What changed, and why it matters
This commit is a routine post-release housekeeping change. It bumps the project version from 0.14.3 to 0.15.0-SNAPSHOT across several build files, re-enables a Maven trusted-checksum feature used for build verification, adds a placeholder release-notes document, and deliberately prevents accidental startup of the new development snapshot by throwing an error unless a special override flag is set. There is no security vulnerability in this commit.
No action required. This is a normal development-state commit. If running from source, note the new startup guard requiring -Declair.allow-unsafe-startup=true for snapshot builds.
Security signals we found
No security-relevant code changes
No vulnerability indicators
No bug fixes or patches
No incident references
No attribution to security researchers
Evidence from the diff
The commit transitions the repository from release state to development state. Changes include: (1) version bump from 0.14.3 to 0.15.0-SNAPSHOT in pom.xml and module pom files; (2) enabling aether.artifactResolver.postProcessor.trustedChecksums=true in .mvn/maven.config, which enforces trusted checksum verification during artifact resolution; (3) adding a new docs/release-notes/eclair-vnext.md template; and (4) adding a guard in Boot.scala that refuses to start unless -Declair.allow-unsafe-startup=true is provided. The guard is an intentional safety measure, not a vulnerability.
Changed components
Build configuration (.mvn/maven.config, pom.xml files)Release documentation (docs/release-notes/eclair-vnext.md)Node startup guard (eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala)Inspect captured patch +74 / −6
### .mvn/maven.config
@@ -2,7 +2,7 @@
-Daether.trustedChecksumsSource.summaryFile=true
-Daether.trustedChecksumsSource.summaryFile.basedir=${session.rootDirectory}/.mvn/checksums/
# post processor: trusted checksums
--Daether.artifactResolver.postProcessor.trustedChecksums=false
+-Daether.artifactResolver.postProcessor.trustedChecksums=true
-Daether.artifactResolver.postProcessor.trustedChecksums.checksumAlgorithms=SHA-256
-Daether.artifactResolver.postProcessor.trustedChecksums.failIfMissing=true
-Daether.artifactResolver.postProcessor.trustedChecksums.snapshots=false
### docs/release-notes/eclair-vnext.md
@@ -0,0 +1,64 @@
+# Eclair vnext
+
+<insert here a high-level description of the release>
+
+## Major changes
+
+<insert changes>
+
+### Configuration changes
+
+<insert changes>
+
+### API changes
+
+<insert changes>
+
+### Miscellaneous improvements and bug fixes
+
+<insert changes>
+
+## Verifying signatures
+
+You will need `gpg` and our release signing key E04E48E72C205463. Note that you can get it:
+
+- from our website: https://acinq.co/pgp/drouinf2.asc
+- from github user @sstone, a committer on eclair: https://api.github.com/users/sstone/gpg_keys
+
+To import our signing key:
+
+```sh
+$ gpg --import drouinf2.asc
+```
+
+To verify the release file checksums and signatures:
+
+```sh
+$ gpg -d SHA256SUMS.asc > SHA256SUMS.stripped
+$ sha256sum -c SHA256SUMS.stripped
+```
+
+## Building
+
+Eclair builds are deterministic. To reproduce our builds, please use the following environment (*):
+
+- Ubuntu 24.04.1
+- Adoptium OpenJDK 21.0.6
+
+Then use the following command to generate the eclair-node packages:
+
+```sh
+./mvnw clean install -DskipTests
+```
+
+That should generate `eclair-node/target/eclair-node-<version>-XXXXXXX-bin.zip` with sha256 checksums that match the one we provide and sign in `SHA256SUMS.asc`
+
+(*) You may be able to build the exact same artefacts with other operating systems or versions of JDK 21, we have not tried everything.
+
+## Upgrading
+
+This release is fully compatible with previous eclair versions. You don't need to close your channels, just stop eclair, upgrade and restart.
+
+## Changelog
+
+<fill this section when publishing the release with `git log --reverse --abbrev=7 --pretty=format:'- [%h](https://github.com/ACINQ/eclair/commit/%H) %s' v0.14.3... --format=oneline --reverse`>
### eclair-core/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.3</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-core_2.13</artifactId>
### eclair-front/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.3</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-front_2.13</artifactId>
### eclair-fuzz/pom.xml
@@ -5,7 +5,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.3</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-fuzz_2.13</artifactId>
### eclair-node/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.3</version>
+ <version>0.15.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-node_2.13</artifactId>
### eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
@@ -33,6 +33,10 @@ import scala.util.{Failure, Success}
*/
object Boot extends App with Logging {
try {
+ if (!System.getProperty("eclair.allow-unsafe-startup", "false").toBooleanOption.contains(true)) {
+ throw new RuntimeException("This version of eclair is unsafe to use: please wait for the next official release to update your node.")
+ }
+
val datadir = new File(System.getProperty("eclair.datadir", System.getProperty("user.home") + "/.eclair"))
val config = NodeParams.loadConfiguration(datadir)
if (config.getString("akka.actor.provider") == "cluster") {
### pom.xml
@@ -20,7 +20,7 @@
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.14.3</version>
+ <version>0.15.0-SNAPSHOT</version>
<packaging>pom</packaging>
<modules>Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.