What changed, and why it matters
This commit pins the 'grpc' networking library to a specific older version (4.0.1) instead of allowing newer compatible versions. It also downgrades a related Google authentication package from 2.0.0 to 1.6.0. The change appears to be a build-stability or compatibility fix rather than a response to a known security vulnerability, but pinning dependencies can affect which security patches are received in future builds.
Review why grpc was pinned to exactly 4.0.1 and whether newer patch releases (e.g., 4.1.0) contained security fixes that are now being missed. If the pin was for build compatibility, document the reason and monitor grpc release notes for security advisories. Consider whether the googleapis_auth downgrade from 2.0.0 to 1.6.0 is intentional and whether it reintroduces any resolved issues.
Security signals we found
Dependency version pinned from caret range to exact version
Transitive dependency googleapis_auth downgraded from 2.0.0 to 1.6.0
No application code changes or vulnerability description in commit
No CVE, advisory, or security disclosure referenced in commit or supplied materials
Evidence from the diff
The commit changes the Dart/Flutter dependency constraint for ‘grpc’ from ‘^4.0.1’ (which allows 4.x up to but not including 5.0.0) to ‘4.0.1’ (exact version only) in cw_bitcoin and cw_mweb pubspec.yaml files. The pubspec.lock is regenerated, showing grpc pinned to 4.0.1 and googleapis_auth downgraded from 2.0.0 to 1.6.0 as a transitive dependency. No code changes are present. The commit message ‘fixate grpc version’ suggests a dependency stabilization intent.
Changed components
cw_bitcoin/pubspec.yamlcw_mweb/pubspec.yamlcw_bitcoin/pubspec.lockgrpc Dart package (version 4.0.1)googleapis_auth Dart package (transitive, version 1.6.0)Inspect captured patch +6 / −6
diff --git a/cw_bitcoin/pubspec.lock b/cw_bitcoin/pubspec.lock
index 8cc60e9d..ff313360 100644
--- a/cw_bitcoin/pubspec.lock
+++ b/cw_bitcoin/pubspec.lock
@@ -468,10 +468,10 @@ packages:
dependency: transitive
description:
name: googleapis_auth
- sha256: b81fe352cc4a330b3710d2b7ad258d9bcef6f909bb759b306bf42973a7d046db
+ sha256: befd71383a955535060acde8792e7efc11d2fccd03dd1d3ec434e85b68775938
url: "https://pub.dev"
source: hosted
- version: "2.0.0"
+ version: "1.6.0"
graphs:
dependency: transitive
description:
@@ -484,10 +484,10 @@ packages:
dependency: "direct main"
description:
name: grpc
- sha256: "2dde469ddd8bbd7a33a0765da417abe1ad2142813efce3a86c512041294e2b26"
+ sha256: "5b99b7a420937d4361ece68b798c9af8e04b5bc128a7859f2a4be87427694813"
url: "https://pub.dev"
source: hosted
- version: "4.1.0"
+ version: "4.0.1"
hex:
dependency: transitive
description:
diff --git a/cw_bitcoin/pubspec.yaml b/cw_bitcoin/pubspec.yaml
index bd4fe327..942a5069 100644
--- a/cw_bitcoin/pubspec.yaml
+++ b/cw_bitcoin/pubspec.yaml
@@ -32,7 +32,7 @@ dependencies:
ref: cake-update-v2
cw_mweb:
path: ../cw_mweb
- grpc: ^4.0.1
+ grpc: 4.0.1
sp_scanner:
git:
url: https://github.com/cake-tech/sp_scanner
diff --git a/cw_mweb/pubspec.yaml b/cw_mweb/pubspec.yaml
index 300bbd59..02f454dd 100644
--- a/cw_mweb/pubspec.yaml
+++ b/cw_mweb/pubspec.yaml
@@ -10,7 +10,7 @@ environment:
dependencies:
flutter:
sdk: flutter
- grpc: ^4.0.1
+ grpc: 4.0.1
path_provider: ^2.1.2
plugin_platform_interface: ^2.0.2
cw_core:
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.