build: update CI+release version to Go 1.25.3
What changed, and why it matters
This commit is a routine build-maintenance change. It updates the version of the Go programming language used by the project's automated tests, release builds, Docker images, and documentation from Go 1.25.2 to Go 1.25.3 (and the minimum required Go version from 1.24.8 to 1.24.9). There are no code logic changes, no bug fixes, and no security patches in the project itself.
No security action required. Treat as normal build hygiene. If the project tracks Go security releases, verify separately whether Go 1.25.3 addresses any upstream Go runtime/compiler issues and ensure release builds use the updated image.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff consists entirely of string replacements of Go version numbers across CI workflows, Dockerfiles, Makefile, golangci-lint config, installation docs, and go.mod files in the main module and sub-modules. No application source code is modified. The change is a dependency/toolchain version bump, not a vulnerability fix.
Changed components
CI/CD configurationRelease build configurationDocker build imagesDeveloper tooling and linter configurationDocumentationInspect captured patch +29 / −29
diff --git a/.github/actions/setup-go/action.yml b/.github/actions/setup-go/action.yml
index 2291616..141097e 100644
--- a/.github/actions/setup-go/action.yml
+++ b/.github/actions/setup-go/action.yml
@@ -52,7 +52,7 @@ runs:
# The key is used to create and later look up the cache. It's made of
# four parts:
# - The base part is made from the OS name, Go version and a
- # job-specified key prefix. Example: `linux-go-1.25.2-unit-test-`.
+ # job-specified key prefix. Example: `linux-go-1.25.3-unit-test-`.
# It ensures that a job running on Linux with Go 1.25 only looks for
# caches from the same environment.
# - The unique part is the `hashFiles('**/go.sum')`, which calculates a
diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index 5cfbdb6..d92e9d2 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -40,7 +40,7 @@ env:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- GO_VERSION: 1.25.2
+ GO_VERSION: 1.25.3
jobs:
static-checks:
diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml
index 0e450de..64b768f 100644
--- a/.github/workflows/release.yaml
+++ b/.github/workflows/release.yaml
@@ -12,7 +12,7 @@ defaults:
env:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- GO_VERSION: 1.25.2
+ GO_VERSION: 1.25.3
jobs:
########################
diff --git a/.golangci.yml b/.golangci.yml
index b06d77a..a60ea93 100644
--- a/.golangci.yml
+++ b/.golangci.yml
@@ -1,7 +1,7 @@
run:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- go: "1.25.2"
+ go: "1.25.3"
# Abort after 10 minutes.
timeout: 10m
diff --git a/Dockerfile b/Dockerfile
index f784f47..e28726d 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.2-alpine as builder
+FROM golang:1.25.3-alpine as builder
# Force Go to use the cgo based DNS resolver. This is required to ensure DNS
# queries required to connect to linked containers succeed.
diff --git a/Makefile b/Makefile
index d7bcb74..0b18ac4 100644
--- a/Makefile
+++ b/Makefile
@@ -28,7 +28,7 @@ ACTIVE_GO_VERSION_MINOR := $(shell echo $(ACTIVE_GO_VERSION) | cut -d. -f2)
