github Consensys-Incorporated/web3signer 26.9.0-RC1

pre-release2 hours ago

Features Added

  • Scheduled the Glamsterdam (Gloas) upgrade on Sepolia for epoch 353024 (October 6, 2026 13:53:36 UTC). #1240
  • Signing support for the upcoming Glamsterdam (GLOAS / ePBS) fork, matching remote-signing-api v1.4.0. #1192
  • Unstable CLI options (names beginning --X) are now listed by web3signer -X (or --Xhelp), grouped by the command they belong to. web3signer eth2 -X lists only the eth2 unstable options. #1228
  • Azure Key Vault connections are now cached per credential/vault set instead of rebuilt on every key load, reducing bulk-load time. #1222
  • Vert.x is upgraded to 5.2.0 and web3j to 6.0.0, together with the other dependencies and build plugins. #1231

Bugs Fixed

  • Azure Key Vault SECP256K1 signing now uses one official Azure SDK CryptographyClient per key instead of REST workaround. #1222
  • Netty is upgraded to 4.2.17.Final to prevent io_uring read stalls on reused connections.#1222
  • eth_signTransaction for EIP-4844 transactions now returns the canonical signed transaction (0x03 || rlp([...])) instead of wrapping it in a blob network wrapper with empty sidecar lists. #1231
  • HTTP API errors (Key Manager, signing, reload, unknown paths) now return application/json with a {"code": <status>, "message": "..."} body instead of plain text or HTML. A host allow-list rejection on the eth1 JSON-RPC endpoint (POST /) returns that body too, instead of an id-less -32603 JSON-RPC envelope. eth1 JSON-RPC responses now send Content-Type: application/json instead of the misspelled Content header. #1235

Breaking Changes

  • The http_vertx_worker_pool_rejected_total metric is no longer exported, because Vert.x 5 does not report rejected worker tasks separately (they only occur once a pool has shut down). The bundled Grafana dashboard now charts worker queue delay instead. #1231
  • POST /reload responses now use the shared {"code": <status>, "message": "..."} body: 202 returns "code": 202 instead of "status": "accepted", and 409 returns "code": 409 instead of "status": "error". GET /reload is unchanged. #1235

CI/Build Enhancements

  • Azure Key Vault acceptance tests now run against local Azure emulator instance instead of live Azure.
  • OWASP dependency-check runs nightly again, scanning only the dependencies shipped in the distribution (runtimeClasspath) and publishing findings to GitHub code scanning. The NVD database is cached between runs and rebuilt weekly; the run fails if the NVD data is more than 48 hours old. Stale suppressions were removed and current false positives documented. #1237

Security

  • Docker base images re-pinned to their current multi-platform index digests. #1230
  • Default image ships ubuntu:26.04 + Eclipse Temurin JRE 25.0.4; distroless image ships Java 25.0.4 on gcr.io/distroless/java25-debian13:nonroot. #1230

Downloads

Binaries

Binary Checksum
web3signer.tar.gz Checksum
web3signer.zip Checksum

Docker

Default image (Ubuntu + Eclipse Temurin JRE 25):
docker pull consensys/web3signer:26.9.0-RC1

Hardened image (Google Distroless, read-only-filesystem compatible):
docker pull consensys/web3signer:26.9.0-RC1-distroless

Verify

Binaries, with the GitHub CLI:

# the file is the one published with this release
gh release verify-asset 26.9.0-RC1 web3signer-26.9.0-RC1.tar.gz --repo Consensys-Incorporated/web3signer
# the file was built by this repository's CI workflow
gh attestation verify web3signer-26.9.0-RC1.tar.gz --repo Consensys-Incorporated/web3signer

Docker images: see Verifying image signatures and attestations.


Full Changelog: 26.7.0...26.9.0-RC1

Don't miss a new web3signer release

NewReleases is sending notifications on new releases.