gup v1.10.2 Releases Go Toolchain Safeguards


On September 26 2026 nao1215 published gup v1.10.2 to fix Go toolchain version handling bugs when updating compiled Go binaries. This release bounds go env inspection calls within the install timeout context and prevents gup from rebuilding binaries with a Go compiler version older than their original build floor.

The full release notes and downloads are on the GitHub release page.

The gup utility automates the parallel updating of binaries installed through go install across $GOPATH/bin or $GOBIN. To determine environment settings module configurations and compiler details gup invokes go env as a subshell command during the initial discovery phase. When managing large sets of binaries gup distributes tasks across concurrent worker routines. In prior releases an unresponsive Go environment or a stalled subprocess call could cause a gup worker routine to block indefinitely while waiting for output.

Commit 44595f1338168dfd0d22b31d5574acd23e6cf361 fixes this issue by bounding the go env toolchain read within the configured installation timeout context. When gup queries the Go environment it wraps the subprocess invocation with a timeout signal. If go env does not complete before the installation deadline expires gup cancels the subshell context terminates the process and surfaces an execution error. This prevents background update scripts and interactive operations from stalling worker pools when the local Go toolchain is misconfigured or unreadable.

Every binary compiled with modern Go includes embedded build info metadata that records the Go toolchain version used during compilation. When gup evaluates installed tools for updates it checks this metadata against the active host environment. In previous versions if go env failed or produced unparseable results gup fell back to default installation logic and dropped the detected Go runtime floor.

Commit 1623e657a94d90e5bddb29ac03672e69f6263759 changes this fallback behavior. When gup cannot read go env it now fails the update process immediately instead of dropping the Go version floor.

Commit 01f304aed6620b630318bc11748253bc995f4687 adds an explicit validation check to prevent version regressions during rebuilds. Under the updated logic gup will never rebuild a binary using a Go compiler version older than the version recorded in the original binary metadata. Rebuilding binaries with older Go compilers can expose systems to resolved standard library security vulnerabilities or cause build failures when source dependencies require modern language features. Halting the build when the host Go version is lower than the original compiler floor ensures consistent runtime behavior across system upgrades.

Documentation commit 18ff9376831e1c58f582de314fa3778aced46744 scopes the reported Go version fix in the changelog specifically to channel updates. Commit f81841dad21e06cf2e0f8ef2c79e8e76bd07a4c6 merged the toolchain downgrade protections from branch fix/no-go-toolchain-downgrade into main.

As with all official releases of gup every published binary artifact for v1.10.2 is signed and includes a Software Bill of Materials alongside build provenance attestations. Operators can verify release integrity using the public signatures provided on the project repository.