Sign in

jub0bs

@jub0bs.com
2.4K followers 276 following 469 posts

infosec enthusiast • Go dev & trainer • contributor to the Go project • minimalist • chaotic good • trying to make sense of the Web • he/him Blog: jub0bs.com Free Go course: github.com/jub0bs/go-course-beginner Free 🇵🇸! Leave 🇱🇧 alone!

PostsRepliesMedia
jub0bs @jub0bs.com · 28/09/2026
Perfloop, Tomás Senart's project, identified a subtle bug (due to an oversight about preflight on my part) in the CORS library I maintain for #golang. Pretty impressive! The latest release (v1.1.3) fixes the bug in question. github.com/jub0bs/cors/... perfloop.ai
perfloop.ai
Perfloop · The Performance Machine
Perfloop learns your system from code and telemetry, hunts a wide catalog of performance patterns, and delivers a stream of proven pull requests. Software that stays fast.
000
jub0bs @jub0bs.com · 17/09/2026
Happy 40th birthday, Elliot Alderson! 🎂 #MrRobot
011
Reposted by jub0bs
Phil Eaton @eatonphil.bsky.social · 24/07/2026
I wrote an article about Go's new Green Tea garbage collector. Paywall has expired, give it a read. theconsensus.dev/p/2026/07/19...
0396
jub0bs @jub0bs.com · 30/06/2026
If "JWT" is meant to be pronounced "jot", is "JWS" meant to be pronounced "jaws"? 🦈 www.rfc-editor.org/info/rfc7519...
rfc-editor.org
RFC 7519: JSON Web Token (JWT) | RFC Editor
JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is used as the payload of a JSON ...
040
jub0bs @jub0bs.com · 11/06/2026
Security-related libraries (for CORS, JWTs, etc.) should be designed to be, not only easy to use, but hard to misuse: - pentesterlab.com/blog/secure-... by @snyff.pentesterlab.com - jub0bs.com/posts/2023-0...
pentesterlab.com
How to Securely Design Your JWT Library - PentesterLab's Blog
This article explores best practices for designing a secure JWT library, focusing on making secure implementations the default and minimizing potential vulnerabilities. Key strategies include disablin...
030
jub0bs @jub0bs.com · 03/05/2026
What a fall from grace for HackerOne, once my favourite bug-bounty platform. 😬 "HackerOne triage analyst incorrectly closes the report as a duplicate [...]" clickup.com/blog/april-2...
clickup.com
April 27th - What happened with our feature flag configuration | The ClickUp Blog
On April 27, 2026, a security researcher publicly disclosed that ClickUp’s client-side feature flag configuration exposed personally identifiable information. Specifically, 893 customer email addresse...
191
jub0bs @jub0bs.com · 01/05/2026
v0.13.3 through v1.0.1 of github.com/jub0bs/cors contain an embarrassing bug that affects functionality (though not security). Thanks to Herman Slatman for reporting it. 🙇 The bug is fixed in v1.0.2. Update when you can.
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
020
jub0bs @jub0bs.com · 28/04/2026
I've just filed a #golang issue aiming to explicitly exclude error messages from the Go 1 compatibility promise: github.com/golang/go/is...
github.com
x/website: explicitly exclude error messages from the Go 1 compatibility promise · Issue #78991 · golang/go
The document that specifies the Go 1 compatibility promise ("go1compat" for short) lists a number of exclusions: Security. A security issue in the specification or implementation may come to light ...
050
Reposted by jub0bs
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
A bit over two years after starting to work on it... Go is officially FIPS 140-3 certified 💥 csrc.nist.gov/projects/cry... I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box.
928962
Reposted by jub0bs
Ky @ky.fyi · 24/04/2026
I wrote about why I quit my job, and how weird and tiring tech feels these days.
ky.fyi
Do I belong in tech anymore?
On quitting, the spread of AI, and the loss of an ideal.
