Sign in

Winni Neessen

@neessen.dev
21 followers 20 following 49 posts

I work in InfoSec. Music-lover, Record-collector, Go-Enthusiast, Perl-veteran. Vir potens spiritus. Mastodon: s.pebcak.de/@winni

PostsRepliesMedia
Reposted by Winni Neessen
Go @golang.org · 19/08/2026
“Go 1.27 is released” by Nicholas Husin, on behalf of the Go team — go.dev/blog/go1.27 #golang
17730
Reposted by Winni Neessen
go-mail @go-mail.dev · 04/07/2026
Great news! go-mail v0.8.0 has just been released and it's a biggie! This release adds native NTLMv2 and DKIM support as well as bunch of cool improvements and fixes. Thanks to everybody who contributed to this release! github.com/wneessen/go-... #go #gomail #smtp #dkim #ntlm
github.com
Release v0.8.0: Native NTLM and DKIM support · wneessen/go-mail
Welcome to go-mail v0.8.0! 🎉 This release brings two big new features and a couple of improvements and fixes to go-mail. We hope you enjoy this release! ImportantThis release adds a new dependency ...
021
Winni Neessen @neessen.dev · 02/07/2026
go-mail v0.8.0 is going to be a good one. Not only will there be native NTLM auth support, but also native DKIM signing (currently work in progress). The signing and canonicalization is working fine alreay. Only the API needs some work, as well as proper test coverage. #go #gomail #dkim
Screenshot showing successful DKIM signing with go-mail
000
Winni Neessen @neessen.dev · 01/07/2026
It took some time, but it's finally working... go-mail v0.8.0 (release planned in the next few days) will add native NTMLv2 SMTP authentication support (without any 3rd party library dependency). #go #gomail #golang #ntlm #smtp
curl.se
The NTLM Authentication Protocol and Security Support Provider
030
Winni Neessen @neessen.dev · 12/05/2026
Great news! go-mail v0.7.3 has just been released and brings some cool new features/improvements and some bug fixes. Thanks to everybody who contributed to this release! All release details can be found here: github.com/wneessen/go-... #go #golang #gomail
github.com
Release v0.7.3: Skippable UTF-8 support, improved Base64LineBreaker, binary size reducing, fixes and more · wneessen/go-mail
Welcome to go-mail v0.7.3! 🎉 This release brings some cool improvements, new features, and fixes to go-mail. We hope you enjoy it! Notable changes/improvements/features/fixes Deadline fix for conne...
000
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
A bit over two years after starting to work on it... Go is officially FIPS 140-3 certified 💥 csrc.nist.gov/projects/cry... I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box.
928962
Reposted by Winni Neessen
Randall Munroe @xkcd.com · 15/04/2026
Countdown Standard xkcd.com/3232/
Comic. One... two... THREE! [text in red] X Deprecated [line break] One... two... three... GO! [text in red] Deprecated [red curly bracket around top two lines] Too easy to mix up [line break] Three... two... one... GO! [text in green] [check mark] ISO Standard [caption] If I were in charge of ISO, the first thing I’d do would be to standardize the way people count out loud before doing something in sync.
995504886
Reposted by Winni Neessen
Go @golang.org · 07/04/2026
🥳 Go 1.26.2 and 1.25.9 are released! 🔐 Security: Includes 10 security fixes for the standard library and the toolchain. 📢 Announcement: groups.google.com/g/golang-announce… ⬇️ Download: go.dev/dl/#go1.26.2 #golang
$ go install golang.org/dl/go1.26.2@latest
$ go1.26.2 download
Downloaded   0.0% (       0 / 63701324 bytes) ...
Downloaded  50.0% (31850662 / 63701324 bytes) ...
Downloaded 100.0% (63701324 / 63701324 bytes)
Unpacking go1.26.2.linux-arm64.tar.gz ...
