2.3 → v2.3.0v0.6.1 → v0.7.0v29.8.0+incompatible → v29.8.1+incompatiblev0.9.5 → v0.9.8v1.0.1 → v1.1.0v0.3.0 → v0.3.1v1.0.4 → v1.1.0v1.9.0 → v1.10.1v1.22.0 → v1.23.0v4.1.4 → v4.1.5v1.4.3 → v1.4.4v2.28.0 → v2.30.0v2.24.0 → v2.25.0v1.18.11 → v1.18.12v0.0.21 → v0.0.27v1.14.23 → v1.14.48v0.4.0 → v0.4.1v0.1.0 → v0.2.1v2.2.0 → v2.4.1v1.1.4 → v1.1.5v0.2.8 → v0.2.9v0.1.5 → v0.1.7v1.9.4 → v1.10.2v0.5.16 → v0.5.17v1.16.3 → v1.19.0v1.4.3 → v1.5.0v0.68.0 → v0.71.0v0.68.0 → v0.71.0v1.44.0 → v1.46.0v1.43.0 → v1.46.0 (🟢 remediated GHSA-8wmf-6v46-5gfg)v1.43.0 → v1.46.0 (🟢 remediated GHSA-8wmf-6v46-5gfg)v1.44.0 → v1.46.0v0.66.0 → v0.68.0v1.44.0 → v1.46.0 (🟢 remediated GHSA-8wmf-6v46-5gfg)v1.44.0 → v1.46.0v1.44.0 → v1.46.0v1.10.0 → v1.11.0v0.56.0 → v0.57.0v0.58.0 → v0.59.0v0.22.0 → v0.23.0v0.47.0 → v0.48.0v0.45.0 → v0.46.0v0.41.0 → v0.42.0v0.49.0 → v0.50.0v0.0.0-e75dac1 → v0.0.0-da73d73v0.0.0-08b0e42 → v0.0.0-da73d73v1.75.6 → v1.75.7v1.58.0 → v1.59.0v0.2.5v1.2.0v17.0.1v0.1.0v0.18.2v0.0.0-c1716e8v1.3.2v0.0.0-19d51d7v0.0.2v1.1.2v4.0.0v0.4.0v1.15.1v0.1.6v0.11.0v1.8.7v0.5.1v1.10.8v0.2.1v0.0.0-7828495v2.3.3v0.12.3v0.0.4v8.14.0v0.0.0-a2c0da2v5.41.2v1.64.1v1.3.2v0.24.0Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
54 dependency changes (54 updated). 6 vulnerabilities remediated.
--show-suppressed can surface them [Issue #3450] [PR #3705 @philroche]--by-cve: which advisory record survives the merge varies between runs [Issue #3630]54 dependency changes (54 updated). 6 vulnerabilities remediated.
🟢 Remediated (6)
v0.22.0 → v0.23.2v1.11.0 → v1.12.0v1.18.0 → v1.19.0v1.29.0 → v1.30.0v1.64.0 → v1.65.1v0.11.0 → v0.12.0v0.1.1 → v0.1.2v0.3.1 → v0.3.2v1.51.1 → v1.52.0v1.43.4 → v1.44.0v1.7.16 → v1.7.20v1.32.35 → v1.32.40v1.19.34 → v1.19.39v1.18.35 → v1.18.40v1.4.35 → v1.4.40v2.7.35 → v2.7.40v1.4.36 → v1.4.41v1.13.15 → v1.13.19v1.9.28 → v1.10.0v1.13.35 → v1.13.40v1.19.36 → v1.19.41v1.106.5 → v1.108.0v1.5.4 → v1.6.0v1.33.4 → v1.34.0v1.38.4 → v1.39.0v1.45.4 → v1.46.0v1.27.6 → v1.28.1v2.3.4 → v2.3.5 (🟢 remediated GHSA-7jxh-36q5-gcqv)v29.7.2+incompatible → v29.8.0+incompatiblev0.21.9 → v0.22.1v0.3.19 → v0.3.20v2.23.0 → v2.24.0v0.25.0 → v0.26.3v1.8.8 → v1.8.9v1.19.2 → v1.20.0v1.55.0 → v1.56.0v0.5.1 → v0.6.0v0.6.2 → v0.6.4v0.1.6 → v0.1.8v0.55.0 → v0.56.0 (🟢 remediated GO-2026-6354, GO-2026-6355)v0.40.0 → v0.41.0v0.15.0 → v0.16.0v0.292.0 → v0.294.0v0.0.0-aa98bba → v0.0.0-e75dac1v0.0.0-925bb5d → v0.0.0-e75dac1v0.0.0-6ac0973 → v0.0.0-08b0e42v1.83.0 → v1.83.2 (🟢 remediated GHSA-2v4p-qf9q-27wj, GHSA-qc2q-p7wx-3px3, GHSA-vp52-pcj8-j9qc)v1.36.12-0.f2248ac → v1.36.12v4.29.1 → v4.29.2v4.34.6 → v4.35.0v3.1.4 → v3.1.5v1.74.4 → v1.75.6v1.11.0 → v1.12.1v1.56.0 → v1.58.0Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
CVSSv4 calculation can produce incorrect vulnerability severity [Issue #3656 ]
72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.
