What changed, and why it matters
This commit updates the Go compiler/toolchain version used to build the LND Lightning node from Go 1.25.5 to Go 1.26.3, and bumps the minimum Go language version declared in module files from 1.25.5 to 1.25.10. It also swaps one Windows release target from 32-bit ARM to 64-bit ARM. There is no code change to LND itself. The main security relevance is that newer Go patch releases typically fix bugs and security vulnerabilities in the Go runtime and standard library, so staying current is good defensive hygiene. However, the commit message does not say this is a security fix, and no specific vulnerability is named.
Treat as routine maintenance. Verify that CI passes and release artifacts build correctly for the new windows-arm64 target. Review the Go 1.26.3 and 1.25.10 release notes for any security fixes relevant to LND's use of the runtime/stdlib, but no immediate incident response is warranted based on this commit alone.
Security signals we found
Go toolchain version bump from 1.25.5 to 1.26.3
Go module minimum version bump from 1.25.5 to 1.25.10
Windows release target changed from windows-arm to windows-arm64
No application code or cryptographic changes
No CVE, security advisory, or vulnerability description in commit message
Evidence from the diff
The diff is a pure build-system/version-bump commit: Dockerfiles, GitHub Actions workflows, Makefile, golangci-lint config, and go.mod files are updated to Go 1.26.3 (release toolchain) / 1.25.10 (module minimum). The only functional-ish change beyond version strings is in make/release_flags.mk and .github/workflows/main.yml, where the windows-arm release target is replaced with windows-arm64. No application code, cryptography, networking, or consensus logic is modified. The security signal is indirect: Go patch releases often include fixes for runtime/stdlib issues, but this commit does not identify any CVE or security bug it is resolving.
Changed components
Build system (Makefile, Dockerfiles, GitHub Actions)Go module declarations (go.mod files across submodules)Release artifact matrix (windows-arm64 replaces windows-arm)Linting configuration (.golangci.yml)Inspect captured patch +42 / −42
diff --git a/.github/actions/setup-go/action.yml b/.github/actions/setup-go/action.yml
index 09f47d7..7a08688 100644
--- a/.github/actions/setup-go/action.yml
+++ b/.github/actions/setup-go/action.yml
@@ -52,8 +52,8 @@ runs:
# The key is used to create and later look up the cache. It's made of
# four parts:
# - The base part is made from the OS name, Go version and a
- # job-specified key prefix. Example: `linux-go-1.25.5-unit-test-`.
- # It ensures that a job running on Linux with Go 1.25 only looks for
+ # job-specified key prefix. Example: `linux-go-1.26.3-unit-test-`.
+ # It ensures that a job running on Linux with Go 1.26 only looks for
# caches from the same environment.
# - The unique part is the `hashFiles('**/go.sum')`, which calculates a
# hash (a fingerprint) of the go.sum file.
diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index a6958a4..7c63fef 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -41,7 +41,7 @@ env:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- GO_VERSION: 1.25.5
+ GO_VERSION: 1.26.3
jobs:
static-checks:
@@ -177,7 +177,7 @@ jobs:
- name: amd64
sys: darwin-amd64 freebsd-amd64 linux-amd64 netbsd-amd64 openbsd-amd64 windows-amd64
- name: arm
- sys: darwin-arm64 freebsd-arm linux-armv6 linux-armv7 linux-arm64 windows-arm
+ sys: darwin-arm64 freebsd-arm linux-armv6 linux-armv7 linux-arm64 windows-arm64
steps:
- name: Git checkout
uses: actions/checkout@v5
diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml
index 012a716..8182810 100644
--- a/.github/workflows/release.yaml
+++ b/.github/workflows/release.yaml
@@ -12,7 +12,7 @@ defaults:
env:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- GO_VERSION: 1.25.5
+ GO_VERSION: 1.26.3
jobs:
########################
diff --git a/.golangci.yml b/.golangci.yml
index 22a7c38..7d3b1a5 100644
--- a/.golangci.yml
+++ b/.golangci.yml
@@ -3,7 +3,7 @@ version: "2"
run:
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
- go: "1.25.5"
+ go: "1.26.3"