Success. You may now run 'go1.26.2'
$ go1.26.2 version
go version go1.26.2 linux/arm64
25813
Reposted by Winni Neessen
jub0bs @jub0bs.com · 07/04/2026
🎉 After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go. Let me know whether it patches things up between you and CORS! github.com/jub0bs/cors #golang #CORS
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
2205
Reposted by Winni Neessen
Josh Baker @tidwall.bsky.social · 09/03/2026
I've spent the past couple months hand crafting a new B-tree map implementation for Go. It's fast. Faster than Rust's BTreeMap. Faster than the fastest C++ (frozenca/btree). And about 2x faster than my current Go btree (tidwall/btree).
61066
Reposted by Winni Neessen
Go @golang.org · 06/03/2026
🎉 Go 1.26.1 and 1.25.8 are released! 🔏 Security: Includes security fixes for the standard library (CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-27142). 📢 Announcement: groups.google.com/g/golang-ann... 📦 Download: go.dev/dl/#go1.26.1 #golang
$ go install golang.org/dl/go1.26.1@latest
$ go1.26.1 download
Downloaded   0.0% (       0 / 64661384 bytes) ...
Downloaded  50.0% (32330692 / 64661384 bytes) ...
Downloaded 100.0% (64661384 / 64661384 bytes)
Unpacking go1.26.1.linux-riscv64.tar.gz ...
Success. You may now run 'go1.26.1'
$ go1.26.1 version
go version go1.26.1 linux/riscv64
14913
Reposted by Winni Neessen
Russ Cox @swtch.com · 19/01/2026
“Floating-Point Printing and Parsing Can Be Simple And Fast” The fastest known floating-point printer and parsing algorithms - fixed-width printing, shortest-width printing, and parsing, all in 400 lines of Go. research.swtch.com/fp research.swtch.com/fp-proof
research.swtch.com
research!rsc: Floating-Point Printing and Parsing Can Be Simple And Fast (Floating Point Formatting, Part 3)
17816
Reposted by Winni Neessen
Anton Zhiyanov @antonz.org · 02/12/2025
Accepted! Go 1.26 will introduce errors.AsType — a modern, type-safe alternative to the clunky errors.As. No reflection. No runtime panics. Concise code. This is big! antonz.org/accepted/err...
antonz.org
Go proposal: Type-safe error checking
errors.AsType is a modern alternative to errors.As.
2164
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 24/12/2025
Really big age release coming tomorrow! 🎅🏻 - native post-quantum keys - built-in recipients for hw plugins - age-inspect tool - plugin framework - batchpass plugin - many improved error messages
age-encryption.org
GitHub - FiloSottile/age: A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. - FiloSottile/age
011723
Reposted by Winni Neessen
Go @golang.org · 02/12/2025
🥳 Go 1.25.5 and 1.24.11 are released! 🔐 Security: Includes security fixes for crypto/x509 (CVE-2025-61729, CVE-2025-61727). 🗣 Announcement: groups.google.com/g/golang-announce… 📦 Download: go.dev/dl/#go1.25.5 #golang
$ go install golang.org/dl/go1.25.5@latest
$ go1.25.5 download
Downloaded   0.0% (       0 / 57815527 bytes) ...
Downloaded  50.0% (28907763 / 57815527 bytes) ...
Downloaded 100.0% (57815527 / 57815527 bytes)
Unpacking go1.25.5.openbsd-riscv64.tar.gz ...
Success. You may now run 'go1.25.5'
$ go1.25.5 version
go version go1.25.5 openbsd/riscv64
03613
Reposted by Winni Neessen
jub0bs @jub0bs.com · 21/11/2025
Your weekly reminder to migrate from rs/cors to jub0bs/cors. 😇 github.com/rs/cors/issu...
github.com
With some CORS configurations, some handlers can introduce synchronisation bugs and cause data races · Issue #198 · rs/cors
Problem Presumably for performance, the library (v1.11.1 and some older versions) reuses some non-exported slice variables and struct field from one middleware call to the next: package-level var h...