🟢 Remediated (3)
v0.25.1 → v0.25.2v0.18.2 → v0.22.0v1.5.3 → v1.11.0v1.13.1 → v1.18.0v0.8.0 → v1.2.0v1.24.3 → v1.29.0v1.61.3 → v1.64.0v1.11.7 → v1.16.0v1.32.0 → v1.33.0v0.55.0 → v0.57.0v0.55.0 → v0.57.0v0.55.0 → v0.57.0v0.3.0 → v0.3.1v1.51.0 → v1.51.1v1.41.5 → v1.43.4v1.7.8 → v1.7.16v1.32.12 → v1.32.35v1.19.12 → v1.19.34v1.18.20 → v1.18.35v1.4.21 → v1.4.35v2.7.21 → v2.7.35v1.4.22 → v1.4.36v1.13.7 → v1.13.15v1.9.13 → v1.9.28v1.13.21 → v1.13.35v1.19.21 → v1.19.36v1.97.3 → v1.106.5v1.0.8 → v1.5.4v1.30.13 → v1.33.4v1.35.17 → v1.38.4v1.41.9 → v1.45.4v1.24.2 → v1.27.6v2.3.3 → v2.3.4v1.0.0-rc.4 → v1.0.0-rc.5v29.6.1+incompatible → v29.7.2+incompatiblev0.7.0 → v0.8.1v1.18.0 → v1.19.0v0.21.7 → v0.21.9v0.0.0-6e76a2b → v0.0.0-ef3492dv0.3.14 → v0.3.19v2.17.0 → v2.23.0v2.0.0-beta.72 → v2.0.0-beta.74v1.8.6 → v1.8.8v1.8.0 → v1.9.0v1.19.1 → v1.19.2v0.0.20 → v0.0.24v0.5.0 → v0.5.1v2.6.0 → v2.7.0v0.5.2 → v0.5.3v1.11.1 → v1.12.1v1.43.0 → v1.44.0v1.43.0 → v1.44.0 (🟢 remediated GO-2026-5158)v1.40.0 → v1.44.0v1.43.0 → v1.44.0v1.43.0 → v1.44.0v1.43.0 → v1.44.0v1.43.0 → v1.44.0v0.54.0 → v0.55.0v0.38.0 → v0.40.0 (🟢 remediated GO-2026-6179, GO-2026-6180)v0.57.0 → v0.58.0v0.40.0 → v0.41.0v0.48.0 → v0.49.0v0.271.0 → v0.292.0v0.0.0-8636f87 → v0.0.0-aa98bbav0.0.0-afd174a → v0.0.0-925bb5dv0.0.0-afd174a → v0.0.0-6ac0973v1.82.1 → v1.83.0v4.29.0 → v4.29.1v1.74.1 → v1.74.4v1.55.0 → v1.56.0v0.66.0v1.8.6Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Include vulnerable ranges in CycloneDX output format [Issue #3512 ] [PR #3519 @somaz94 ]
11 dependency changes (11 updated). 2 vulnerabilities remediated.
