What changed, and why it matters
This commit updates the Go programming language version used to build LND from 1.23.10 to 1.23.12 across build files, Docker images, and documentation. Go patch releases typically include bug fixes and security fixes in the Go runtime and standard library. The commit itself does not change any LND application code, but it may pull in upstream security fixes from the Go toolchain. Without explicit vendor disclosure or a CVE reference in the commit, we cannot confirm which specific vulnerabilities are being addressed.
Treat as a routine maintenance update with potential latent security benefit. Verify the published SHA-256 checksums in docs/INSTALL.md against official Go downloads. Review the Go 1.23.11 and 1.23.12 release notes for any security fixes that may affect LND's threat model, and consider expediting deployment if a relevant CVE is identified. No immediate code-level mitigation is required.
Security signals we found
Toolchain version bump to latest patch release
No application code changes
No CVE or security advisory referenced in commit message
Updated published SHA-256 checksums in INSTALL.md
May incorporate upstream Go security fixes
Evidence from the diff
The diff is a mechanical version bump of the Go toolchain from 1.23.10 to 1.23.12 in 20 files: GitHub Actions workflows, Makefile, golangci-lint config, Dockerfiles, go.mod files for the main module and sub-modules (healthcheck, kvdb, sqldb, tlv, tools, tor), and installation docs including updated SHA-256 checksums. No LND source code is modified. Go 1.23.11 and 1.23.12 are patch releases; historically such bumps include fixes for issues in the Go runtime, compiler, and standard library, some of which may have security implications (e.g., CVEs in crypto/tls, net/http, or the runtime). The commit message does not cite a CVE or security rationale.
Changed components
Build toolchain (Go 1.23.10 -> 1.23.12)GitHub Actions CI/CDRelease build Docker imagesDeveloper Docker imagesgo.mod files for main module and sub-modulesInstallation documentationInspect captured patch +28 / −28
diff --git a/.github/actions/setup-go/action.yml b/.github/actions/setup-go/action.yml
index aa6a50f..0f1313d 100644
--- a/.github/actions/setup-go/action.yml
+++ b/.github/actions/setup-go/action.yml
@@ -52,7 +52,7 @@ runs:
# The key is used to create and later look up the cache. It's made of
# four parts:
# - The base part is made from the OS name, Go version and a
- # job-specified key prefix. Example: `linux-go-1.23.10-unit-test-`.
+ # job-specified key prefix. Example: `linux-go-1.23.12-unit-test-`.
# It ensures that a job running on Linux with Go 1.23 only looks for
# caches from the same environment.
# - The unique part is the `hashFiles('**/go.sum')`, which calculates a
diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index 550830d..7c4868d 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -40,7 +40,7 @@ env:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- GO_VERSION: 1.23.10
+ GO_VERSION: 1.23.12
jobs:
static-checks:
diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml
index 5224d15..9158690 100644
--- a/.github/workflows/release.yaml
+++ b/.github/workflows/release.yaml
@@ -12,7 +12,7 @@ defaults:
env:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- GO_VERSION: 1.23.10
+ GO_VERSION: 1.23.12
jobs:
main:
diff --git a/.golangci.yml b/.golangci.yml
index 9f1ab49..eaf7371 100644
--- a/.golangci.yml
+++ b/.golangci.yml
@@ -1,7 +1,7 @@
run:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- go: "1.23.10"
+ go: "1.23.12"
# Abort after 10 minutes.
timeout: 10m
diff --git a/Dockerfile b/Dockerfile
index 5415863..5cf4f96 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.23.10-alpine as builder
+FROM golang:1.23.12-alpine as builder
# Force Go to use the cgo based DNS resolver. This is required to ensure DNS
# queries required to connect to linked containers succeed.
diff --git a/Makefile b/Makefile
index c9a3bac..97863b0 100644
--- a/Makefile
+++ b/Makefile
@@ -28,7 +28,7 @@ ACTIVE_GO_VERSION_MINOR := $(shell echo $(ACTIVE_GO_VERSION) | cut -d. -f2)