1281791545
Reposted by jub0bs
Marcus Hutchins @malwaretech.com · 21/04/2026
Shot: "We were hit by a sophisticated AI-accelerated cyberattack"
6679
jub0bs @jub0bs.com · 11/04/2026
Issue 596 of the Golang Weekly newsletter mentions the v1 release of github.com/jub0bs/cors. Nice! #golang golangweekly.com/issues/596
golangweekly.com
Golang Weekly Issue 596: April 10, 2026
#​596 — April 10, 2026
071
jub0bs @jub0bs.com · 11/04/2026
There are no benign data races. In fact, some are lethal. ☠️ en.wikipedia.org/wiki/Therac-25
en.wikipedia.org
Therac-25 - Wikipedia
The Therac-25 was a computer-controlled radiation therapy machine produced by Atomic Energy of Canada Limited (AECL) in 1982 after the Therac-6 (neptune) and Therac-20 units (the earlier units had been produced in partnership with Compagnie générale de radiologie (CGR) of France).[1]
000
Reposted by jub0bs
Go @golang.org · 07/04/2026
🥳 Go 1.26.2 and 1.25.9 are released! 🔐 Security: Includes 10 security fixes for the standard library and the toolchain. 📢 Announcement: groups.google.com/g/golang-announce… ⬇️ Download: go.dev/dl/#go1.26.2 #golang
$ go install golang.org/dl/go1.26.2@latest
$ go1.26.2 download
Downloaded   0.0% (       0 / 63701324 bytes) ...
Downloaded  50.0% (31850662 / 63701324 bytes) ...
Downloaded 100.0% (63701324 / 63701324 bytes)
Unpacking go1.26.2.linux-arm64.tar.gz ...
Success. You may now run 'go1.26.2'
$ go1.26.2 version
go version go1.26.2 linux/arm64
25813
jub0bs @jub0bs.com · 07/04/2026
🎉 After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go. Let me know whether it patches things up between you and CORS! github.com/jub0bs/cors #golang #CORS
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
2205
jub0bs @jub0bs.com · 27/03/2026
I love how the conjunction of #golang's modules system and build constraints lets you have your cake and eat it too! 🍰 You can let users of your library take advantage of the bleeding edge if they so wish without cutting off one of the currently supported Go toolchains.
190
jub0bs @jub0bs.com · 26/03/2026
Even when you cannot eliminate all bounds checks within a loop, eliminating most of them may benefit performance. 😉 #golang go-review.googlesource.com/c/go/+/759100
go-review.googlesource.com
Gerrit Code Review
1110
jub0bs @jub0bs.com · 23/03/2026
Paradoxically (perhaps), as the Go compiler becomes better at eliminating bounds checks, attacker-reachable panics due to incorrect programmer assumptions about indices become easier to find. #golang
140
jub0bs @jub0bs.com · 19/03/2026
Fewer bounds checks in #golang thanks to Youlin Feng: go-review.googlesource.com/c/go/+/719881
go-review.googlesource.com
Gerrit Code Review
030
Reposted by jub0bs
Alan Donovan @adonovan.bsky.social · 11/03/2026
Find out how the source-level inliner in Go 1.26 can help you with API migrations. go.dev/blog/inliner
go.dev
//go:fix inline and the source-level inliner - The Go Programming Language
How Go 1.26's source-level inliner works, and how it can help you with self-service API migrations.
15513
jub0bs @jub0bs.com · 09/03/2026
I've just filed a proposal to make bool an ordered type (compatible with operators <, <=, >, and >=) in #golang: github.com/golang/go/is...
github.com
proposal: spec: make bool an ordered type · Issue #78027 · golang/go
Go Programming Experience Experienced Other Languages Experience Python, Haskell, JavaScript, C Related Idea Has this idea, or one like it, been proposed before? Does this affect error handling? Is...
190
jub0bs @jub0bs.com · 02/03/2026
#golang quiz: What happens if you try to compile and run the following program? package main import ( "fmt" "math" ) func main() { fmt.Println(int(math.NaN())) } a. It prints 0. b. It prints -1. c. It panics. d. Compilation fails. e. Something else.
100
jub0bs @jub0bs.com · 26/02/2026
🚀 "spec: generic methods for Go" has been accepted! You will soon (1.27?) be able to declare (on concrete types only) methods that introduce type parameters, i.e. type parameters other than the ones (if any) that come from the method's receiver. github.com/golang/go/is... #golang
github.com
spec: generic methods for Go · Issue #77273 · golang/go
Proposal: Generic Methods for Go A change of view. Background For clarity, in the following we use the term concrete method (or just method when the context is clear) to describe a non-interface me...
