Skip to main content

Node v1.0.2 release notes

For the complete documentation index, see llms.txt
  • Version: v1.0.2
  • Date: September 18, 2026
  • Components: node-1.0.2, toolkit-1.0.0, runtime-1.0.0
Use node and toolkit v1.0.300 on public networks

Preview, Preprod, and Mainnet now run runtime 1.0.300 (spec_version 1_000_300). That runtime imports version 2 Ledger8Bridge host functions that node v1.0.2 does not provide, so a v1.0.2 node cannot import blocks from that runtime upgrade onward. Toolkit 1.0.0, which ships with this release, also fails with UnsupportedBlockVersion(1000300) on blocks from that runtime. Run node v1.0.300 and toolkit 1.0.300 on these networks. They include every change in this release.


Docker images​

docker pull midnightntwrk/midnight-node:1.0.2
docker pull midnightntwrk/midnight-node-toolkit:1.0.0

The toolkit version number is unchanged, but the midnight-node-toolkit:1.0.0 image was rebuilt for this release and carries the dependency fixes described below. Pull the tag again to pick them up.


High-level summary​

Node v1.0.2 is a small dependency and security patch on the v1.0.0 GA line. It moves the ledger 8 dependency to the ledger 8.1.2 security release. It also clears npm audit findings in the toolkit image and fixes a toolkit-js stack overflow on Node.js 24.15 and later.

No pallet or runtime code changed. The runtime stays at 1.0.0 with spec_version 1_000_000 and transaction_version 3, so this is a binary-only upgrade with no runtime upgrade or governance action.

The changes below are the delta from v1.0.1. For the full diff, see the comparison between the two tags.


Audience​

This release note is relevant for users who:

  • Run a node on the 1.0.x line and want to know what changed between v1.0.1 and v1.0.2.
  • Run the node toolkit image and scan it for npm advisories.
  • Build or run toolkit-js from source on Node.js 24.15 or later, where it previously overflowed the stack.

DApp developers do not need to take any action for this release.


What changed (Summary of updates)​

The updates below describe the key changes introduced in this release.

  • Moved the ledger 8 dependency from 8.1.1 to 8.1.2, a security release that rejects non-canonical encodings and values that violate their type invariants.
  • Picked up the ledger 8.1.2 crate set, including the direct dependencies midnight-zswap 8.1.2, midnight-onchain-runtime 3.1.1, midnight-storage 2.0.3, midnight-storage-core 1.2.1, and midnight-serialize 1.1.1.
  • Cleared npm audit findings in the toolkit image JavaScript dependencies: toml 4.3.0 through an override, nanoid 3.3.19, turbo 2.9.14, and vitest 4.1.11.
  • Fixed a toolkit-js stack overflow on Node.js 24.15 and later, where the module resolve hook re-entered itself.
  • Left the runtime at 1.0.0, so you do not need a runtime upgrade.

New features​

No new features in this release.


Breaking changes​

No breaking changes to the node interface. The runtime remains at 1.0.0, so you do not need a runtime upgrade.

Ledger 8.1.2 decodes more strictly, so a node on 8.1.2 rejects some data that a node on 8.1.1 accepted. The stricter decoding affects only maliciously formed transactions and rejects nothing that indexers, wallets, or SDKs have already ingested. Validator sets that mix 8.1.1 and 8.1.2 nodes are safe. See the ledger v8.1.2 release notes for the per-crate rules.


Bug fixes and quality improvements​

Ledger 8.1.2​

The ledger 8 pin moves from 8.1.1 to 8.1.2. The release:

  • Hardens low-level deserialization across the serialize, base-crypto, storage, onchain-state, onchain-vm, and transient-crypto crates.
  • Guards DustParameters::time_to_cap against a zero generation_decay_rate.
  • Uses saturating arithmetic for DUST sequence increments and for delta accumulation in normalize_deltas.
  • Stops Zswap binding randomness extraction from panicking on a proof preimage with no witness.
  • Counts contract call public inputs through ContractCall::public_inputs_len instead of materializing them.

Toolkit dependency advisories​

#2179 clears the npm audit findings in the JavaScript dependencies that ship in the toolkit image. toml moves to 4.3.0 through an npm override (GHSA-82x6-q7mm-w9cf, GHSA-v5mp-jgw5-2x6j), nanoid to 3.3.19 (GHSA-2v37-7h3g-55p8), turbo to 2.9.14, and vitest to 4.1.11.

Toolkit resolve hook on Node.js 24.15 and later​

The toolkit-js build and test stages move from Node.js 23.11.0 to Node.js 24.21.0. From Node.js 24.15, the CommonJS require.resolve call inside toolkit-js goes through module.registerHooks, so the resolve hook re-entered itself for the same bare specifier until the stack overflowed. The hook now skips interception for a specifier it is already resolving, so default resolution finishes. The published toolkit image runs Node.js 22.22.0, outside the affected range. (#2179)


Known issues​

  • Node v1.0.2 cannot run runtime 1.0.300, which Preview, Preprod, and Mainnet now use. Run node v1.0.300 on those networks.
  • Toolkit 1.0.0 fails with UnsupportedBlockVersion(1000300) on blocks produced by runtime 1.0.300. Use toolkit 1.0.300 on Preview, Preprod, and Mainnet.
  • The block timestamp (tblock) correction for midnight-node#1924 is not in this release. It ships in node v1.0.300, where the on-chain runtime version controls when it applies.