# GO_VERSION is the Go version used for the release build, docker files, and
# GitHub Actions. This is the reference version for the project. All other Go
# versions are checked against this version.
-GO_VERSION = 1.23.10
+GO_VERSION = 1.23.12
GOBUILD := $(GOCC) build -v
GOINSTALL := $(GOCC) install -v
diff --git a/dev.Dockerfile b/dev.Dockerfile
index 6a3036c..aa58411 100644
--- a/dev.Dockerfile
+++ b/dev.Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.23.10-alpine AS builder
+FROM golang:1.23.12-alpine AS builder
LABEL maintainer="Olaoluwa Osuntokun <laolu@lightning.engineering>"
diff --git a/docker/btcd/Dockerfile b/docker/btcd/Dockerfile
index 0af8692..22d48a8 100644
--- a/docker/btcd/Dockerfile
+++ b/docker/btcd/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.23.10-alpine as builder
+FROM golang:1.23.12-alpine as builder
LABEL maintainer="Olaoluwa Osuntokun <laolu@lightning.engineering>"
diff --git a/docs/INSTALL.md b/docs/INSTALL.md
index 1f8244c..b953b6f 100644
--- a/docs/INSTALL.md
+++ b/docs/INSTALL.md
@@ -93,7 +93,7 @@ following build dependencies are required:
### Installing Go
-`lnd` is written in Go, with a minimum version of `1.23.10` (or, in case this
+`lnd` is written in Go, with a minimum version of `1.23.12` (or, in case this
document gets out of date, whatever the Go version in the main `go.mod` file
requires). To install, run one of the following commands for your OS:
@@ -101,16 +101,16 @@ requires). To install, run one of the following commands for your OS:
<summary>Linux (x86-64)</summary>
```
- wget https://dl.google.com/go/go1.23.10.linux-amd64.tar.gz
- sha256sum go1.23.10.linux-amd64.tar.gz | awk -F " " '{ print $1 }'
+ wget https://dl.google.com/go/go1.23.12.linux-amd64.tar.gz
+ sha256sum go1.23.12.linux-amd64.tar.gz | awk -F " " '{ print $1 }'
```
The final output of the command above should be
- `535f9f81802499f2a7dbfa70abb8fda3793725fcc29460f719815f6e10b5fd60`. If it
+ `d3847fef834e9db11bf64e3fb34db9c04db14e068eeb064f49af747010454f90`. If it
isn't, then the target REPO HAS BEEN MODIFIED, and you shouldn't install
this version of Go. If it matches, then proceed to install Go:
```
- sudo rm -rf /usr/local/go && sudo tar -C /usr/local -xzf go1.23.10.linux-amd64.tar.gz
+ sudo rm -rf /usr/local/go && sudo tar -C /usr/local -xzf go1.23.12.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin
```
</details>
@@ -119,16 +119,16 @@ requires). To install, run one of the following commands for your OS:
<summary>Linux (ARMv6)</summary>
```
- wget https://dl.google.com/go/go1.23.10.linux-armv6l.tar.gz
- sha256sum go1.23.10.linux-armv6l.tar.gz | awk -F " " '{ print $1 }'
+ wget https://dl.google.com/go/go1.23.12.linux-armv6l.tar.gz
+ sha256sum go1.23.12.linux-armv6l.tar.gz | awk -F " " '{ print $1 }'
```
The final output of the command above should be
- `b6e00c9a72406d394b9f167e74670e28b72ed559cca8115b21be1cb9d5316cb4`. If it
+ `9704eba01401a3793f54fac162164b9c5d8cc6f3cab5cee72684bb72294d9f41`. If it
isn't, then the target REPO HAS BEEN MODIFIED, and you shouldn't install
this version of Go. If it matches, then proceed to install Go:
```
- sudo rm -rf /usr/local/go && tar -C /usr/local -xzf go1.23.10.linux-armv6l.tar.gz
+ sudo rm -rf /usr/local/go && tar -C /usr/local -xzf go1.23.12.linux-armv6l.tar.gz
export PATH=$PATH:/usr/local/go/bin
```
diff --git a/go.mod b/go.mod
index 06be591..c321cf9 100644
--- a/go.mod
+++ b/go.mod
@@ -220,6 +220,6 @@ replace google.golang.org/protobuf => github.com/lightninglabs/protobuf-go-hex-d
// If you change this please also update docs/INSTALL.md and GO_VERSION in
// Makefile (then run `make lint` to see where else it needs to be updated as
// well).