3113
jub0bs @jub0bs.com · 25/02/2026
A friendly reminder that a Go program doesn't need an import of the "unsafe" package to undermine the language's type system; a synchronisation bug may be enough: go.dev/play/p/L0_Zr... #golang
go.dev
Go Playground - The Go Programming Language
270
jub0bs @jub0bs.com · 22/02/2026
For months (maybe years, even) now, I've been accumulating notes with a view to producing a performance-oriented Go training course. There's just so many techniques and tools to master! I'm hopeful for a release some time in 2026, though. 🤞 #golang
090
jub0bs @jub0bs.com · 21/02/2026
If you've already migrated to Go 1.26, there's no longer any point in relying on github.com/jub0bs/errutil. Simply rely on errors.Astype instead. pkg.go.dev/errors#AsType #golang
pkg.go.dev
errors package - errors - Go Packages
032
jub0bs @jub0bs.com · 12/02/2026
🎉 I've just released v0.12.0 of jub0bs/cors, my CORS middleware library for #golang! - Go 1.25 or above is now required. - Some minor performance improvements. Still guaranteed free of AI slop, of course. github.com/jub0bs/cors
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
190
Reposted by jub0bs
Go @golang.org · 10/02/2026
🎆 Go 1.26.0 is released! 🗒️ Release notes: go.dev/doc/go1.26 ⬇️ Download: go.dev/dl/#go1.26.0 #golang
$ go install golang.org/dl/go1.26.0@latest
$ go1.26.0 download
Downloaded   0.0% (       0 / 63102509 bytes) ...
Downloaded  50.0% (31551254 / 63102509 bytes) ...
Downloaded 100.0% (63102509 / 63102509 bytes)
Unpacking go1.26.0.openbsd-arm64.tar.gz ...
Success. You may now run 'go1.26.0'
$ go1.26.0 version
go version go1.26.0 openbsd/arm64
217349
jub0bs @jub0bs.com · 10/02/2026
#golang quizz: why is the implementation of the following function naive/incorrect, and how would you fix it? 😉 // opposite returns the opposite of comparator function cmp. func opposite[T any](cmp func(T, T) int) func(T, T) int { return func(x, y T) int { return -cmp(x, y) } }
120
jub0bs @jub0bs.com · 09/02/2026
I must confess I regret github.com/golang/go/is.... I've since found cmp.Or to be quite useful, esp. for implementing comparator functions for struct types. Thanks to @carlana.net for pushing for its addition to #golang's standard library.
github.com
cmp: add Or · Issue #60204 · golang/go
An extremely common string operation is testing if a string is blank and if so replacing it with a default value. I propose adding First(...strings) string to package strings (and probably an equiv...
0100
jub0bs @jub0bs.com · 08/02/2026
Well, I might produce a v0.12.0 to accompany Go 1.26, whose release is imminent.
030
jub0bs @jub0bs.com · 03/02/2026
Rare enough to be worth sharing: a video about CORS of remarkable precision, courtesy of Digital Boundary Group's Ryan Armstrong: www.youtube.com/watch?v=79Ud...
youtube.com
Cross-App Security: Cross-Origin Resource Sharing (CORS)
YouTube video by Ryan Armstrong
041
jub0bs @jub0bs.com · 31/01/2026
🎉 I've just released v0.11.0 of jub0bs/cors, my CORS middleware library for Go! Bar any surprises, this will be the last minor release before v1. github.com/jub0bs/cors
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
1173
Reposted by jub0bs
Daniel Martí @handle.invalid · 23/01/2026
Interesting expansion of generics in #golang 👀
github.com
Proposal: Generic Methods for Go · Issue #77273 · golang/go
Proposal: Generic Methods for Go A change of view. Background For clarity, in the following we use the term concrete method (or just method when the context is clear) to describe a non-interface me...
3368
Reposted by jub0bs
thepudds @thepudds.bsky.social · 16/01/2026
A good way to keep up with the Go project is this starter pack from @mvdan.cc (long-time #golang contributor). Two other good ways to keep up are subscribing to the Go proposal review meeting GitHub issue: go.dev/issue/33502 and the Go compiler & runtime meeting notes issue: go.dev/issue/43930
0143
Reposted by jub0bs
thepudds @thepudds.bsky.social · 14/01/2026
Related #golang PSA: Gophers often mistakenly put a -u in 'go get -u foo', when they would have been better off with just 'go get foo'. 'go get foo' says to upgrade foo itself. It's shorthand for 'go get foo@upgrade' 'go get -u foo' says to *also* upgrade all the direct and indirect deps of foo.
