lightningnetwork/lightning-onion
68.2
Adequate · 21 September 2026
2.8k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based implementation of the Lightning Network's Sphinx onion routing protocol, providing core cryptographic primitives, replay protection, and route blinding capabilities. It includes a command-line interface for generating and decoding onion packets, alongside automated CI scripts to enforce Go version consistency across the project's build environment.
Features
Add CLI tool for generating and decoding Lightning Network onion packets
A new command-line utility (sphinx-cli) is introduced in the cmd directory, providing commands to generate new onion packets and peel existing ones. The tool reads input data from JSON files located in cmd/example-data (such as hop-data.json, onion.json, and several onion-blinded variants) and utilizes the Lightning Network's sphinx library to handle the cryptographic operations for routing payloads.
cmd · high confidence
Automated Go version validation for CI
Added two new shell scripts in the scripts directory that enforce a consistent Go version across all Dockerfiles and YAML configuration files. The new check-go-version-dockerfile.sh script scans Dockerfiles to ensure they use the specified Go version, while check-go-version-yaml.sh validates that YAML files (including environment variables like GO\_VERSION) match the required version. These scripts are designed to be integrated into the CI pipeline to prevent version drift.
scripts · high confidence
Initial implementation of the Lightning Network onion routing protocol
The repository now contains a complete implementation of the Sphinx onion routing protocol, including packet construction, processing, and error handling. This adds the core cryptographic primitives, replay protection via a configurable log, and support for variable-sized payloads and route blinding. The codebase also includes a Makefile for building and testing, a .golangci.yml for linting, and comprehensive unit and benchmark tests.
(repo-wide) · high confidence
Dependencies
Modernize Go module configuration and tooling dependencies
The project has been modernized to use Go modules, replacing the legacy glide-based dependency management. The root module now targets Go 1.24.6 and includes updated dependencies such as \github.com/urfave/cli v1.22.9\ and \github.com/btcsuite/btcd/btcec/v2 v2.3.4\. Additionally, a new \tools\ module has been introduced to manage the \golangci-lint\ and \gosimports\ tooling dependencies, establishing a dedicated space for development tooling separate from the main application code.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 67 → 68 (+1.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 97 (-2.6)
- Architecture 100 → 100 (+0.0)
- Maturity 57 → 56 (-0.7)
- Readiness 64 → 65 (+0.4)
- Security 77 → 90 (+12.7)
Resolved (16)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2025-4006 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (tools/go.mod)
- Medium IaC: CKV_DOCKER_3 (tools/Dockerfile)
- No exposed public API
- Test reliability not included
New (40)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/aead/chacha20
- Documentation: no installation or build instructions (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2025-4006 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (tools/go.mod)
- Medium CVE: GO-2026-6179 (tools/go.mod)
- Medium IaC: WD-DOCKER-0003 (tools/Dockerfile)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No ADRs found
- …and 20 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
lightningnetwork/lightning-onion was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3991b0b381405745125b35f6d51da6a216b0a473 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.