# GO_VERSION is the Go version used for the release build, docker files, and
# GitHub Actions. This is the reference version for the project. All other Go
# versions are checked against this version.
-GO_VERSION = 1.25.2
+GO_VERSION = 1.25.3
GOBUILD := $(GOCC) build -v
GOINSTALL := $(GOCC) install -v
diff --git a/dev.Dockerfile b/dev.Dockerfile
index 944e957..41a9b66 100644
--- a/dev.Dockerfile
+++ b/dev.Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.2-alpine AS builder
+FROM golang:1.25.3-alpine AS builder
LABEL maintainer="Olaoluwa Osuntokun <laolu@lightning.engineering>"
diff --git a/docker/btcd/Dockerfile b/docker/btcd/Dockerfile
index 8b3ac86..699c346 100644
--- a/docker/btcd/Dockerfile
+++ b/docker/btcd/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.2-alpine as builder
+FROM golang:1.25.3-alpine as builder
LABEL maintainer="Olaoluwa Osuntokun <laolu@lightning.engineering>"
diff --git a/docs/INSTALL.md b/docs/INSTALL.md
index a21bce2..bc1a64d 100644
--- a/docs/INSTALL.md
+++ b/docs/INSTALL.md
@@ -93,7 +93,7 @@ following build dependencies are required:
### Installing Go
-`lnd` is written in Go, with a minimum version of `1.24.8` (or, in case this
+`lnd` is written in Go, with a minimum version of `1.24.9` (or, in case this
document gets out of date, whatever the Go version in the main `go.mod` file
requires). To install, run one of the following commands for your OS:
@@ -101,15 +101,15 @@ requires). To install, run one of the following commands for your OS:
<summary>Linux (x86-64)</summary>
```
- wget https://dl.google.com/go/go1.24.8.linux-amd64.tar.gz
- echo "6842c516ca66c89d648a7f1dbe28e28c47b61b59f8f06633eb2ceb1188e9251d go1.24.8.linux-amd64.tar.gz" | sha256sum --check
+ wget https://dl.google.com/go/go1.24.9.linux-amd64.tar.gz
+ echo "5b7899591c2dd6e9da1809fde4a2fad842c45d3f6b9deb235ba82216e31e34a6 go1.24.9.linux-amd64.tar.gz" | sha256sum --check
```
- The command above should output `go1.24.8.linux-amd64.tar.gz: OK`. If it
+ The command above should output `go1.24.9.linux-amd64.tar.gz: OK`. If it
doesn't, then the target REPO HAS BEEN MODIFIED, and you shouldn't install
this version of Go. If it matches, then proceed to install Go:
```
- sudo rm -rf /usr/local/go && sudo tar -C /usr/local -xzf go1.24.8.linux-amd64.tar.gz
+ sudo rm -rf /usr/local/go && sudo tar -C /usr/local -xzf go1.24.9.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin
```
</details>
@@ -118,15 +118,15 @@ requires). To install, run one of the following commands for your OS:
<summary>Linux (ARMv6)</summary>
```
- wget https://dl.google.com/go/go1.24.8.linux-armv6l.tar.gz
- echo "3ed8537300ab22449885a43d2931336a571df72c5433d2db4377fe7e2d5e83db go1.24.8.linux-armv6l.tar.gz" | sha256sum --check
+ wget https://dl.google.com/go/go1.24.9.linux-armv6l.tar.gz
+ echo "39dafc8e7e5e455995f87e1ffc6b0892302ea519c1f0e59c9e2e0fda41b8aa56 go1.24.9.linux-armv6l.tar.gz" | sha256sum --check
```
- The command above should output `go1.24.8.linux-armv6l.tar.gz: OK`. If it
+ The command above should output `go1.24.9.linux-armv6l.tar.gz: OK`. If it
isn't, then the target REPO HAS BEEN MODIFIED, and you shouldn't install
this version of Go. If it matches, then proceed to install Go:
```
- sudo rm -rf /usr/local/go && tar -C /usr/local -xzf go1.24.8.linux-armv6l.tar.gz
+ sudo rm -rf /usr/local/go && tar -C /usr/local -xzf go1.24.9.linux-armv6l.tar.gz
export PATH=$PATH:/usr/local/go/bin
```
diff --git a/go.mod b/go.mod
index 37f842f..7c501f8 100644
--- a/go.mod
+++ b/go.mod
@@ -216,6 +216,6 @@ replace google.golang.org/protobuf => github.com/lightninglabs/protobuf-go-hex-d
// If you change this please also update docs/INSTALL.md and GO_VERSION in
// Makefile (then run `make lint` to see where else it needs to be updated as
// well).