# Abort after 10 minutes.
timeout: 10m
diff --git a/Dockerfile b/Dockerfile
index 9cbe354..30353ad 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.5-alpine as builder
+FROM golang:1.26.3-alpine as builder
# Force Go to use the cgo based DNS resolver. This is required to ensure DNS
# queries required to connect to linked containers succeed.
diff --git a/Makefile b/Makefile
index 3ee1ee4..559a2e0 100644
--- a/Makefile
+++ b/Makefile
@@ -36,7 +36,7 @@ ACTIVE_GO_VERSION_MINOR := $(shell echo $(ACTIVE_GO_VERSION) | cut -d. -f2)
# GO_VERSION is the Go version used for the release build, docker files, and
# GitHub Actions. This is the reference version for the project. All other Go
# versions are checked against this version.
-GO_VERSION = 1.25.5
+GO_VERSION = 1.26.3
GOBUILD := $(GOCC) build -v
GOINSTALL := $(GOCC) install -v
diff --git a/actor/go.mod b/actor/go.mod
index c762776..bf5a392 100644
--- a/actor/go.mod
+++ b/actor/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/actor
-go 1.25.5
+go 1.25.10
require (
github.com/btcsuite/btclog/v2 v2.0.1-0.20250602222548-9967d19bb084
diff --git a/cert/go.mod b/cert/go.mod
index 13208c3..5bef041 100644
--- a/cert/go.mod
+++ b/cert/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/cert
-go 1.25.5
+go 1.25.10
require github.com/stretchr/testify v1.8.2
diff --git a/clock/go.mod b/clock/go.mod
index a81ac57..ed65a5b 100644
--- a/clock/go.mod
+++ b/clock/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/clock
-go 1.25.5
+go 1.25.10
require github.com/stretchr/testify v1.8.2
diff --git a/dev.Dockerfile b/dev.Dockerfile
index 4d681d8..999b2e7 100644
--- a/dev.Dockerfile
+++ b/dev.Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.5-alpine AS builder
+FROM golang:1.26.3-alpine AS builder
LABEL maintainer="Olaoluwa Osuntokun <laolu@lightning.engineering>"
diff --git a/docker/btcd/Dockerfile b/docker/btcd/Dockerfile
index 6e4ba58..a4b2301 100644
--- a/docker/btcd/Dockerfile
+++ b/docker/btcd/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.5-alpine AS builder
+FROM golang:1.26.3-alpine AS builder
LABEL maintainer="Olaoluwa Osuntokun <laolu@lightning.engineering>"
diff --git a/docs/INSTALL.md b/docs/INSTALL.md
index b038dc9..0c2f33b 100644
--- a/docs/INSTALL.md
+++ b/docs/INSTALL.md
@@ -93,7 +93,7 @@ following build dependencies are required:
### Installing Go
-`lnd` is written in Go, with a minimum version of `1.25.5` (or, in case this
+`lnd` is written in Go, with a minimum version of `1.25.10` (or, in case this
document gets out of date, whatever the Go version in the main `go.mod` file
requires). To install, run one of the following commands for your OS:
@@ -101,15 +101,15 @@ requires). To install, run one of the following commands for your OS:
<summary>Linux (x86-64)</summary>
```
- wget https://dl.google.com/go/go1.25.5.linux-amd64.tar.gz
- echo "9e9b755d63b36acf30c12a9a3fc379243714c1c6d3dd72861da637f336ebb35b go1.25.5.linux-amd64.tar.gz" | sha256sum --check
+ wget https://dl.google.com/go/go1.25.10.linux-amd64.tar.gz
+ echo "42d4f7a32316aa66591eca7e89867256057a4264451aca10570a715b3637ba70 go1.25.10.linux-amd64.tar.gz" | sha256sum --check
```
- The command above should output `go1.25.5.linux-amd64.tar.gz: OK`. If it
+ The command above should output `go1.25.10.linux-amd64.tar.gz: OK`. If it
doesn't, then the target REPO HAS BEEN MODIFIED, and you shouldn't install
