Node v1.0.2 release notes
For the complete documentation index, see llms.txt
- Version: v1.0.2
- Date: September 18, 2026
- Components:
node-1.0.2,toolkit-1.0.0,runtime-1.0.0
Preview, Preprod, and Mainnet now run runtime 1.0.300 (spec_version 1_000_300). That runtime imports version 2 Ledger8Bridge host functions that node v1.0.2 does not provide, so a v1.0.2 node cannot import blocks from that runtime upgrade onward. Toolkit 1.0.0, which ships with this release, also fails with UnsupportedBlockVersion(1000300) on blocks from that runtime. Run node v1.0.300 and toolkit 1.0.300 on these networks. They include every change in this release.
Docker images
docker pull midnightntwrk/midnight-node:1.0.2
docker pull midnightntwrk/midnight-node-toolkit:1.0.0
The toolkit version number is unchanged, but the midnight-node-toolkit:1.0.0 image was rebuilt for this release and carries the dependency fixes described below. Pull the tag again to pick them up.
High-level summary
Node v1.0.2 is a small dependency and security patch on the v1.0.0 GA line. It moves the ledger 8 dependency to the ledger 8.1.2 security release. It also clears npm audit findings in the toolkit image and fixes a toolkit-js stack overflow on Node.js 24.15 and later.
No pallet or runtime code changed. The runtime stays at 1.0.0 with spec_version 1_000_000 and transaction_version 3, so this is a binary-only upgrade with no runtime upgrade or governance action.
The changes below are the delta from v1.0.1. For the full diff, see the comparison between the two tags.
Audience
This release note is relevant for users who:
- Run a node on the 1.0.x line and want to know what changed between v1.0.1 and v1.0.2.
- Run the node toolkit image and scan it for npm advisories.
- Build or run
toolkit-jsfrom source on Node.js 24.15 or later, where it previously overflowed the stack.
DApp developers do not need to take any action for this release.
What changed (Summary of updates)
The updates below describe the key changes introduced in this release.
- Moved the ledger 8 dependency from 8.1.1 to 8.1.2, a security release that rejects non-canonical encodings and values that violate their type invariants.
- Picked up the ledger 8.1.2 crate set, including the direct dependencies
midnight-zswap8.1.2,midnight-onchain-runtime3.1.1,midnight-storage2.0.3,midnight-storage-core1.2.1, andmidnight-serialize1.1.1. - Cleared
npm auditfindings in the toolkit image JavaScript dependencies:toml4.3.0 through an override,nanoid3.3.19,turbo2.9.14, andvitest4.1.11. - Fixed a
toolkit-jsstack overflow on Node.js 24.15 and later, where the module resolve hook re-entered itself. - Left the runtime at 1.0.0, so you do not need a runtime upgrade.
New features
No new features in this release.
Breaking changes
No breaking changes to the node interface. The runtime remains at 1.0.0, so you do not need a runtime upgrade.
Ledger 8.1.2 decodes more strictly, so a node on 8.1.2 rejects some data that a node on 8.1.1 accepted. The stricter decoding affects only maliciously formed transactions and rejects nothing that indexers, wallets, or SDKs have already ingested. Validator sets that mix 8.1.1 and 8.1.2 nodes are safe. See the ledger v8.1.2 release notes for the per-crate rules.
Bug fixes and quality improvements
Ledger 8.1.2
The ledger 8 pin moves from 8.1.1 to 8.1.2. The release:
- Hardens low-level deserialization across the
serialize,base-crypto,storage,onchain-state,onchain-vm, andtransient-cryptocrates. - Guards
DustParameters::time_to_capagainst a zerogeneration_decay_rate. - Uses saturating arithmetic for DUST sequence increments and for delta accumulation in
normalize_deltas. - Stops Zswap binding randomness extraction from panicking on a proof preimage with no witness.
- Counts contract call public inputs through
ContractCall::public_inputs_leninstead of materializing them.
Toolkit dependency advisories
#2179 clears the npm audit findings in the JavaScript dependencies that ship in the toolkit image. toml moves to 4.3.0 through an npm override (GHSA-82x6-q7mm-w9cf, GHSA-v5mp-jgw5-2x6j), nanoid to 3.3.19 (GHSA-2v37-7h3g-55p8), turbo to 2.9.14, and vitest to 4.1.11.
Toolkit resolve hook on Node.js 24.15 and later
The toolkit-js build and test stages move from Node.js 23.11.0 to Node.js 24.21.0. From Node.js 24.15, the CommonJS require.resolve call inside toolkit-js goes through module.registerHooks, so the resolve hook re-entered itself for the same bare specifier until the stack overflowed. The hook now skips interception for a specifier it is already resolving, so default resolution finishes. The published toolkit image runs Node.js 22.22.0, outside the affected range. (#2179)
Known issues
- Node v1.0.2 cannot run runtime 1.0.300, which Preview, Preprod, and Mainnet now use. Run node v1.0.300 on those networks.
- Toolkit 1.0.0 fails with
UnsupportedBlockVersion(1000300)on blocks produced by runtime 1.0.300. Use toolkit 1.0.300 on Preview, Preprod, and Mainnet. - The block timestamp (
tblock) correction for midnight-node#1924 is not in this release. It ships in node v1.0.300, where the on-chain runtime version controls when it applies.