-go 1.24.8
+go 1.24.9
retract v0.0.2
diff --git a/healthcheck/go.mod b/healthcheck/go.mod
index db16637..a9f8460 100644
--- a/healthcheck/go.mod
+++ b/healthcheck/go.mod
@@ -24,4 +24,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.24.8
+go 1.24.9
diff --git a/kvdb/go.mod b/kvdb/go.mod
index b9ee0bc..8171f7e 100644
--- a/kvdb/go.mod
+++ b/kvdb/go.mod
@@ -147,4 +147,4 @@ replace github.com/ulikunitz/xz => github.com/ulikunitz/xz v0.5.11
// https://deps.dev/advisory/OSV/GO-2021-0053?from=%2Fgo%2Fgithub.com%252Fgogo%252Fprotobuf%2Fv1.3.1
replace github.com/gogo/protobuf => github.com/gogo/protobuf v1.3.2
-go 1.24.8
+go 1.24.9
diff --git a/lnrpc/Dockerfile b/lnrpc/Dockerfile
index 4c7f736..431eeb2 100644
--- a/lnrpc/Dockerfile
+++ b/lnrpc/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.2-bookworm
+FROM golang:1.25.3-bookworm
RUN apt-get update && apt-get install -y \
git \
diff --git a/lnrpc/gen_protos_docker.sh b/lnrpc/gen_protos_docker.sh
index 5e10850..604c3bb 100755
--- a/lnrpc/gen_protos_docker.sh
+++ b/lnrpc/gen_protos_docker.sh
@@ -6,7 +6,7 @@ set -e
DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# golang docker image version used in this script.
-GO_IMAGE=docker.io/library/golang:1.25.2-alpine
+GO_IMAGE=docker.io/library/golang:1.25.3-alpine
PROTOBUF_VERSION=$(docker run --rm -v $DIR/../:/lnd -w /lnd $GO_IMAGE \
go list -f '{{.Version}}' -m google.golang.org/protobuf)
diff --git a/make/builder.Dockerfile b/make/builder.Dockerfile
index 636bc72..c85ddbd 100644
--- a/make/builder.Dockerfile
+++ b/make/builder.Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.2-bookworm
+FROM golang:1.25.3-bookworm
MAINTAINER Olaoluwa Osuntokun <laolu@lightning.engineering>
diff --git a/sqldb/go.mod b/sqldb/go.mod
index 064960d..33a497e 100644
--- a/sqldb/go.mod
+++ b/sqldb/go.mod
@@ -75,4 +75,4 @@ require (
modernc.org/token v1.1.0 // indirect
)
-go 1.24.8
+go 1.24.9
diff --git a/tlv/go.mod b/tlv/go.mod
index a7d3fe3..44953d0 100644
--- a/tlv/go.mod
+++ b/tlv/go.mod
@@ -22,4 +22,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.24.8
+go 1.24.9
diff --git a/tools/Dockerfile b/tools/Dockerfile
index 7061f86..9d9f13f 100644
--- a/tools/Dockerfile
+++ b/tools/Dockerfile
@@ -1,4 +1,4 @@
-FROM golang:1.25.2
+FROM golang:1.25.3
RUN apt-get update && apt-get install -y git
ENV GOCACHE=/tmp/build/.cache
diff --git a/tools/go.mod b/tools/go.mod
index b05e991..72af050 100644
--- a/tools/go.mod
+++ b/tools/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/tools
-go 1.24.8
+go 1.24.9
require (
github.com/btcsuite/btcd v0.24.2
diff --git a/tools/linters/go.mod b/tools/linters/go.mod
index 6ab59b8..cebb0e7 100644
--- a/tools/linters/go.mod
+++ b/tools/linters/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/tools/linters
-go 1.24.8
+go 1.24.9
require (
github.com/golangci/plugin-module-register v0.1.1
diff --git a/tor/go.mod b/tor/go.mod
index ecba66b..fd4c3d4 100644
--- a/tor/go.mod
+++ b/tor/go.mod
@@ -23,4 +23,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.24.8
+go 1.24.9
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.