What changed, and why it matters
This commit is a routine post-release housekeeping change. It bumps the project version from 0.14.2 to 0.15.0-SNAPSHOT, re-enables a Maven trusted-checksum feature used for build verification, adds a placeholder release-notes file, and deliberately prevents the new development snapshot from starting in production by throwing an error unless a special override flag is set. There is no security vulnerability here; the change is a safety guard, not a flaw.
No security action required. This is a normal development-version transition. Operators should not run 0.15.0-SNAPSHOT in production unless explicitly instructed, as the built-in startup guard indicates.
Security signals we found
No security-relevant code changes indicating a vulnerability
Boot.scala startup guard prevents accidental deployment of an unsafe development snapshot
Maven trusted checksum verification is re-enabled, improving supply-chain/build integrity
No references to CVEs, advisories, or security incidents in commit or diff
Evidence from the diff
The commit transitions the repository back to development mode after the v0.14.2 release. Key changes: (1) version bumped to 0.15.0-SNAPSHOT across all Maven modules; (2) .mvn/maven.config re-enables aether.artifactResolver.postProcessor.trustedChecksums (true) with SHA-256 and failIfMissing=true, which enforces trusted checksums during artifact resolution; (3) a new docs/release-notes/eclair-vnext.md template is added; (4) Boot.scala now refuses to start unless the system property eclair.allow-unsafe-startup is set to true, explicitly warning that this development version is unsafe for production use. The checksum enforcement is a hardening measure, and the startup guard is a defensive safety mechanism.
Changed components
Maven build configuration (.mvn/maven.config, pom.xml, module pom.xml files)Release notes template (docs/release-notes/eclair-vnext.md)Node startup logic (eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala)Inspect captured patch +74 / −6
### .mvn/maven.config
@@ -2,7 +2,7 @@
-Daether.trustedChecksumsSource.summaryFile=true
-Daether.trustedChecksumsSource.summaryFile.basedir=${session.rootDirectory}/.mvn/checksums/
# post processor: trusted checksums
--Daether.artifactResolver.postProcessor.trustedChecksums=false
+-Daether.artifactResolver.postProcessor.trustedChecksums=true
-Daether.artifactResolver.postProcessor.trustedChecksums.checksumAlgorithms=SHA-256
-Daether.artifactResolver.postProcessor.trustedChecksums.failIfMissing=true
-Daether.artifactResolver.postProcessor.trustedChecksums.snapshots=false
### docs/release-notes/eclair-vnext.md
@@ -0,0 +1,64 @@
+# Eclair vnext
+
+<insert here a high-level description of the release>
+
+## Major changes
+
+<insert changes>
+
+### Configuration changes
+
+<insert changes>
+
+### API changes
+
+<insert changes>
+
+### Miscellaneous improvements and bug fixes
+
+<insert changes>
+
+## Verifying signatures
+
+You will need `gpg` and our release signing key E04E48E72C205463. Note that you can get it:
+
+- from our website: https://acinq.co/pgp/drouinf2.asc
+- from github user @sstone, a committer on eclair: https://api.github.com/users/sstone/gpg_keys
+
+To import our signing key:
+
+```sh
+$ gpg --import drouinf2.asc
+```
+
+To verify the release file checksums and signatures:
+
+```sh
+$ gpg -d SHA256SUMS.asc > SHA256SUMS.stripped
+$ sha256sum -c SHA256SUMS.stripped
+```
+
+## Building
+
+Eclair builds are deterministic. To reproduce our builds, please use the following environment (*):
+
+- Ubuntu 24.04.1
+- Adoptium OpenJDK 21.0.6
+
+Then use the following command to generate the eclair-node packages:
+
+```sh
+./mvnw clean install -DskipTests
+```
+
+That should generate `eclair-node/target/eclair-node-<version>-XXXXXXX-bin.zip` with sha256 checksums that match the one we provide and sign in `SHA256SUMS.asc`
+
+(*) You may be able to build the exact same artefacts with other operating systems or versions of JDK 21, we have not tried everything.
+
+## Upgrading
+
+This release is fully compatible with previous eclair versions. You don't need to close your channels, just stop eclair, upgrade and restart.
+
+## Changelog
+
+<fill this section when publishing the release with `git log v0.14.2... --format=oneline --reverse`>
### eclair-core/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.2</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-core_2.13</artifactId>
### eclair-front/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.2</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-front_2.13</artifactId>
### eclair-fuzz/pom.xml
@@ -5,7 +5,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.2</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-fuzz_2.13</artifactId>
### eclair-node/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.2</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-node_2.13</artifactId>
### eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
@@ -33,6 +33,10 @@ import scala.util.{Failure, Success}
*/
object Boot extends App with Logging {
try {
+ if (!System.getProperty("eclair.allow-unsafe-startup", "false").toBooleanOption.contains(true)) {
+ throw new RuntimeException("This version of eclair is unsafe to use: please wait for the next official release to update your node.")
+ }
+
val datadir = new File(System.getProperty("eclair.datadir", System.getProperty("user.home") + "/.eclair"))
val config = NodeParams.loadConfiguration(datadir)
if (config.getString("akka.actor.provider") == "cluster") {
### pom.xml
@@ -20,7 +20,7 @@
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.2</version>
+ <version>0.15.0-SNAPSHOT</version>
<packaging>pom</packaging>
<modules>Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.