this version of Go. If it matches, then proceed to install Go:
```
- sudo rm -rf /usr/local/go && sudo tar -C /usr/local -xzf go1.25.5.linux-amd64.tar.gz
+ sudo rm -rf /usr/local/go && sudo tar -C /usr/local -xzf go1.25.10.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin
```
</details>
@@ -118,15 +118,15 @@ requires). To install, run one of the following commands for your OS:
<summary>Linux (ARMv6)</summary>
```
- wget https://dl.google.com/go/go1.25.5.linux-armv6l.tar.gz
- echo "0b27e3dec8d04899d6941586d2aa2721c3dee67c739c1fc1b528188f3f6e8ab5 go1.25.5.linux-armv6l.tar.gz" | sha256sum --check
+ wget https://dl.google.com/go/go1.25.10.linux-armv6l.tar.gz
+ echo "39f168f158e693887d3ad006168af1b1a3007b19c5993cae4d9d57f82f52aaf8 go1.25.10.linux-armv6l.tar.gz" | sha256sum --check
```
- The command above should output `go1.25.5.linux-armv6l.tar.gz: OK`. If it
+ The command above should output `go1.25.10.linux-armv6l.tar.gz: OK`. If it
isn't, then the target REPO HAS BEEN MODIFIED, and you shouldn't install
this version of Go. If it matches, then proceed to install Go:
```
- sudo rm -rf /usr/local/go && tar -C /usr/local -xzf go1.25.5.linux-armv6l.tar.gz
+ sudo rm -rf /usr/local/go && sudo tar -C /usr/local -xzf go1.25.10.linux-armv6l.tar.gz
export PATH=$PATH:/usr/local/go/bin
```
diff --git a/fn/go.mod b/fn/go.mod
index 41d1a61..471655d 100644
--- a/fn/go.mod
+++ b/fn/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/fn/v2
-go 1.25.5
+go 1.25.10
require (
github.com/stretchr/testify v1.8.1
diff --git a/go.mod b/go.mod
index 4ce18fb..0c6d51c 100644
--- a/go.mod
+++ b/go.mod
@@ -217,9 +217,9 @@ replace github.com/gogo/protobuf => github.com/gogo/protobuf v1.3.2
// allows us to specify that as an option.
replace google.golang.org/protobuf => github.com/lightninglabs/protobuf-go-hex-display v1.33.0-hex-display
-// If you change this please also update docs/INSTALL.md and GO_VERSION in
-// Makefile (then run `make lint` to see where else it needs to be updated as
-// well).
-go 1.25.5
+// If you change this please also update docs/INSTALL.md and all other go.mod
+// files. The release build toolchain version is tracked separately by
+// GO_VERSION in Makefile.
+go 1.25.10
retract v0.0.2
diff --git a/healthcheck/go.mod b/healthcheck/go.mod
index e563bfa..8ff703a 100644
--- a/healthcheck/go.mod
+++ b/healthcheck/go.mod
@@ -24,4 +24,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.25.5
+go 1.25.10
diff --git a/kvdb/go.mod b/kvdb/go.mod
index 6d3fca0..87702b2 100644
--- a/kvdb/go.mod
+++ b/kvdb/go.mod
@@ -145,4 +145,4 @@ replace github.com/ulikunitz/xz => github.com/ulikunitz/xz v0.5.11
// https://deps.dev/advisory/OSV/GO-2021-0053?from=%2Fgo%2Fgithub.com%252Fgogo%252Fprotobuf%2Fv1.3.1
replace github.com/gogo/protobuf => github.com/gogo/protobuf v1.3.2
-go 1.25.5
+go 1.25.10
diff --git a/lnrpc/Dockerfile b/lnrpc/Dockerfile
index 680a774..cd51a12 100644
--- a/lnrpc/Dockerfile
+++ b/lnrpc/Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.5-bookworm
+FROM golang:1.26.3-bookworm
RUN apt-get update && apt-get install -y \
git \
diff --git a/lnrpc/gen_protos_docker.sh b/lnrpc/gen_protos_docker.sh
index 68c6558..4b4071d 100755
--- a/lnrpc/gen_protos_docker.sh
+++ b/lnrpc/gen_protos_docker.sh
@@ -6,7 +6,7 @@ set -e
DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# golang docker image version used in this script.
