cleaning reown previous folder
What changed, and why it matters
This commit changes an Android build script to delete leftover files from a previous download before downloading a fresh copy of a software package called reown_flutter. On its own, this is a routine cleanup step in a CI/CD build pipeline. There is no direct evidence in the commit that it fixes a security vulnerability, but it removes a potential source of stale or tampered files being reused accidentally during builds.
Treat as a low-risk build-hardening change. If reviewing supply-chain security, verify whether the downloaded `reown_flutter.tar.gz` is validated against a checksum or signature before use, and confirm the release source is trusted. No immediate incident response is indicated by this commit alone.
Security signals we found
Build hygiene: removes potentially stale dependency artifacts before re-downloading
Supply-chain adjacent: touches how an external dependency archive is fetched in CI
No integrity verification (checksum/signature) is visible in the surrounding workflow
Evidence from the diff
The diff adds rm -rf reown_flutter and rm -f reown_flutter.tar.gz before a wget and extraction step in .github/workflows/pr_test_build_android.yml. This ensures the build job starts from a clean state when fetching the reown_flutter dependency from a Cake Wallet-controlled GitHub release. The change reduces the risk of stale cached artifacts influencing the build, but does not by itself address a demonstrated vulnerability in the dependency, the download, or the workflow.
Changed components
.github/workflows/pr_test_build_android.ymlInspect captured patch +4 / −0
diff --git a/.github/workflows/pr_test_build_android.yml b/.github/workflows/pr_test_build_android.yml
index 02f6e1b4..3442111a 100644
--- a/.github/workflows/pr_test_build_android.yml
+++ b/.github/workflows/pr_test_build_android.yml
@@ -212,6 +212,10 @@ jobs:
run: |
set -x -e
pushd scripts
+ # cleaning
+ rm -rf reown_flutter
+ rm -f reown_flutter.tar.gz
+
wget https://github.com/cake-tech/reown_flutter/releases/download/v0.0.4/reown_flutter-v0.0.4.tar.gz -O reown_flutter.tar.gz
mkdir reown_flutter
pushd reown_flutter
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.