bump breez_sdk_spark_flutter to v0.14.0 (#3245)
What changed, and why it matters
This commit updates a Lightning payment library (breez_sdk_spark_flutter) from version 0.11.0 to 0.14.0 and makes small matching code changes. It also fixes one app crash bug where the wallet tried to read a parsed address before checking whether an address had actually been parsed. The crash fix is a straightforward stability improvement; the library bump itself is a routine dependency update whose security implications are not described in the commit.
Treat as a routine dependency and stability patch. Review the Breez SDK v0.14.0 release notes separately for any security fixes included in the upstream upgrade, since the commit itself does not disclose them. Verify the crash guard covers all code paths that access parsed addresses.
Security signals we found
Dependency version bump of Lightning SDK (breez_sdk_spark_flutter 0.11.0 -> 0.14.0)
Null/empty-list guard added before accessing parsed address list
No explicit security claims or CVE references in commit
Evidence from the diff
The diff bumps the Breez SDK Spark Flutter dependency from v0.11.0 to v0.14.0 across pubspec.yaml, pubspec.lock, and the iOS Podfile.lock. API changes in the SDK renamed the amountSats parameter to amount in PrepareLnurlPayRequest, so two call sites in cw_bitcoin/lib/lightning/lightning_wallet.dart are updated. In lib/new-ui/widgets/send_page/send_confirm_sheet.dart, the code that decides whether to show a recipient address now guards access to e.parsedAddress.addresses.first with e.isParsedAddress && e.parsedAddress.addresses.isNotEmpty, preventing a possible null/empty-list access. No security-relevant explanation is provided by the vendor in the commit message or title.
Changed components
cw_bitcoin/lib/lightning/lightning_wallet.dartcw_bitcoin/pubspec.yamlcw_bitcoin/pubspec.lockios/Podfile.locklib/new-ui/widgets/send_page/send_confirm_sheet.dartInspect captured patch +15 / −11
diff --git a/cw_bitcoin/lib/lightning/lightning_wallet.dart b/cw_bitcoin/lib/lightning/lightning_wallet.dart
index 91890d20..deef7204 100644
--- a/cw_bitcoin/lib/lightning/lightning_wallet.dart
+++ b/cw_bitcoin/lib/lightning/lightning_wallet.dart
@@ -213,14 +213,14 @@ class LightningWallet {
PrepareLnurlPayRequest request;
if (inputType is InputType_LightningAddress) {
request = PrepareLnurlPayRequest(
- amountSats: amountSats!,
+ amount: amountSats!,
payRequest: inputType.field0.payRequest,
validateSuccessActionUrl: optionalValidateSuccessActionUrl,
feePolicy: feePolicy,
);
} else {
request = PrepareLnurlPayRequest(
- amountSats: amountSats!,
+ amount: amountSats!,
payRequest: (inputType as InputType_LnurlPay).field0,
validateSuccessActionUrl: optionalValidateSuccessActionUrl,
feePolicy: feePolicy,
diff --git a/cw_bitcoin/pubspec.lock b/cw_bitcoin/pubspec.lock
index 4d33cf36..b7e893e9 100644
--- a/cw_bitcoin/pubspec.lock
+++ b/cw_bitcoin/pubspec.lock
@@ -134,11 +134,11 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: "v0.11.0"
- resolved-ref: "4a6110477c526ddf236c6b5d4ad064802062f5ad"
+ ref: "v0.14.0"
+ resolved-ref: e18b6437daaf0572de6aea2439c2ec4d22658bbb
url: "https://github.com/breez/breez-sdk-spark-flutter"
source: git
- version: "0.11.0"
+ version: "0.14.0"
bs58check:
dependency: transitive
description:
diff --git a/cw_bitcoin/pubspec.yaml b/cw_bitcoin/pubspec.yaml
index d58919ea..28e99f48 100644
--- a/cw_bitcoin/pubspec.yaml
+++ b/cw_bitcoin/pubspec.yaml
@@ -72,7 +72,7 @@ dependencies:
breez_sdk_spark_flutter:
git:
url: https://github.com/breez/breez-sdk-spark-flutter
- ref: v0.11.0
+ ref: v0.14.0
dev_dependencies:
flutter_test:
diff --git a/ios/Podfile.lock b/ios/Podfile.lock
index fef7209a..e661632c 100644
--- a/ios/Podfile.lock
+++ b/ios/Podfile.lock
@@ -1,6 +1,8 @@
PODS:
- bitbox_flutter (0.0.1):
- Flutter
+ - breez_sdk_spark_flutter (0.14.0):
+ - Flutter
- connectivity_plus (0.0.1):
- Flutter
- CryptoSwift (1.8.4)
@@ -252,8 +254,9 @@ EXTERNAL SOURCES:
:path: ".symlinks/plugins/wakelock_plus/ios"
SPEC CHECKSUMS:
- bitbox_flutter: 506f80b961ddf646b0d80cef9f6eadaab96d91b0
- connectivity_plus: 2a701ffec2c0ae28a48cf7540e279787e77c447d
+ bitbox_flutter: 9505732798041c413152669751beeaecc5fe400f
+ breez_sdk_spark_flutter: ed3b6709b8ce9b40309d8728640eade5b19e8a0d
+ connectivity_plus: cb623214f4e1f6ef8fe7403d580fdad517d2f7dd
CryptoSwift: e64e11850ede528a02a0f3e768cec8e9d92ecb90
device_display_brightness: 1510e72c567a1f6ce6ffe393dcd9afd1426034f7
device_info_plus: c6fb39579d0f423935b0c9ce7ee2f44b71b9fce6
diff --git a/lib/new-ui/widgets/send_page/send_confirm_sheet.dart b/lib/new-ui/widgets/send_page/send_confirm_sheet.dart
index d793216d..853a82ad 100644
--- a/lib/new-ui/widgets/send_page/send_confirm_sheet.dart
+++ b/lib/new-ui/widgets/send_page/send_confirm_sheet.dart
@@ -15,7 +15,6 @@ import 'package:cw_core/crypto_amount_format.dart';
import 'package:cw_core/crypto_currency.dart';
import 'package:flutter/material.dart';
import 'package:flutter_mobx/flutter_mobx.dart';
-import 'package:flutter_svg/flutter_svg.dart';
import 'package:mobx/mobx.dart';
class SendConfirmSheet extends StatefulWidget {
@@ -216,8 +215,10 @@ class SendTransactionDetails extends StatelessWidget {
final showAddress = !sendViewModel.outputs.any((e) =>
RegExp(AddressValidator.bolt11InvoiceMatcher).hasMatch(e.address.toLowerCase()) ||
RegExp(AddressValidator.lnurlMatcher).hasMatch(e.address.toLowerCase()) ||
- RegExp(AddressValidator.lnurlMatcher)
- .hasMatch(e.parsedAddress.addresses.first.toLowerCase()));
+ (e.isParsedAddress &&
+ e.parsedAddress.addresses.isNotEmpty &&
+ RegExp(AddressValidator.lnurlMatcher)
+ .hasMatch(e.parsedAddress.addresses.first.toLowerCase())));
final outputs = sendViewModel.outputs;
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.