Go HTTP/2 fixes, PEP 823, LLVM RFCs
Go shipped multiple HTTP/2 security fixes while Python debated None-aware operators and LLVM argued over AI text and ClangIR defaults. Build and review friction also surfaced in the LLVM GitHub workflow.
Go x/net v0.60.0 fixes HTTP/2 trailer memory exhaustion
The Go team released golang.org/x/net v0.60.0, addressing CVE-2026-78659, a memory-exhaustion flaw triggered by HTTP/2 trailers. The same advisory went to both golang-nuts and golang-dev. Projects that pull in x/net for HTTP handling should upgrade to limit resource exhaustion under crafted traffic.
PEP 823 proposes None-aware access operators
PEP 823 would add None-aware ?. and ?[] operators to Python. A long discuss.python.org thread, with Guido van Rossum participating, debated design details and how None should propagate. If accepted, the change would reshape everyday null-handling patterns in the language.
LLVM reports project-wide GitHub PR merge failures
LLVM engineers describe persistent failures merging pull requests through the GitHub UI, tied to 10s timeouts. Contributors are circulating REST and script workarounds while GitHub investigates. The problem disrupts routine integration across the project.
Go closes HTTP/2 SETTINGS_INITIAL_WINDOW_SIZE CPU path
The Go repository landed a fix for CVE-2026-78669, tracked as change 81742. HTTP/2 peers could previously force O(n) CPU use by repeating SETTINGS_INITIAL_WINDOW_SIZE frames. Services that terminate HTTP/2 benefit from taking the patch to reduce denial-of-service exposure.
LLVM RFC seeks ban on AI-generated communication
An LLVM RFC proposes forbidding AI-generated pull request descriptions and RFC text. The discussion argues that low-quality automated submissions consume reviewer time. The thread is lengthy and heated as the community weighs quality controls against contribution volume.
RFC to enable ClangIR build by default
A separate LLVM RFC proposes turning the ClangIR build on by default, which would introduce an MLIR dependency and about 20 percent extra build time. Advocates point to optimization gains from the representation. A large technical thread is weighing default-on cost against keeping the feature optional.
Go 1.27.2 and 1.26.9 deliver fifteen security fixes
Go 1.27.2 and Go 1.26.9 are out with fifteen security fixes. One highlighted issue is an HTTP/2 server crash from unsynchronized HPACK encoder access. Operators on supported release lines should move to the new point releases.