052
Winni Neessen @neessen.dev · 19/11/2025
waybar-weather v0.2.4 is out. Some exciting new features were added: GPSd for geolocation lookup, an alternate text template to show current or forecasted weather by clicking the widget and i18n support for all displayable elements. Check it out! github.com/wneessen/way... #linux #waybar #golang
waybar-weather in englishwaybar-weather in german
000
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 19/11/2025
So tempted to write a troll thread on how this incident shows Rust has bad error handling and wouldn’t have happened in Go, where we actually handle errors 🫣🫢😜 blog.cloudflare.com/18-november-...
blog.cloudflare.com
Cloudflare outage on November 18, 2025
Cloudflare suffered a service outage on November 18, 2025. The outage was triggered by a bug in generation logic for a Bot Management feature file causing many Cloudflare services to be affected.
1513221
Winni Neessen @neessen.dev · 10/11/2025
waybar-weather v0.2.0 is out and removes the depencency on Geoclue by implenting its own geolocation sub/pub bus. It also is now fully customizable via templates, allowing the user to make it look like they want. Feedback is, as always, welcome! github.com/wneessen/way... #linux #waybar #weather
github.com
Release v0.2.0: Better geolocation lookup · wneessen/waybar-weather
Welcome to waybar-weather v0.2.0 🎉 This release brings some major refactors and fixes that improve how waybar weather works. Geoclue removal So far waybar-weather used Geoclue as 3rd party dependen...
010
Winni Neessen @neessen.dev · 07/11/2025
I've published my #waybar weather module on Github. Feel free to give it a try: github.com/wneessen/way... #linux #go #waybar #weather
Screenshot of the waybar weather module
010
Reposted by Winni Neessen
Go @golang.org · 05/11/2025
🎊 Go 1.25.4 and 1.24.10 are released! 📡 Announcement: groups.google.com/g/golang-announce… 🗃 Download: go.dev/dl/#go1.25.4 #golang
$ go install golang.org/dl/go1.25.4@latest
$ go1.25.4 download
Downloaded   0.0% (       0 / 60491166 bytes) ...
Downloaded  50.0% (30245583 / 60491166 bytes) ...
Downloaded 100.0% (60491166 / 60491166 bytes)
Unpacking go1.25.4.darwin-amd64.tar.gz ...
Success. You may now run 'go1.25.4'
$ go1.25.4 version
go version go1.25.4 darwin/amd64
04614
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 23/10/2025
Serious take: the solution to Safe Browsing false positives like the Immich one is passkeys. Phishing regularly upends people's lives. The Safe Browsing cat-and-mouse with all its opaque false positives will be necessary until we roll out phishing-resistant auth.
1556
Winni Neessen @neessen.dev · 21/10/2025
I consider this PR a win. #go #golang #syslog #syslog #rfc5324 #rfc3164
Screenshot showing benchmark differences
000
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 16/10/2025
It's been 14 months since the ML-KEM spec was published. age still isn't PQ because it's waiting for trivial details of the HPKE hybrids to stabilize, but they are blocked on the CFRG. The TLS, SSHM, and LAMPS (X.509) IETF WGs are not waiting for CFRG. I just posted a plea for HPKE to do the same.
mailarchive.ietf.org
[hpke] Let's ship post-quantum HPKE
Search IETF mail list archives
1519
Reposted by Winni Neessen
Go @golang.org · 13/10/2025
🥳 Go 1.25.3 and 1.24.9 are released! 📣 Announcement: groups.google.com/g/golang-announce… ⬇️ Download: go.dev/dl/#go1.25.3 #golang
$ go install golang.org/dl/go1.25.3@latest
$ go1.25.3 download
Downloaded   0.0% (       0 / 56475454 bytes) ...
Downloaded  50.0% (28237727 / 56475454 bytes) ...
Downloaded 100.0% (56475454 / 56475454 bytes)
Unpacking go1.25.3.linux-mipsle.tar.gz ...
Success. You may now run 'go1.25.3'
$ go1.25.3 version
go version go1.25.3 linux/mipsle
04511
Reposted by Winni Neessen
Go @golang.org · 07/10/2025
🥳 Go 1.25.2 and 1.24.8 are released! 📢 Announcement: groups.google.com/g/golang-announce… 📦 Download: go.dev/dl/#go1.25.2 #golang
$ go install golang.org/dl/go1.25.2@latest
$ go1.25.2 download
Downloaded   0.0% (       0 / 58280426 bytes) ...
