Dockerfiles: fetch dependencies over https instead of git:// / http://
What changed, and why it matters
This commit changes how the Monero GUI's release build containers download some important software libraries. Previously, several libraries were downloaded over unencrypted or unauthenticated connections (git:// and http://), which could allow a network attacker to tamper with the downloaded code before it was compiled into Monero's release binaries. The commit switches those downloads to https, which provides encryption and server authentication. The commit message explicitly notes that the Qt library was only pinned by tag, so a man-in-the-middle attacker could have substituted malicious Qt source code into the build. The other libraries (libgpg-error, libgcrypt, libiconv) had additional integrity checks (commit hash pins or sha256sum), so the practical risk there was lower, but the change still removes an unnecessary weak link.
Verify that the new https URLs resolve to the same upstream repositories and that the build still succeeds. Consider adding commit-hash pinning for Qt clones (as already done for libgpg-error/libgcrypt) and enabling git's transfer.fsckObjects or similar verification. Review other Dockerfiles and build scripts for remaining git:// or http:// dependency fetches. No immediate user action is required, but release builders should ensure they rebuild with this commit included.
Security signals we found
Unauthenticated git:// protocol used for source code retrieval
Unencrypted http:// used for source tarball retrieval
Qt source cloned by tag only, without commit-pin verification before build
Build-time dependency integrity improvement
Supply-chain / build pipeline hardening
Evidence from the diff
The patch updates Dockerfiles used to produce Android, Linux, and Windows release builds of the Monero GUI. It replaces git://code.qt.io and git://git.gnupg.org clone URLs with https:// equivalents, and replaces an http:// wget of libiconv with https://. For Qt, the clone uses –depth 1 and a branch/tag name (${QT_VERSION}), so the git protocol offered no transport-level integrity; an active MITM could present arbitrary repository contents. For libgpg-error and libgcrypt, the build later runs git reset –hard
Changed components
Dockerfile.androidDockerfile.linuxDockerfile.windowsQt5 build dependency retrievallibgpg-error build dependency retrievallibgcrypt build dependency retrievallibiconv build dependency retrievalInspect captured patch +33 / −33
diff --git a/Dockerfile.android b/Dockerfile.android
index 7e3189c..daa0acc 100644
--- a/Dockerfile.android
+++ b/Dockerfile.android
@@ -56,7 +56,7 @@ RUN wget -q https://github.com/madler/zlib/releases/download/v${ZLIB_VERSION}/zl
&& make -j${THREADS} install \
&& rm -rf $(pwd)
-RUN git clone git://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 \
+RUN git clone https://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 \
&& cd qt5 \
&& perl init-repository --module-subset=default,-qtwebengine \
&& PATH=${HOST_PATH} ./configure -v -developer-build -release \
@@ -90,7 +90,7 @@ RUN git clone git://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 \
ARG ICONV_VERSION=1.16
ARG ICONV_HASH=e6a1b1b589654277ee790cce3734f07876ac4ccfaecbee8afa0b649cf529cc04
-RUN wget -q http://ftp.gnu.org/pub/gnu/libiconv/libiconv-${ICONV_VERSION}.tar.gz \
+RUN wget -q https://ftp.gnu.org/pub/gnu/libiconv/libiconv-${ICONV_VERSION}.tar.gz \
&& echo "${ICONV_HASH} libiconv-${ICONV_VERSION}.tar.gz" | sha256sum -c \
&& tar -xzf libiconv-${ICONV_VERSION}.tar.gz \
&& rm -f libiconv-${ICONV_VERSION}.tar.gz \
@@ -179,7 +179,7 @@ RUN set -ex \
&& make -j${THREADS} install \
&& rm -rf $(pwd)
-RUN git clone -b libgpg-error-1.41 --depth 1 git://git.gnupg.org/libgpg-error.git \
+RUN git clone -b libgpg-error-1.41 --depth 1 https://dev.gnupg.org/source/libgpg-error.git \
&& cd libgpg-error \
&& git reset --hard 98032624ae89a67ee6fe3b1db5d95032e681d163 \
&& ./autogen.sh \
@@ -188,7 +188,7 @@ RUN git clone -b libgpg-error-1.41 --depth 1 git://git.gnupg.org/libgpg-error.gi
&& make -j${THREADS} install \
&& rm -rf $(pwd)
-RUN git clone -b libgcrypt-1.10.1 --depth 1 git://git.gnupg.org/libgcrypt.git \
+RUN git clone -b libgcrypt-1.10.1 --depth 1 https://dev.gnupg.org/source/libgcrypt.git \
&& cd libgcrypt \
&& git reset --hard ae0e567820c37f9640440b3cff77d7c185aa6742 \
&& ./autogen.sh \
diff --git a/Dockerfile.linux b/Dockerfile.linux
index dc5795c..1e08748 100644
--- a/Dockerfile.linux
+++ b/Dockerfile.linux
@@ -188,20 +188,20 @@ RUN wget https://www.nlnetlabs.nl/downloads/unbound/unbound-1.16.2.tar.gz && \
RUN rm /usr/lib/x86_64-linux-gnu/libX11.a && \
rm /usr/lib/x86_64-linux-gnu/libXext.a && \
rm /usr/lib/x86_64-linux-gnu/libX11-xcb.a && \
- git clone git://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 && \
cd qt5 && \
