AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 24 Monero

fix: downgrade and fork reown (#2566)

Public commit record

What the developer wrote

Authored by cyan

100/100 · Strong
fix: downgrade and fork reown (#2566)

Due to reown changing their license in version
1.2.0 we switched to use last open source release
of reown with all fixes for flutter 3.32.0 and
16kb page size requirements.

chore: drop dependency overrides for reown
ci: switch prebuilds to use github releases instead of CDN
fix: reown socket errors in onDone and onError
fix: remove flutter_secure_storage on linux (closes #2577, #2561)
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes how Cake Wallet builds and bundles a third-party library called Reown. The stated reason is a license change in Reown's upstream version 1.2.0, so the project switches to its own forked/prebuilt release. The diff also removes a Linux secure-storage plugin and updates many iOS dependency checksums. There is no direct evidence in the commit of a security vulnerability being fixed or introduced, but any change to how sensitive wallet libraries are fetched, built, and distributed deserves careful review because it touches code that handles cryptographic wallet operations.

Recommended action

Treat this as a supply-chain and build-hygiene change rather than a confirmed vulnerability. Reviewers should verify the pinned hash in cake-tech/reown_flutter, inspect the contents of the v0.0.4 release tarball and generate_all.sh, confirm reproducibility of the native builds, and audit whether removing flutter_secure_storage on Linux leaves secrets in a less protected storage location. No immediate exploit mitigation is indicated by the diff itself.

Security signals we found

01

Switches supply-chain source for a security-sensitive library (Reown/WalletKit) from upstream pub package to a forked repository and prebuilt GitHub release

02

Removes CDN-downloaded native binaries in favor of GitHub release tarballs; both are remote artifact fetches during CI

03

Pins forked source to a specific git hash, which is a positive supply-chain practice

04

Removes flutter_secure_storage on Linux, which may affect how secrets are stored on that platform

05

Large number of iOS Pod checksum changes suggest a broad dependency refresh, increasing risk of unexpected transitive changes

06

No CVE, advisory, or vendor security disclosure is present in the supplied materials

Risk score

Why this scored 24/100

Our methodology →
Potential impact 5/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 5/15
Confidence 5/10
Evidence quality 2/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.