Downloaded  50.0% (29140213 / 58280426 bytes) ...
Downloaded 100.0% (58280426 / 58280426 bytes)
Unpacking go1.25.2.linux-riscv64.tar.gz ...
Success. You may now run 'go1.25.2'
$ go1.25.2 version
go version go1.25.2 linux/riscv64
04819
Reposted by Winni Neessen
Signal @signal.org · 03/10/2025
We are alarmed by reports that Germany is on the verge of a catastrophic about-face, reversing its longstanding and principled opposition to the EU’s Chat Control proposal which, if passed, could spell the end of the right to privacy in Europe. signal.org/blog/pdfs/ge...
signal.org
4039242365
Reposted by Winni Neessen
go-mail @go-mail.dev · 27/09/2025
go-mail v0.7.1 has just been released! This is a security release fixing a vulnerability in the mail address handling. You can find the release notes here: github.com/wneessen/go-... The corresponding security advisory can be found here: github.com/wneessen/go-... We encouraged to update!
github.com
Release v0.7.1: Vulnerability fix in mail address handling · wneessen/go-mail
ImportantThis release fixes a vulnerability. All users are encouraged to update to this release at their earliest convenience. Welcome to go-mail v0.7.1! This is a security release, which addresse...
021
Reposted by Winni Neessen
jub0bs @jub0bs.com · 21/08/2025
We may still get a generified version of errors.As in #golang's standard library! 🤞 github.com/golang/go/is...
github.com
proposal: errors: As with type parameters · Issue #51945 · golang/go
Currently in 1.18 and before, when using the errors.As method, an error type you would like to write into must be predeclared before calling the function. For example: var myErr *MyCustomError if e...
0163
Reposted by Winni Neessen
Felix Geisendörfer @felixge.de · 28/07/2025
Check out this new blog post outlining how profiling is becoming the fourth pillar of observability 🚀. www.datadoghq.com/blog/continu...
datadoghq.com
Why continuous profiling is the fourth pillar of observability | Datadog
Learn how modern continuous profilers have transformed profiling into a core observability practice.
0126
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 15/07/2025
We announced the new native Go FIPS 140-3 mode today! FIPS 140, like it or not, is often a requirement, and I was increasingly sad about large deployments replacing the Go crypto packages with non-memory safe cgo bindings. Go is now one of the easiest and most secure ways to build under FIPS 140.
go.dev
The FIPS 140-3 Go Cryptographic Module
Go now has a built-in, native FIPS 140-3 compliant mode.
1119949
Reposted by Winni Neessen
jub0bs @jub0bs.com · 14/06/2025
🎉 I've just released v0.7.0 of jub0bs/cors, my #CORS middleware library for #golang! 💀 Now that Private-Network Access (PNA) has been put on indefinite hold in favor of a new permission-based mechanism named "Local-Network Access", I've removed all support for PNA. github.com/jub0bs/cors
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
062
Reposted by Winni Neessen
Go @golang.org · 11/06/2025
🎉 Go 1.25 Release Candidate 1 is released! 🏃‍♀️ Run it in dev! Run it in prod! File bugs! go.dev/issue/new 📢 Announcement: groups.google.com/g/golang-ann... 📦 Download: go.dev/dl/#go1.25rc1
Go 1.25RC1
38528
Reposted by Winni Neessen
go-mail @go-mail.dev · 10/06/2025
HOLY SHIT! We've reached 1k stars on Github last night. That's insane. Thanks to all the stargazers. #go #golang #gomail
Screenshot of github showing 1k stars
021
Reposted by Winni Neessen
Daniel Martí @mvdan.cc · 09/06/2025
At least for #golang, avoid using deps.dev for now. It seems to be reporting security advisories based on outdated information, and the project seems unmaintained, as I reported this two weeks ago but got nothing at all.
github.com
Go dependency versions are wrong or outdated for a tagged module version · Issue #251 · google/deps.dev
https://deps.dev/go/cuelang.org%2Fgo/v0.13.0 shows that cuelang.org/go@v0.13.0 is vulnerable to https://deps.dev/advisory/osv/GO-2025-3488. This is because it thinks we depend on golang.org/x/oauth...
0207
Reposted by Winni Neessen
jub0bs @jub0bs.com · 03/06/2025
🫡 "For the foreseeable future, the Go team will stop pursuing syntactic language changes for error handling. We will also close all open and incoming proposals that concern themselves primarily with the syntax of error handling, without further investigation." go.dev/blog/error-s... #golang
go.dev
[ On | No ] syntactic support for error handling - The Go Programming Language
Go team plans around error handling support
3111
Reposted by Winni Neessen
Markus 🤓✨ @markus.maragu.dev · 20/05/2025
It's so awesome to build on a stack like this, where security is taken seriously from the ground up! #GoLang
021
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 19/05/2025
Three Trail of Bits engineers audited core Go cryptography for a month and found only one low-sev security issue... in unsupported Go+BoringCrypto! 🍾 Years of efforts on testing, limiting complexity, safe APIs, and readability have paid off! ✨ Yes I am taking a victory lap. No I am not sorry. 🏆
go.dev
Go Cryptography Security Audit
Go's cryptography libraries underwent an audit by Trail of Bits. Read more about the scope and results.
1457083
Winni Neessen @neessen.dev · 12/05/2025
While listening to Green Day's "American Idiot" album again, I just realized how much at the pulse of time the song "Holiday" is. Even though it was meant for/against the Bush Jr. regime, it fits pretty well into "Trump America" as well. The complete album is a masterpiece in my opinion.
000
Reposted by Winni Neessen
jub0bs @jub0bs.com · 30/04/2025
New blog post! 🤓 jub0bs.com/posts/2025-0... #golang #optimization
jub0bs.com
Challenge: make this Go function inlinable and free of bounds checks
In this post, I challenge you to refactor a small function in such a way as to make it inlinable and free of bounds checks, for better performance. Disclaimer: this post assumes version 1.24.2 of the ...
284
Reposted by Winni Neessen
Mat Ryer @matryer.bsky.social · 12/04/2025
I don’t do competitive analysis. I don’t want to be influenced by what others are doing. I’ll hear about the amazing stuff naturally, but I’d rather we do things our way. The only way to be truly innovative is to forge your own path.
042
Reposted by Winni Neessen
Filippo Valsorda @filippo.abyssdomain.expert · 13/03/2025
TypeScript team: rewrites compiler in Go. Go community: what do you mean your new compiler takes more than a minute to compile? Unacceptable. Dishonorable even. We are so sorry for this sub par experience. Not how we do things around here. Two days later: WIP 5x speedup. HN: why pick Go anyway?
github.com
cmd/compile: slow escape analysis in large package in the typescript compiler · Issue #72815 · golang/go
Go version go version go1.24.1 linux/amd64 Output of go env in your module/workspace: AR='ar' CC='gcc' CGO_CFLAGS='-O2 -g' CGO_CPPFLAGS='' CGO_CXXFLAGS='-O2 -g' CGO_ENABLED='1' CGO_FFLAGS='-O2 -g' ...
14666125
Reposted by Winni Neessen
jub0bs @jub0bs.com · 13/03/2025
Microsoft's announcement that the #TypeScript compiler is being ported to #golang is a good opportunity for me to once again promote my introductory Go course. 😇 I regularly update the course material, which is freely available on GitHub. 🍺 github.com/jub0bs/go-co...
github.com
GitHub - jub0bs/go-course-beginner: a practical introduction to Go
a practical introduction to Go. Contribute to jub0bs/go-course-beginner development by creating an account on GitHub.
