Repository navigation
Bump litecoin-core 0.21.5.6 - #38
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
Bumps the pinned Litecoin Core patch version used by the 0.21 Docker image to pick up upstream security hardening around MWEB validation, while keeping the image’s overall build and runtime flow the same.
Changes:
- Update
LITECOIN_VERSIONin0.21/Dockerfilefrom0.21.2.2to0.21.5.6.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Urgent security release hardening MWEB validation (resource-exhaustion protections, relay-policy tx weight/input limits). Strongly recommended by upstream for all users. https://github.com/litecoin-project/litecoin/releases/tag/v0.21.5.6
joaomatbarbosa
force-pushed
the
bugfix/bump-litecoin-0.21.5.6
branch
from
August 3, 2026 13:22
72baa50 to
797e0d6
Compare
pedrobranco
approved these changes
Aug 3, 2026
1 of 2 tasks
joaomatbarbosa
added a commit
that referenced
this pull request
Aug 6, 2026
pgp.mit.edu, keyserver.pgp.com and the sks-keyservers.net pool are unreachable, so key import fails and every build (0.10 through 0.21) dies at that step. This blocked publishing the 0.21.5.6 security bump from #38 -- `build (0.21)` failed 5 consecutive attempts on master and uphold/litecoin-core:0.21 still serves the image built in Feb 2024. Switch to keys.openpgp.org with keyserver.ubuntu.com as fallback. Also pin both Litecoin signing keys by full 40-hex fingerprint instead of 64-bit long key ID, matching what docker-dash-core already does and what the gosu key here already used. Fetching by long ID leaves the import open to key-ID collision; with a full fingerprint gpg rejects any key that does not match. 3620E9D387E55666 -> D35621D53A1CC6A3456758D03620E9D387E55666 David Burkett <davidburkett38@gmail.com> FE3348877809386C -> 59CAF0E96F23F53747945FD4FE3348877809386C Adrian Gallagher <thrasher@addictionsoftware.com>
pedrobranco
pushed a commit
that referenced
this pull request
Aug 6, 2026
pgp.mit.edu, keyserver.pgp.com and the sks-keyservers.net pool are unreachable, so key import fails and every build (0.10 through 0.21) dies at that step. This blocked publishing the 0.21.5.6 security bump from #38 -- `build (0.21)` failed 5 consecutive attempts on master and uphold/litecoin-core:0.21 still serves the image built in Feb 2024. Switch to keys.openpgp.org with keyserver.ubuntu.com as fallback. Also pin both Litecoin signing keys by full 40-hex fingerprint instead of 64-bit long key ID, matching what docker-dash-core already does and what the gosu key here already used. Fetching by long ID leaves the import open to key-ID collision; with a full fingerprint gpg rejects any key that does not match. 3620E9D387E55666 -> D35621D53A1CC6A3456758D03620E9D387E55666 David Burkett <davidburkett38@gmail.com> FE3348877809386C -> 59CAF0E96F23F53747945FD4FE3348877809386C Adrian Gallagher <thrasher@addictionsoftware.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
0.21/Dockerfilefrom0.21.2.2to0.21.5.6.uphold/litecoin-core:0.21) has been on MWEB-enabled versions since activation, so it validates MWEB blocks regardless of whether we use MWEB txs ourselves.Release notes: https://github.com/litecoin-project/litecoin/releases/tag/v0.21.5.6
Test plan
0.21taglitecoin-0instance, monitor logs/peers after restart