-go 1.23.10
+go 1.23.12
retract v0.0.2
diff --git a/healthcheck/go.mod b/healthcheck/go.mod
index f459a92..ac36350 100644
--- a/healthcheck/go.mod
+++ b/healthcheck/go.mod
@@ -24,4 +24,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.23.10
+go 1.23.12
diff --git a/kvdb/go.mod b/kvdb/go.mod
index b711afc..e37ff83 100644
--- a/kvdb/go.mod
+++ b/kvdb/go.mod
@@ -147,4 +147,4 @@ replace github.com/ulikunitz/xz => github.com/ulikunitz/xz v0.5.11
// https://deps.dev/advisory/OSV/GO-2021-0053?from=%2Fgo%2Fgithub.com%252Fgogo%252Fprotobuf%2Fv1.3.1
replace github.com/gogo/protobuf => github.com/gogo/protobuf v1.3.2
-go 1.23.10
+go 1.23.12
diff --git a/lnrpc/Dockerfile b/lnrpc/Dockerfile
index 05f9166..be8c9f7 100644
--- a/lnrpc/Dockerfile
+++ b/lnrpc/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.23.10-bookworm
+FROM golang:1.23.12-bookworm
RUN apt-get update && apt-get install -y \
git \
diff --git a/lnrpc/gen_protos_docker.sh b/lnrpc/gen_protos_docker.sh
index e724863..2253bdc 100755
--- a/lnrpc/gen_protos_docker.sh
+++ b/lnrpc/gen_protos_docker.sh
@@ -6,7 +6,7 @@ set -e
DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# golang docker image version used in this script.
-GO_IMAGE=docker.io/library/golang:1.23.10-alpine
+GO_IMAGE=docker.io/library/golang:1.23.12-alpine
PROTOBUF_VERSION=$(docker run --rm -v $DIR/../:/lnd -w /lnd $GO_IMAGE \
go list -f '{{.Version}}' -m google.golang.org/protobuf)
diff --git a/make/builder.Dockerfile b/make/builder.Dockerfile
index 66e9bc8..d2abf4b 100644
--- a/make/builder.Dockerfile
+++ b/make/builder.Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.23.10-bookworm
+FROM golang:1.23.12-bookworm
MAINTAINER Olaoluwa Osuntokun <laolu@lightning.engineering>
diff --git a/sqldb/go.mod b/sqldb/go.mod
index dbe0d20..213042a 100644
--- a/sqldb/go.mod
+++ b/sqldb/go.mod
@@ -75,4 +75,4 @@ require (
modernc.org/token v1.1.0 // indirect
)
-go 1.23.10
+go 1.23.12
diff --git a/tlv/go.mod b/tlv/go.mod
index 383f655..5319833 100644
--- a/tlv/go.mod
+++ b/tlv/go.mod
@@ -22,4 +22,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.23.10
+go 1.23.12
diff --git a/tools/Dockerfile b/tools/Dockerfile
index 43a3405..a9b39ed 100644
--- a/tools/Dockerfile
+++ b/tools/Dockerfile
@@ -1,4 +1,4 @@
-FROM golang:1.23.10
+FROM golang:1.23.12
RUN apt-get update && apt-get install -y git
ENV GOCACHE=/tmp/build/.cache
diff --git a/tools/go.mod b/tools/go.mod
index 5d40dc3..2b81efe 100644
--- a/tools/go.mod
+++ b/tools/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/tools
-go 1.23.10
+go 1.23.12
require (
github.com/btcsuite/btcd v0.24.2
diff --git a/tor/go.mod b/tor/go.mod
index 98869a2..2a12e29 100644
--- a/tor/go.mod
+++ b/tor/go.mod
@@ -23,4 +23,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.23.10
+go 1.23.12
Why this scored 37/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.