github Ride-The-Lightning/RTL v0.15.13
Release v0.15.13-beta

3 hours ago

0.15.13 is primarily a request-validation and clean-up release: RTL now checks the values it forwards to LND, Core Lightning, Eclair and Loop before they leave, the Boltz integration is removed, and two first-login problems are fixed. Operators who still have Boltz settings in their config have nothing to do, but will see a one-line notice at start-up; see below.

Full detail, entry by entry, in release-notes/Release-notes-0.15.13.md.

Boltz integration removed

Boltz suspended its swap service in August 2026 and it has not returned, so the integration could neither create a swap nor be tested. The Services > Boltz pages, the /api/boltz endpoints and the boltzServerUrl / boltzMacaroonPath settings are gone (#1726, closes #1724).

A config file or environment that still sets boltzServerUrl, boltzMacaroonPath, BOLTZ_SERVER_URL or BOLTZ_MACAROON_PATH keeps working. RTL ignores those settings and prints one line at start-up saying so; they can be deleted, and a bundled boltz-client container is no longer used by RTL.

Values are checked before they are forwarded to the node

Several handlers passed request values on to the node as they arrived. They now check the value's form first and answer 400 otherwise:

  • LND: query parameters are built through the request wrapper and omitted when absent, instead of being sent as the string undefined (#1713, fixes #1698); path values for node, channel and route lookups, payment decode and lookup, and peer disconnect must be a public key, channel id, amount, payment request or payment hash (#1722); channel backup, verify and restore accept only a channel point or ALL, and an invalid one can no longer stop the process (#1718).
  • Loop: each request builds its options from the selected node, so on a multi-node RTL a Loop call no longer goes to another node's swap server, and a missing swap server URL is reported as such (#1715, fixes #1714).
  • Core Lightning: the invoice fetched for a BOLT 12 offer is validated before it is paid (#1720).
  • Core Lightning and Eclair: the payments list and the sent-payments info list ask the node for at most 20 entries at a time, each with the request's own options, instead of all at once (#1725). The LND payment-request list does the same (#1722).

Login and first-run fixes

  • The first login no longer fails with "Invalid CSRF token" when RTL is entered at /rtl/ (#1711, fixes #1710).
  • On a multi-node setup the node dropdown now appears after the first login; it stayed hidden after a default-password login, or when a node had index 0 or string indexes in the config (#1600, thanks @CosimoRicciardi).
  • An LND wallet can be initialised through RTL with any seed passphrase. Passphrases whose encoded form holds + or / used to fail; the passphrase now travels in the request body, and the wallet requests check their password and passphrase input (#1728, #1729).

Code health and tooling

A batched dependency pass (#1727) resolved the open Dependabot alerts: the Angular framework moves to 20.3.33 and the CLI line to 20.3.37 within v20, axios to 1.20.0, and hono, js-yaml, ip-address and other transitive packages to their fixed versions. Production dependencies are clean at 0; the six remaining findings are dev-only build tooling under Angular's v20 builder, which only an Angular 22 migration moves.

The backend regression suite grew from 159 to 275 tests this cycle and the frontend specs from 230 to 248. The docker regtest fixture's Core Lightning node moves to v26.06.8 (#1717).

Verification

The branch was verified as a whole at its tip, not just per PR:

  • npm run lint clean; 275/275 backend tests; 248/248 frontend Karma specs
  • Committed backend/ and frontend/ artifacts reproduce byte-for-byte from a clean install and build
  • End-to-end against the docker regtest fixture running an image built from the tip: 66/66 API checks across LND, Core Lightning and Eclair, including node switching and real payments through RTL, and the BTCPay SSO harness at 16/16; 22 pages across the three implementations rendered in a browser with no console errors or failed API calls
  • npm audit --omit=dev: 0 vulnerabilities (full audit 6, all dev-only build tooling)

Contributors:
@CosimoRicciardi @saubyk


PGP Key: https://keybase.io/suheb
Retrieve the source code repository, check for the latest release and verify the code signature

$ git clone https://github.com/Ride-The-Lightning/RTL.git
$ cd RTL

$ git checkout v0.15.12

$ git verify-tag v0.15.13
gpg: Signature made Thu Oct  1 11:25:39 2026 PDT
gpg:                using RSA key 3E9BD4436C288039CA827A9200C9E2BC2E45666F
gpg: Good signature from "saubyk (added uid) <39208279+saubyk@users.noreply.github.com>" [ultimate]
gpg:                 aka "Suheb <39208279+saubyk@users.noreply.github.com>" [ultimate]
gpg:                 aka "RTL Security <security@ridethelightning.info>" [ultimate]

Install RTL via npm

npm ci --omit=dev --legacy-peer-deps

Docker images available at https://hub.docker.com/r/shahanafarooqui/rtl/tags

Don't miss a new RTL release

NewReleases is sending notifications on new releases.