go/src
Tom Thorogood 2e65ef623b [release-branch.go1.13] encoding/json: revert Compact HTML escaping documentation
This partly reverts CL 173417 as it incorrectly documented that Compact
performed HTML escaping and the output was safe to embed inside HTML
<script> tags. This has never been true.

Although Compact does escape U+2028 and U+2029, it doesn't escape <, >
or &. Compact is thus only performing a subset of HTML escaping and it's
output is not safe to embed inside HTML <script> tags.

A more complete fix would be for Compact to either never perform any
HTML escaping, as it was prior to CL 10883045, or to actually perform
the same HTML escaping as HTMLEscape. Neither change is likely safe
enough for go1.13.

Fixes #34006
Updates #30357

Change-Id: I912f0fe9611097d988048b28228c4a5b985080ba
GitHub-Last-Rev: aebababc92
GitHub-Pull-Request: golang/go#33427
Reviewed-on: https://go-review.googlesource.com/c/go/+/188717
Reviewed-by: Daniel Martí <mvdan@mvdan.cc>
Run-TryBot: Daniel Martí <mvdan@mvdan.cc>
TryBot-Result: Gobot Gobot <gobot@golang.org>
(cherry picked from commit 79669dc705)
Reviewed-on: https://go-review.googlesource.com/c/go/+/192747
Reviewed-by: Andrew Bonventre <andybons@golang.org>
Run-TryBot: Andrew Bonventre <andybons@golang.org>
2019-09-02 21:39:04 +00:00
..
archive all: shorten some tests 2019-05-22 12:54:00 +00:00
bufio bufio: fix ExampleScanner_Bytes comment, add error check 2019-06-25 00:29:24 +00:00
builtin
bytes bytes: remove obsolete comment 2019-05-28 02:52:39 +00:00
cmd [release-branch.go1.13] cmd/go/internal/modload: fix swapped paths in error message 2019-08-27 21:14:34 +00:00
compress compress/gzip: add missing error check in test 2019-05-24 14:55:39 +00:00
container all: shorten some tests 2019-05-22 12:54:00 +00:00
context all: remove os.ErrTimeout 2019-08-02 17:57:18 +00:00
crypto [release-branch.go1.13] crypto/tls: make SSLv3 again disabled by default 2019-08-27 20:56:38 +00:00
database/sql database/sql: add support for decimal interface 2019-06-13 16:59:01 +00:00
debug debug/elf: add version information to all dynamic symbols 2019-07-05 18:18:26 +00:00
encoding [release-branch.go1.13] encoding/json: revert Compact HTML escaping documentation 2019-09-02 21:39:04 +00:00
errors errors: improve doc 2019-08-06 11:13:05 +00:00
expvar all: change some function documentation to be more idiomatic 2019-07-28 18:09:57 +00:00
flag
fmt [release-branch.go1.13] doc/go1.13: document fmt's number syntax updates 2019-08-25 16:54:13 +00:00
go Revert "go/ast: fix SortImports to handle block comments" 2019-08-08 19:18:56 +00:00
hash
html html/template, text/template: document glob semantics 2019-06-17 21:53:49 +00:00
image image/draw: change argument type to be consistent with other args 2019-05-24 15:22:14 +00:00
index/suffixarray index/suffixarray: index 3-10X faster in half the memory 2019-05-13 18:50:32 +00:00
internal all: remove os.ErrTimeout 2019-08-02 17:57:18 +00:00
io
log
math cmd/gofmt: fix normalization of imaginary number literals 2019-06-21 17:24:29 +00:00
mime mime: encode CTL and non-US-ASCII characters in FormatMediaType 2019-05-23 15:45:00 +00:00
net [release-branch.go1.13] net/http: fix wantConnQueue memory leaks in Transport 2019-08-27 18:37:25 +00:00
os os: change Readdirnames doc to follow that of Readdir 2019-08-02 21:52:01 +00:00
path path: fix mismatch between error message and corresponding test function 2019-08-08 00:38:10 +00:00
plugin
reflect reflect: align first argument in callMethod 2019-08-14 19:49:15 +00:00
regexp regexp/syntax: exclude full range from String negation case 2019-05-22 04:43:25 +00:00
runtime runtime/pprof: Mention goroutine label heritability 2019-08-07 14:40:17 +00:00
sort
strconv [release-branch.go1.13] strconv: update documentation 2019-08-22 17:40:31 +00:00
strings strings: clarify usage of Title and ToTitle 2019-07-30 02:52:57 +00:00
sync sync: document implementation of Once.Do 2019-07-01 14:45:49 +00:00
syscall syscall: include complete prototype of system calls 2019-08-05 19:01:06 +00:00
testdata
testing Revert "cmd/go: move automatic testing.Init call into generated test code" 2019-07-22 21:42:51 +00:00
text text/scanner: remove AllowDigitSeparator flag again 2019-06-27 21:13:53 +00:00
time time: update TestSub to avoid future regressions 2019-08-16 19:54:57 +00:00
unicode
unsafe
vendor [release-branch.go1.13] net/http: update bundled golang.org/x/net/http2 to import security fix 2019-08-23 17:16:16 +00:00
Make.dist
README.vendor all: document vendoring in the standard library 2019-05-09 17:11:16 +00:00
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash cmd/go: run full 'go vet' during 'go test' for packages in GOROOT 2019-05-16 03:24:56 +00:00
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod [release-branch.go1.13] net/http: update bundled golang.org/x/net/http2 to import security fix 2019-08-23 17:16:16 +00:00
go.sum [release-branch.go1.13] net/http: update bundled golang.org/x/net/http2 to import security fix 2019-08-23 17:16:16 +00:00
iostest.bash
make.bash
make.bat
make.rc
naclmake.bash
nacltest.bash
race.bash
race.bat
run.bash
run.bat
run.rc

README.vendor

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -m golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not just
the target module.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.