- git clone git://code.qt.io/qt/qtbase.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtdeclarative.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtgraphicaleffects.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtimageformats.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtmultimedia.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtquickcontrols.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtquickcontrols2.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtsvg.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qttools.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qttranslations.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtx11extras.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtxmlpatterns.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtbase.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtdeclarative.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtgraphicaleffects.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtimageformats.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtmultimedia.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtquickcontrols.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtquickcontrols2.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtsvg.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qttools.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qttranslations.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtx11extras.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtxmlpatterns.git -b ${QT_VERSION} --depth 1 && \
sed -ri s/\(Libs:.*\)/\\1\ -lexpat/ /usr/local/lib/pkgconfig/fontconfig.pc && \
sed -ri s/\(Libs:.*\)/\\1\ -lz/ /usr/local/lib/pkgconfig/freetype2.pc && \
sed -ri s/\(Libs:.*\)/\\1\ -lXau/ /usr/local/lib/pkgconfig/xcb.pc && \
@@ -251,7 +251,7 @@ RUN git clone -b v4.3.4 --depth 1 https://github.com/zeromq/libzmq && \
make -j$THREADS install && \
rm -rf $(pwd)
-RUN git clone -b libgpg-error-1.45 --depth 1 git://git.gnupg.org/libgpg-error.git && \
+RUN git clone -b libgpg-error-1.45 --depth 1 https://dev.gnupg.org/source/libgpg-error.git && \
cd libgpg-error && \
git reset --hard dbac537e5e865fb6f3aa8596d213aa8c47a9dea1 && \
./autogen.sh && \
@@ -260,7 +260,7 @@ RUN git clone -b libgpg-error-1.45 --depth 1 git://git.gnupg.org/libgpg-error.gi
make -j$THREADS install && \
rm -rf $(pwd)
-RUN git clone -b libgcrypt-1.10.1 --depth 1 git://git.gnupg.org/libgcrypt.git && \
+RUN git clone -b libgcrypt-1.10.1 --depth 1 https://dev.gnupg.org/source/libgcrypt.git && \
cd libgcrypt && \
git reset --hard ae0e567820c37f9640440b3cff77d7c185aa6742 && \
./autogen.sh && \
diff --git a/Dockerfile.windows b/Dockerfile.windows
index 0754270..2c760c6 100644
--- a/Dockerfile.windows
+++ b/Dockerfile.windows
@@ -21,19 +21,19 @@ RUN git clone -b v0.18.5.0 --depth 1 https://github.com/monero-project/monero &&
RUN make -j$THREADS -C /depends HOST=x86_64-w64-mingw32 NO_QT=1
-RUN git clone git://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 && \
+RUN git clone https://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 && \
cd qt5 && \
- git clone git://code.qt.io/qt/qtbase.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtdeclarative.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtgraphicaleffects.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtimageformats.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtmultimedia.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtquickcontrols.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtquickcontrols2.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtsvg.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qttools.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qttranslations.git -b ${QT_VERSION} --depth 1 && \
- git clone git://code.qt.io/qt/qtxmlpatterns.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtbase.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtdeclarative.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtgraphicaleffects.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtimageformats.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtmultimedia.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtquickcontrols.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtquickcontrols2.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtsvg.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qttools.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qttranslations.git -b ${QT_VERSION} --depth 1 && \
+ git clone https://code.qt.io/qt/qtxmlpatterns.git -b ${QT_VERSION} --depth 1 && \
./configure --prefix=/depends/x86_64-w64-mingw32 -xplatform win32-g++ \
-device-option CROSS_COMPILE=/usr/bin/x86_64-w64-mingw32- \
-I $(pwd)/qtbase/src/3rdparty/angle/include \
@@ -58,7 +58,7 @@ RUN git clone git://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 && \
cd ../../../.. && \
rm -rf $(pwd)
-RUN git clone -b libgpg-error-1.38 --depth 1 git://git.gnupg.org/libgpg-error.git && \
+RUN git clone -b libgpg-error-1.38 --depth 1 https://dev.gnupg.org/source/libgpg-error.git && \
cd libgpg-error && \
git reset --hard 71d278824c5fe61865f7927a2ed1aa3115f9e439 && \
./autogen.sh && \
@@ -69,7 +69,7 @@ RUN git clone -b libgpg-error-1.38 --depth 1 git://git.gnupg.org/libgpg-error.gi
cd .. && \
rm -rf libgpg-error
-RUN git clone -b libgcrypt-1.8.5 --depth 1 git://git.gnupg.org/libgcrypt.git && \
+RUN git clone -b libgcrypt-1.8.5 --depth 1 https://dev.gnupg.org/source/libgcrypt.git && \
cd libgcrypt && \
git reset --hard 56606331bc2a80536db9fc11ad53695126007298 && \
./autogen.sh && \
Why this scored 60/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.