-GO_IMAGE=docker.io/library/golang:1.25.5-alpine
+GO_IMAGE=docker.io/library/golang:1.26.3-alpine
PROTOBUF_VERSION=$(docker run --rm -v $DIR/../:/lnd -w /lnd $GO_IMAGE \
go list -f '{{.Version}}' -m google.golang.org/protobuf)
diff --git a/make/builder.Dockerfile b/make/builder.Dockerfile
index 99d4aec..4e043a0 100644
--- a/make/builder.Dockerfile
+++ b/make/builder.Dockerfile
@@ -1,6 +1,6 @@
# If you change this please also update GO_VERSION in Makefile (then run
# `make lint` to see where else it needs to be updated as well).
-FROM golang:1.25.5-bookworm
+FROM golang:1.26.3-bookworm
MAINTAINER Olaoluwa Osuntokun <laolu@lightning.engineering>
diff --git a/make/release_flags.mk b/make/release_flags.mk
index 1e74b29..d063194 100644
--- a/make/release_flags.mk
+++ b/make/release_flags.mk
@@ -26,7 +26,7 @@ netbsd-amd64 \
openbsd-amd64 \
windows-386 \
windows-amd64 \
-windows-arm
+windows-arm64
RELEASE_TAGS = autopilotrpc signrpc walletrpc chainrpc invoicesrpc watchtowerrpc neutrinorpc monitoring peersrpc kvdb_postgres kvdb_etcd kvdb_sqlite
diff --git a/queue/go.mod b/queue/go.mod
index aab9770..93cde11 100644
--- a/queue/go.mod
+++ b/queue/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/queue
-go 1.25.5
+go 1.25.10
require (
github.com/lightningnetwork/lnd/fn/v2 v2.0.8
diff --git a/sqldb/go.mod b/sqldb/go.mod
index f77a90c..cddd663 100644
--- a/sqldb/go.mod
+++ b/sqldb/go.mod
@@ -71,4 +71,4 @@ require (
modernc.org/token v1.1.0 // indirect
)
-go 1.25.5
+go 1.25.10
diff --git a/sqldb/v2/go.mod b/sqldb/v2/go.mod
index 4d69fe6..e8baaeb 100644
--- a/sqldb/v2/go.mod
+++ b/sqldb/v2/go.mod
@@ -70,4 +70,4 @@ require (
// did not yet make it into the upstream repository.
replace github.com/golang-migrate/migrate/v4 => github.com/lightninglabs/migrate/v4 v4.18.2-9023d66a-fork-pr-2.0.20251211093704-71c1eef09789
-go 1.23.12
+go 1.25.10
diff --git a/ticker/go.mod b/ticker/go.mod
index 868a66c..9c5a634 100644
--- a/ticker/go.mod
+++ b/ticker/go.mod
@@ -1,3 +1,3 @@
module github.com/lightningnetwork/lnd/ticker
-go 1.25.5
+go 1.25.10
diff --git a/tlv/go.mod b/tlv/go.mod
index 365968f..ccfaca5 100644
--- a/tlv/go.mod
+++ b/tlv/go.mod
@@ -22,4 +22,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.25.5
+go 1.25.10
diff --git a/tools/Dockerfile b/tools/Dockerfile
index 986edda..eb60bc7 100644
--- a/tools/Dockerfile
+++ b/tools/Dockerfile
@@ -1,4 +1,4 @@
-FROM golang:1.25.5
+FROM golang:1.26.3
RUN apt-get update && apt-get install -y git
ENV GOCACHE=/tmp/build/.cache
diff --git a/tools/go.mod b/tools/go.mod
index fbd1b80..077c83b 100644
--- a/tools/go.mod
+++ b/tools/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/tools
-go 1.25.5
+go 1.25.10
require (
4d63.com/gocheckcompilerdirectives v1.3.0 // indirect
diff --git a/tools/linters/go.mod b/tools/linters/go.mod
index 76add99..82ce03d 100644
--- a/tools/linters/go.mod
+++ b/tools/linters/go.mod
@@ -1,6 +1,6 @@
module github.com/lightningnetwork/lnd/tools/linters
-go 1.25.5
+go 1.25.10
require (
github.com/golangci/plugin-module-register v0.1.1
diff --git a/tor/go.mod b/tor/go.mod
index 1af867f..198a0b2 100644
--- a/tor/go.mod
+++ b/tor/go.mod
@@ -23,4 +23,4 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
)
-go 1.25.5
+go 1.25.10
Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.