🟢 Remediated (2)
v1.50.0 → v1.51.0v1.9.3 → v1.9.4v1.4.13 → v1.4.15v5.9.0 → v5.9.1v5.19.1 → v5.19.2 (🟢 remediated GHSA-hc8v-wwc9-vgxm, GHSA-qgq7-7hm3-q39j)v1.19.0 → v1.19.1v1.8.10 → v1.18.11v6.0.2 → v6.0.3v0.5.15 → v0.5.16v3.0.4 → v3.0.5v1.54.0 → v1.55.0b5fa92b
This commit was created on GitHub.com and signed with GitHub’s verified signature .
GPG key ID: B5690EEEBB952194
Verified Learn about vigilant mode .
11 dependency changes (11 updated). 2 vulnerabilities remediated.
🟢 Remediated (2)
GHSA-hc8v-wwc9-vgxm (High) — github.com/go-git/go-git/v5
GHSA-qgq7-7hm3-q39j (Medium) — github.com/go-git/go-git/v5 Updated (11 packages)
github.com/anchore/syft v1.50.0 → v1.51.0
github.com/diskfs/go-diskfs v1.9.3 → v1.9.4
github.com/gabriel-vasile/mimetype v1.4.13 → v1.4.15
github.com/go-git/go-billy/v5 v5.9.0 → v5.9.1
github.com/go-git/go-git/v5 v5.19.1 → v5.19.2 (🟢 remediated GHSA-hc8v-wwc9-vgxm , GHSA-qgq7-7hm3-q39j )
github.com/klauspost/compress v1.19.0 → v1.19.1
github.com/magiconair/properties v1.8.10 → v1.18.11
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 → v6.0.3
github.com/ulikunitz/xz v0.5.15 → v0.5.16
go.yaml.in/yaml/v3 v3.0.4 → v3.0.5
modernc.org/sqlite v1.54.0 → v1.55.0
(Full Changelog)
Dashtid and somaz94
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
grype reporting CVE-64091 as critical - redhat says it is not affected [Issue #3591 ]
30 dependency changes (30 updated). 1 vulnerability remediated.
🟢 Remediated (1)
v1.31.0 → v1.32.0v0.2.2 → v0.3.0v1.48.0 → v1.50.0v0.0.0-ee656c7 → v0.0.0-dba9d58v2.3.2 → v2.3.3v29.5.3+incompatible → v29.6.1+incompatiblev1.36.0 → v1.37.0v1.3.0 → v1.3.3v0.5.22 → v0.5.23v0.24.1 → v0.25.0v1.54.2 → v1.55.0v0.4.1 → v0.5.0v2.3.1 → v2.4.3v1.39.0 → v1.43.0v0.53.0 → v0.54.0v0.37.0 → v0.38.0v0.56.0 → v0.57.0v0.21.0 → v0.22.0v0.46.0 → v0.47.0v0.44.0 → v0.45.0v0.39.0 → v0.40.0v0.47.0 → v0.48.0v0.0.0-9d38bb4 → v0.0.0-afd174av0.0.0-6f92a3b → v0.0.0-afd174av1.80.0 → v1.82.1 (🟢 remediated GHSA-hrxh-6v49-42gf)v4.28.4 → v4.29.0v4.34.4 → v4.34.6v3.1.3 → v3.1.4v1.73.4 → v1.74.1v1.53.0 → v1.54.0Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Go vulnerability returned when installed version is greater than fixed version [Issue #3520 ]
govulndb GO-* ID and its GHSA) [Issue #3511] [PR #3509 @spiffcs]14 dependency changes (11 updated, 3 added).
Updated (11 packages)v0.1.0 → v0.2.0v1.46.0 → v1.48.0v1.18.6 → v1.19.0v0.38.0 → v0.39.0v0.46.0 → v0.47.0v1.31.1 → v1.31.2v4.28.2 → v4.28.4v4.34.0 → v4.34.4v3.1.2 → v3.1.3v1.72.3 → v1.73.4v1.51.0 → v1.53.0v1.14.23v1.6.0v1.0.1Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →