[HN Gopher] Go 1.21.6 Released
       ___________________________________________________________________
        
       Go 1.21.6 Released
        
       Author : is_taken
       Score  : 13 points
       Date   : 2024-01-09 19:24 UTC (3 hours ago)
        
 (HTM) web link (go.dev)
 (TXT) w3m dump (go.dev)
        
       | kramerger wrote:
       | This is dot-dot release with just a few minor fixes. Not sure why
       | it's on the front page, but since I have your attention... here
       | something I noticed just the other day:
       | 
       | > the go command by default downloads and authenticates modules
       | using the Go module mirror
       | 
       | Maybe I'm reading this incorrectly but it sounds as google will
       | be able to see every dependency for every project I ever work on.
       | 
       | This is the second time Go adds something that can be used to spy
       | on developers. Obviously they pinky promise to not abuse it, by
       | why does this eventually happens to every Google product?
        
         | dharmab wrote:
         | The Python foundation can see all the dependencies you download
         | from PyPI, and NPM can see all the dependencies you download
         | from NPM/Yarn. This isn't unusual for a package manager.
         | 
         | If you prefer, you can run your own proxy and configure the Go
         | command to use it instead.
         | 
         | Private modules don't use the mirror.
        
           | kramerger wrote:
           | Unlike the ones you mentioned, Go doesn't have a central
           | repository. The go.mod contains references to git
           | repositories or local folders:
           | 
           | https://go.dev/doc/modules/gomod-ref
           | 
           | Not sure why a proxy is needed.
        
             | dharmab wrote:
             | It's needed to provide checksums for each module. It also
             | significantly improves performance and prevents a left-pad
             | situation.
             | 
             | https://go.dev/blog/module-mirror-launch
        
               | kramerger wrote:
               | These are GIT repositories, they have their own
               | cryptographically unique identifiers. No need to send
               | your data to a third-party to get it confirmed.
               | 
               | Maybe I'm missing something, but this whole operation
               | feels like a huge infrastructure paid by Google for
               | something that is not needed.
        
       | vlod wrote:
       | If you're too lazy..
       | 
       | From: [0]
       | 
       | "go1.21.6 (released 2024-01-09) includes fixes to the compiler,
       | the runtime, and the crypto/tls, maps, and runtime/pprof
       | packages. See the Go 1.21.6 milestone on our issue tracker for
       | details."
       | 
       | https://go.dev/doc/devel/release#go1.21.minor
        
       | cryptos wrote:
       | From the Guidelines:
       | 
       | > What to submit? [...] anything that gratifies one's
       | intellectual curiosity.
       | 
       | https://news.ycombinator.com/newsguidelines.html
       | 
       | Maybe it's just me, but I don't feel very inspired on an
       | intellectual level by news about a patch version ;-)
        
       ___________________________________________________________________
       (page generated 2024-01-09 23:02 UTC)