12910
jub0bs @jub0bs.com · 08/01/2026
Developers who rely on AI coding agents to produce documentation for otherwise undocumented code, have you heard of Hyrum's law? 🤔 www.hyrumslaw.com Can you guarantee that the resulting documentation only advertises behaviour that was intended by the author(s) and isn't merely accidental? (No.) 🙄
hyrumslaw.com
Hyrum's Law
290
Reposted by jub0bs
Jake Bailey @jakebailey.dev · 07/01/2026
My GopherCon talk was just posted!
youtu.be
GopherCon 2025: Porting the TypeScript Compiler to Go for a 10x Speedup V2 - Jake Bailey
YouTube video by Gopher Academy
27819
Reposted by jub0bs
Anton Zhiyanov @antonz.org · 02/12/2025
Accepted! Go 1.26 will introduce errors.AsType — a modern, type-safe alternative to the clunky errors.As. No reflection. No runtime panics. Concise code. This is big! antonz.org/accepted/err...
antonz.org
Go proposal: Type-safe error checking
errors.AsType is a modern alternative to errors.As.
2164
jub0bs @jub0bs.com · 13/12/2025
☝️Unpopular opinion: most Gophers should (re-)read @joshbloch.bsky.social's Effective Java book. Much (though not all) of the wisdom it contains is transferable to #golang.
282
jub0bs @jub0bs.com · 12/12/2025
Difficult to disagree with this post by Efron Licht: Gin, #golang's arguably most popular Web framework, is pretty bad and should be avoided at all costs. 🙅 eblog.fly.dev/ginbad.html
eblog.fly.dev
ginbad.md
A good software article you should probably read
051
jub0bs @jub0bs.com · 21/11/2025
Your weekly reminder to migrate from rs/cors to jub0bs/cors. 😇 github.com/rs/cors/issu...
github.com
With some CORS configurations, some handlers can introduce synchronisation bugs and cause data races · Issue #198 · rs/cors
Problem Presumably for performance, the library (v1.11.1 and some older versions) reuses some non-exported slice variables and struct field from one middleware call to the next: package-level var h...
052
Reposted by jub0bs
Filippo Valsorda @filippo.abyssdomain.expert · 19/11/2025
So tempted to write a troll thread on how this incident shows Rust has bad error handling and wouldn’t have happened in Go, where we actually handle errors 🫣🫢😜 blog.cloudflare.com/18-november-...
blog.cloudflare.com
Cloudflare outage on November 18, 2025
Cloudflare suffered a service outage on November 18, 2025. The outage was triggered by a bug in generation logic for a Bot Management feature file causing many Cloudflare services to be affected.
1513221
Reposted by jub0bs
Nicolas Grégoire @agarri.fr · 07/11/2025
The release candidate of the OWASP Top 10 2025 has been released owasp.org/Top10/2025/0... The definitive release should be out on November 20th
owasp.org
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
0811
jub0bs @jub0bs.com · 09/11/2025
"A good API should be, not only easy to use, but also hard to misuse." (Josh Bloch) github.com/rs/cors/issu... #golang #CORS
github.com
Near-arbitrary origins can still be allowed with credentials · Issue #197 · rs/cors
Problem PR #56 implemented a restriction regarding the wildcard; middleware created as follows don't reflect arbitrary origins (good): cors.New(cors.Options{ AllowedOrigins: []string{"*"}, AllowCre...
080
jub0bs @jub0bs.com · 04/11/2025
Productivity tip: don't have kids; don't have cats. 😬
130
Reposted by jub0bs
Go @golang.org · 07/10/2025
🥳 Go 1.25.2 and 1.24.8 are released! 📢 Announcement: groups.google.com/g/golang-announce… 📦 Download: go.dev/dl/#go1.25.2 #golang
$ go install golang.org/dl/go1.25.2@latest
$ go1.25.2 download
Downloaded   0.0% (       0 / 58280426 bytes) ...
Downloaded  50.0% (29140213 / 58280426 bytes) ...
Downloaded 100.0% (58280426 / 58280426 bytes)
Unpacking go1.25.2.linux-riscv64.tar.gz ...
Success. You may now run 'go1.25.2'
$ go1.25.2 version
go version go1.25.2 linux/riscv64
04819
jub0bs @jub0bs.com · 25/09/2025
"Bonjour. Je suis Nicolas Sarkozy, et j'ai le grand plaisir de lire 'Le temps des oranges' pour Audible." 😂
010
jub0bs @jub0bs.com · 24/09/2025
CVE-2025-10630: REDoS in Zabbix plugin for Grafana dashboard (fixed in v6.0.2) To anybody relying on some PCRE engine (such as github.com/dlclark/regexp2): either forbid users to submit arbitrary patterns or enforce some reasonable timeout on matching. #websecurity #golang youtu.be/Z_mYyBYP4ZI
youtu.be
CVE-2025-10630: REDoS in Zabbix plugin for Grafana dashboard (fixed in v6.0.2)
YouTube video by jub0bs
000