| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This point release includes fixes for vulnerabilities responsibly reported by a number of sources. It also comes at a time when increasingly capable AI models are being used to identify potential vulnerabilities in open-source code, significantly increasing the volume and pace of security reports.
The potential impact and associated risks are front of mind for everyone involved, not least the remediation team who have worked tirelessly to triage, resolve, and compile this release.
This embargo period will last for two weeks. The source code will not be published until 14 days have passed. During this time, we strongly encourage everyone to upgrade. At the end of this two-week period, the full release details will be made available.
This delay is designed to reduce the chances of prospective attackers reverse-engineering the fixes and exploiting them before the network can update.
Download the tarball for your platform below, verify it (see next section), then unpack it over your existing installation:
sudo tar -xvf <release>.tar.xz -C /usr/local --strip-components=2Restart lightningd afterwards. No database migration steps are required beyond the automatic ones applied at startup.
Docker images are not yet available and will follow shortly after this release. Do not wait for them to upgrade — the tarballs above are the release, and upgrading promptly is the whole point of the embargo period.
⚠️ The Docker images currently published for this release are not correct and must not be used.
elementsproject/lightningd:v26.06.7 and elementsproject/lightningd:latest were published automatically by CI and do not contain the fixes in this release, despite reporting v26.06.7 on startup. Corrected images will replace them shortly and this notice will be removed.
If you have already pulled, check which image you have:
docker image inspect --format '{{index .RepoDigests 0}}' elementsproject/lightningd:v26.06.7If the digest begins sha256:f0bd6bf2, you have the incorrect image. Do not run it as an upgrade; re-pull once this notice is removed.
Users pinned to v26.06.6 or earlier are unaffected.
Upgrade using the tarballs above rather than waiting for Docker. They are the release, they are signed, and upgrading promptly is the whole point of the embargo period.
Every binary is covered by a signed manifest. Check the checksums first:
sha256sum -c SHA256SUMS-v26.06.7 --ignore-missingThen the signatures:
gpg --verify SHA256SUMS-v26.06.7.asc SHA256SUMS-v26.06.7SHA256SUMS-v26.06.7 covers the amd64 tarballs and is signed by maintainers. SHA256SUMS-v26.06.7-arm64 covers the arm64 tarballs and has its own signature file. Signing keys:
| Signer | Fingerprint |
|---|---|
| nGoline | 4E4A 142F 8BD3 C38A 56B3 62ED 578C AC08 4725 45C5 |
| Christian Decker | B731 AAC5 21B0 1385 9313 F674 A26D 6D9F E088 ED58 |
| Peter Neuroth | 653B 19F3 3DF7 EFF3 E9D1 C94C C3F2 1EE3 87FF 4CD2 |
| daywalker90 | 8A07 9421 A871 D0B1 0835 1193 7AB4 802E D5A6 39F3 |
Fetch them with gpg --recv-keys <fingerprint>, or from the contrib/keys/ directory of the repository once the source is published.
The "Source code (zip)" and "Source code (tar.gz)" links that GitHub attaches to this release are not the v26.06.7 source. They are generated automatically and cannot be removed. The v26.06.7 source will be published when the embargo ends, 14 days from this release. Do not build from those archives expecting to get these binaries.
A commitment to the source has been published in advance. SHA256SUMS-v26.06.7 includes an entry for clightning-v26.06.7.zip, the source archive, even though that file is not attached to this release. Because the manifest is signed and published today, anyone can confirm when the source appears that it is the same source these binaries were built from, and that nothing was altered during the embargo.
Reproducing the binaries. Full build instructions will accompany the source release. This release was not built with the default optimisation settings, so a standard build will not reproduce these checksums; the exact parameters will be published alongside the source.
v26.06.3, v26.06.4, and v26.06.5 had issues during publishing with the pypi releases and were deleted.
Thanks to the Lightning team and our community contributors for their work on this release.
And, of course, to the core-Core Lightning team: @cdecker, @ShahanaFarooqui, @Lagrang3, @sangbida, @daywalker90, @nGoline, and @niftynei — carrying forward the work started by @rustyrussell, whose technical leadership and long-standing care for the project remain central to Core Lightning.
This point release if recommended for all minimal OS setups, including docker images, that have no root certificates for TLS installed.
Thanks to the Lightning team and our community contributors for their work on this release.
And of course, to the core-Core Lightning team: @rustyrussell, @ShahanaFarooqui, @sangbida, @cdecker, @nepet, @Lagrang3, @daywalker90, @nGoline and @niftynei
This point release fixes the bwatch plugin failure at registration.
Check out the updated Changelog
Thanks to the Lightning team and our community contributors for their work on this release.
Special thanks to @ddustin—still splicing, still appreciated! 🙌
A shutout to the core-Core Lightning team: @rustyrussell, @ShahanaFarooqui, @sangbida, @cdecker, @nepet, @Lagrang3, @daywalker90, @nGoline and @niftynei
This release has been named by @enaples
See the changelog for full details
A special mention to our three first time contributors:
A huge shout-out to @ddustin for his ongoing contributions and support. We truly appreciate your splicing—you really know how to keep things together! 🧬
An enormous thanks to the core-Core Lightning team:
@rustyrussell, @ShahanaFarooqui, @sangbida, @cdecker, @nepet, @Lagrang3, @daywalker90, @nGoline and @niftynei
This release has been named by @enaples
This RC builds upon RC1, with these changes:
See the changelog for full details
An enormous thanks to the core-Core Lightning team:
@rustyrussell, @ShahanaFarooqui, @sangbida, @cdecker, @nepet, @Lagrang3, @daywalker90, @nGoline and @niftynei
And of course, our invaluable open-source community!
See the changelog for full details
Since v26.04 we’ve had 211 commits in 22 days by 17 authors.
A special mention to our three first time contributors:
An enormous thanks to the core-Core Lightning team:
@rustyrussell, @ShahanaFarooqui, @sangbida, @cdecker, @nepet, @Lagrang3, @daywalker90, @nGoline and @niftynei
This is a hotfix release addressing build and protocol correctness issues found shortly after v26.04.
Thanks to the Core Lightning team for their work on this release
An enormous thanks to the Core Lightning team:
@rustyrussell, @ShahanaFarooqui, @sangbida, @cdecker, @nepet, @Lagrang3, @daywalker90, @nGoline and @niftynei
This release has been named by @Chand-ra
See the changelog for full details
@ScuttoZ
@Raimo33
@TatianaMoroz
@dovgopoly
@erdoganishe
@Nazarevsky
An enormous thanks to the Core Lightning team:
@rustyrussell, @ShahanaFarooqui, @sangbida, @endothermicdev, @cdecker, @nepet, @Lagrang3, @daywalker90 and @niftynei
This release has been named by @Chand-ra
See the changelog for full details
@ScuttoZ
@Raimo33
@TatianaMoroz
@dovgopoly
@erdoganishe
@Nazarevsky
An enormous thanks to the Core Lightning team:
@rustyrussell, @ShahanaFarooqui, @sangbida, @endothermicdev, @cdecker, @nepet, @Lagrang3, @daywalker90 and @niftynei
| Back | FazBrowse Home | New Git URL |