What changed, and why it matters
This commit is a routine post-release housekeeping change. It bumps the project version from 0.13.1 to 0.14.0-SNAPSHOT, re-enables Maven trusted checksum verification for development builds, adds a placeholder release notes file, and intentionally prevents accidental production use of the new development snapshot by refusing to start unless a special override flag is set. There is no security vulnerability here.
No security action needed. This is normal release-cycle maintenance. If running from source, set `-Declair.allow-unsafe-startup=true` only for intentional development/testing, never for production mainnet nodes.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit titled ‘Back to dev (#3197)’ transitions the repository from the v0.13.1 release state back to active development. Changes include: version bumps in pom.xml files to 0.14.0-SNAPSHOT; enabling the Maven Aether trusted checksums post-processor (changing trustedChecksums from false to true in .mvn/maven.config); adding a blank release notes template at docs/release-notes/eclair-vnext.md; and adding a startup guard in Boot.scala that throws a RuntimeException unless the system property eclair.allow-unsafe-startup is set to true. The guard is a safety mechanism to stop users from running an unreleased development snapshot on a mainnet node, not a vulnerability.
Changed components
Build configuration (.mvn/maven.config, pom.xml files)Release notes template (docs/release-notes/eclair-vnext.md)Node startup logic (eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala)Inspect captured patch +73 / −5
diff --git a/.mvn/maven.config b/.mvn/maven.config
index e92391e..acf5164 100644
--- a/.mvn/maven.config
+++ b/.mvn/maven.config
@@ -2,7 +2,7 @@
-Daether.trustedChecksumsSource.summaryFile=true
-Daether.trustedChecksumsSource.summaryFile.basedir=${session.rootDirectory}/.mvn/checksums/
# post processor: trusted checksums
--Daether.artifactResolver.postProcessor.trustedChecksums=false
+-Daether.artifactResolver.postProcessor.trustedChecksums=true
-Daether.artifactResolver.postProcessor.trustedChecksums.checksumAlgorithms=SHA-256
-Daether.artifactResolver.postProcessor.trustedChecksums.failIfMissing=true
-Daether.artifactResolver.postProcessor.trustedChecksums.snapshots=false
diff --git a/docs/release-notes/eclair-vnext.md b/docs/release-notes/eclair-vnext.md
new file mode 100644
index 0000000..3566257
--- /dev/null
+++ b/docs/release-notes/eclair-vnext.md
@@ -0,0 +1,64 @@
+# Eclair vnext
+
+<insert here a high-level description of the release>
+
+## Major changes
+
+<insert changes>
+
+### Configuration changes
+
+<insert changes>
+
+### API changes
+
+<insert changes>
+
+### Miscellaneous improvements and bug fixes
+
+<insert changes>
+
+## Verifying signatures
+
+You will need `gpg` and our release signing key E04E48E72C205463. Note that you can get it:
+
+- from our website: https://acinq.co/pgp/drouinf2.asc
+- from github user @sstone, a committer on eclair: https://api.github.com/users/sstone/gpg_keys
+
+To import our signing key:
+
+```sh
+$ gpg --import drouinf2.asc
+```
+
+To verify the release file checksums and signatures:
+
+```sh
+$ gpg -d SHA256SUMS.asc > SHA256SUMS.stripped
+$ sha256sum -c SHA256SUMS.stripped
+```
+
+## Building
+
+Eclair builds are deterministic. To reproduce our builds, please use the following environment (*):
+
+- Ubuntu 24.04.1
+- Adoptium OpenJDK 21.0.6
+
+Then use the following command to generate the eclair-node packages:
+
+```sh
+./mvnw clean install -DskipTests
+```
+
+That should generate `eclair-node/target/eclair-node-<version>-XXXXXXX-bin.zip` with sha256 checksums that match the one we provide and sign in `SHA256SUMS.asc`
+
+(*) You may be able to build the exact same artefacts with other operating systems or versions of JDK 21, we have not tried everything.
+
+## Upgrading
+
+This release is fully compatible with previous eclair versions. You don't need to close your channels, just stop eclair, upgrade and restart.
+
+## Changelog
+
+<fill this section when publishing the release with `git log v0.13.1... --format=oneline --reverse`>
diff --git a/eclair-core/pom.xml b/eclair-core/pom.xml
index 374d1e8..0d74be9 100644
--- a/eclair-core/pom.xml
+++ b/eclair-core/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.13.1</version>
+ <version>0.14.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-core_2.13</artifactId>
diff --git a/eclair-front/pom.xml b/eclair-front/pom.xml
index 79c5936..4aa1b66 100644
--- a/eclair-front/pom.xml
+++ b/eclair-front/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.13.1</version>
+ <version>0.14.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-front_2.13</artifactId>
diff --git a/eclair-node/pom.xml b/eclair-node/pom.xml
index 7b7af79..851e897 100644
--- a/eclair-node/pom.xml
+++ b/eclair-node/pom.xml
@@ -21,7 +21,7 @@
<parent>
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.13.1</version>
+ <version>0.14.0-SNAPSHOT</version>
</parent>
<artifactId>eclair-node_2.13</artifactId>
diff --git a/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala b/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
index 7e29046..1d6c4ec 100644
--- a/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
+++ b/eclair-node/src/main/scala/fr/acinq/eclair/Boot.scala
@@ -33,6 +33,10 @@ import scala.util.{Failure, Success}
*/
object Boot extends App with Logging {
try {
+ if (!System.getProperty("eclair.allow-unsafe-startup", "false").toBooleanOption.contains(true)) {
+ throw new RuntimeException("This version of eclair is unsafe to use: please wait for the next official release to update your node.")
+ }
+
val datadir = new File(System.getProperty("eclair.datadir", System.getProperty("user.home") + "/.eclair"))
val config = NodeParams.loadConfiguration(datadir)
diff --git a/pom.xml b/pom.xml
index c38c325..63c266d 100644
--- a/pom.xml
+++ b/pom.xml
@@ -20,7 +20,7 @@
<groupId>fr.acinq.eclair</groupId>
<artifactId>eclair_2.13</artifactId>
- <version>0.13.1</version>
+ <version>0.14.0-SNAPSHOT</version>
<packaging>pom</packaging>
<modules>
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.