What changed, and why it matters
This commit is a routine post-release housekeeping change. It bumps the software version from 0.14.0 to 0.15.0-SNAPSHOT across build files, creates a placeholder for future release notes, re-enables a Maven trusted-checksum feature used for build verification, and adds an explicit safety guard that refuses to start the node unless a special override flag is set. There is no vulnerability fix or security flaw introduced in the diff itself.
No security action required. This is a normal development-version transition commit. Operators should not run 0.15.0-SNAPSHOT in production unless explicitly instructed by the project.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit transitions the repository from release mode to development mode after v0.14.0. Changes include: (1) version bumps in pom.xml files to 0.15.0-SNAPSHOT; (2) creation of docs/release-notes/eclair-vnext.md as a template; (3) enabling aether.artifactResolver.postProcessor.trustedChecksums in .mvn/maven.config, which enforces trusted SHA-256 checksums during artifact resolution; and (4) adding a startup guard in Boot.scala that throws a RuntimeException unless -Declair.allow-unsafe-startup=true is provided. The guard is a deliberate safety measure to prevent accidental use of an in-development snapshot, not a security bug.
Changed components
Build configuration (pom.xml files)Maven trusted checksum configuration (.mvn/maven.config)Release notes template (docs/release-notes/eclair-vnext.md)Node startup logic (eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala)Inspect captured patch +74 / −6
diff --git a/.mvn/maven.config b/.mvn/maven.config
index e92391e..acf5164 100644
--- a/.mvn/maven.config
+++ b/.mvn/maven.config
@@ -2,7 +2,7 @@
-Daether.trustedChecksumsSource.summaryFile=true
-Daether.trustedChecksumsSource.summaryFile.basedir=${session.rootDirectory}/.mvn/checksums/
# post processor: trusted checksums
--Daether.artifactResolver.postProcessor.trustedChecksums=false
+-Daether.artifactResolver.postProcessor.trustedChecksums=true
-Daether.artifactResolver.postProcessor.trustedChecksums.checksumAlgorithms=SHA-256
-Daether.artifactResolver.postProcessor.trustedChecksums.failIfMissing=true
-Daether.artifactResolver.postProcessor.trustedChecksums.snapshots=false
diff --git a/docs/release-notes/eclair-vnext.md b/docs/release-notes/eclair-vnext.md
new file mode 100644
index 0000000..a5a9998
--- /dev/null
+++ b/docs/release-notes/eclair-vnext.md
@@ -0,0 +1,64 @@
+# Eclair vnext
+
+<insert here a high-level description of the release>
+
+## Major changes
+
+<insert changes>
+
+### Configuration changes
+
+<insert changes>
+
+### API changes
+
+<insert changes>
+
+### Miscellaneous improvements and bug fixes
+
+<insert changes>
+
+## Verifying signatures
+
+You will need `gpg` and our release signing key E04E48E72C205463. Note that you can get it:
+
+- from our website: https://acinq.co/pgp/drouinf2.asc
+- from github user @sstone, a committer on eclair: https://api.github.com/users/sstone/gpg_keys
+
+To import our signing key:
+
+```sh
+$ gpg --import drouinf2.asc
+```
+
+To verify the release file checksums and signatures:
+
+```sh
+$ gpg -d SHA256SUMS.asc > SHA256SUMS.stripped
+$ sha256sum -c SHA256SUMS.stripped
+```
+
+## Building
+
+Eclair builds are deterministic. To reproduce our builds, please use the following environment (*):
+
+- Ubuntu 24.04.1
+- Adoptium OpenJDK 21.0.6
+
+Then use the following command to generate the eclair-node packages:
+
+```sh
+./mvnw clean install -DskipTests
+```
+
+That should generate `eclair-node/target/eclair-node-<version>-XXXXXXX-bin.zip` with sha256 checksums that match the one we provide and sign in `SHA256SUMS.asc`
+
+(*) You may be able to build the exact same artefacts with other operating systems or versions of JDK 21, we have not tried everything.
+
+## Upgrading
+
+This release is fully compatible with previous eclair versions. You don't need to close your channels, just stop eclair, upgrade and restart.
+
+## Changelog
+
+<fill this section when publishing the release with `git log v0.14.0... --format=oneline --reverse`>
diff --git a/eclair-core/pom.xml b/eclair-core/pom.xml
index d4e1be1..849d6cb 100644
--- a/eclair-core/pom.xml
+++ b/eclair-core/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.0</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-core_2.13</artifactId>
diff --git a/eclair-front/pom.xml b/eclair-front/pom.xml
index 68f6860..57dc724 100644
--- a/eclair-front/pom.xml
+++ b/eclair-front/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.0</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-front_2.13</artifactId>
diff --git a/eclair-fuzz/pom.xml b/eclair-fuzz/pom.xml
index 7b9eb20..42042f9 100644
--- a/eclair-fuzz/pom.xml
+++ b/eclair-fuzz/pom.xml
@@ -5,7 +5,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.0</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-fuzz_2.13</artifactId>
diff --git a/eclair-node/pom.xml b/eclair-node/pom.xml
index 16a44c3..2d16440 100644
--- a/eclair-node/pom.xml
+++ b/eclair-node/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.0</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-node_2.13</artifactId>
diff --git a/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala b/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
index 7e29046..1d6c4ec 100644
--- a/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
+++ b/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
@@ -33,6 +33,10 @@ import scala.util.{Failure, Success}
*/
object Boot extends App with Logging {
try {
+ if (!System.getProperty("eclair.allow-unsafe-startup", "false").toBooleanOption.contains(true)) {
+ throw new RuntimeException("This version of eclair is unsafe to use: please wait for the next official release to update your node.")
+ }
+
val datadir = new File(System.getProperty("eclair.datadir", System.getProperty("user.home") + "/.eclair"))
val config = NodeParams.loadConfiguration(datadir)
diff --git a/pom.xml b/pom.xml
index 87e80f3..83224d9 100644
--- a/pom.xml
+++ b/pom.xml
@@ -20,7 +20,7 @@
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.0</version>
+ <version>0.15.0-SNAPSHOT</version>
<packaging>pom</packaging>
<modules>
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.