1156
Reposted by Winni Neessen
Markus 🤓✨ @markus.maragu.dev · 05/03/2025
#gomponents v1.1.0 is out today, with many small additions and fixes, thanks to all the awesome contributors! 😊 github.com/maragudk/gom...
github.com
Release v1.1.0 - Many small additions and improvements · maragudk/gomponents
Thanks to all the new contributors, you're awesome! 😎 What's Changed Add web component elements and slot attribute by @knpwrs in #235 Add popover attributes by @knpwrs in #236 Upgrade codecov Gith...
011
Reposted by Winni Neessen
go-mail @go-mail.dev · 16/02/2025
Hear ye! Hear ye! go-mail v0.6.2 has just been released. This is mainly a bug fix release, addressing some issue that were reported of the last weeks. Thanks to all reporters and contributors. The full release notes can be found here: github.com/wneessen/go-... #go #golang #gomail
github.com
Release v0.6.2: Bugfix release · wneessen/go-mail
Welcome to go-mail v0.6.2! This release fixes some bugs and makes go-mail ready for Go 1.24. Fix regression of custom SMTP authentication handling PR #429 fixes a regression in the handling of cust...
011
Reposted by Winni Neessen
Go @golang.org · 11/02/2025
🥳 Go 1.24.0 is released! 📰 Release notes: go.dev/doc/go1.24 📦 Download: go.dev/dl/#go1.24.0 #golang
$ go install golang.org/dl/go1.24.0@latest
$ go1.24.0 download
Downloaded   0.0% (       0 / 74636413 bytes) ...
Downloaded  50.0% (37318206 / 74636413 bytes) ...
Downloaded 100.0% (74636413 / 74636413 bytes)
Unpacking go1.24.0.linux-arm64.tar.gz ...
Success. You may now run 'go1.24.0'
$ go1.24.0 version
go version go1.24.0 linux/arm64
327994
Reposted by Winni Neessen
Go @golang.org · 05/02/2025
🎉 Go 1.24 Release Candidate 3 is released! 🔐 Security: Includes security fixes for the go tool and the crypto/elliptic package. 🏖 Run it in dev! Run it in prod! File bugs! go.dev/issue/new 🗣 Announcement: groups.google.com/g/golang-ann... 🚚 Download: go.dev/dl/#go1.24rc3
17816
Reposted by Winni Neessen
Daniel Martí @mvdan.cc · 31/01/2025
The #golang encoding/json/v2 proposal is live! Huge props to Joe Tsai for the hundreds of hours he poured into this project. github.com/golang/go/is...
github.com
proposal: encoding/json/v2: new API for encoding/json · Issue #71497 · golang/go
Proposal Details This is a formal proposal for the addition of "encoding/json/v2" and "encoding/json/jsontext" packages that has previously been discussed in #63397. This focuses on just the newly ...
17815
Reposted by Winni Neessen
Daniel Martí @mvdan.cc · 26/01/2025
Just tagged a new release for garble, a #golang obfuscator - focusing on improved compatibility with reflect, as well as using Go 1.23's type alias tracking!
github.com
Release v0.14.0 · burrowers/garble
This release drops support for Go 1.22 and continues support for Go 1.23. @lu4p improved the compatibility with reflection of Go types by collecting the set of all types used with reflection during...
0132
Reposted by Winni Neessen
Go @golang.org · 16/01/2025
🥳 Go 1.23.5 and 1.22.11 are released! 🔏 Security: Includes security fixes for CVE-2024-45336 and CVE-2024-45341 in crypto/x509 and net/http 🔈 Announcement: groups.google.com/g/golang-ann... ⬇️ Download: go.dev/dl/#go1.23.5
$ go install golang.org/dl/go1.23.5@latest
$ go1.23.5 download
Downloaded 0.0% ( 0 / 70443026 bytes) ...
Downloaded 50.0% (35221513 / 70443026 bytes) ...
Downloaded 100.0% (70443026 / 70443026 bytes)
Unpacking go1.23.5.linux-ppc64le.tar.gz ...
Success. You may now run 'go1.23.5'
$ go1.23.5 version
go version go1.23.5 linux/ppc64le
07615