Dockerfiles: pin Qt to a commit hash
What changed, and why it matters
This change tightens how the Monero GUI's build containers fetch the Qt user-interface library. Previously, the build scripts downloaded Qt using only a version tag (like 'v5.15.19-lts-lgpl'), which could silently point to different code if Qt's maintainers ever moved or re-created that tag. Now the scripts reset the downloaded Qt source to a specific, fixed commit hash, so every release build uses the exact same Qt code. This is a supply-chain hardening fix: it prevents a malicious or accidental tag change from slipping modified Qt code into Monero's official wallets.
Treat this as a positive security hardening commit. Verify that the pinned commit `dc2ac680fa9d0ef7b0d9520859593d13951bedea` corresponds to the intended Qt v5.15.19-lts-lgpl release and that submodule URLs remain on `https://` (as the commit message states). No immediate user action is required; downstream release builders should rebuild containers to incorporate the pinned source.
Security signals we found
Supply-chain / build-integrity hardening
Pinning dependency to immutable commit hash instead of mutable tag
Prevents tag-rewriting or tag-squatting attacks on upstream Qt repository
Reduces non-determinism in release build inputs
Follow-up to prior hardening PR #4613
Evidence from the diff
The Dockerfiles for Android, Linux, and Windows previously cloned qt5 and individual Qt modules with -b ${QT_VERSION} --depth 1, relying on a floating Git tag. The patch pins the qt5 superproject to commit dc2ac680fa9d0ef7b0d9520859593d13951bedea via git reset --hard, then lets the superproject resolve submodules (git submodule update on Linux/Windows, init-repository on Android). This removes per-module shallow clones and ensures reproducible, tag-tamper-resistant Qt builds. The commit message explicitly frames this as closing a gap relative to other dependencies and as a follow-up to PR #4613.
Changed components
Dockerfile.androidDockerfile.linuxDockerfile.windowsQt5 build-time dependency in Monero GUI release containersInspect captured patch +5 / −23
diff --git a/Dockerfile.android b/Dockerfile.android
index daa0acc..c99a8d4 100644
--- a/Dockerfile.android
+++ b/Dockerfile.android
@@ -58,6 +58,7 @@ RUN wget -q https://github.com/madler/zlib/releases/download/v${ZLIB_VERSION}/zl
RUN git clone https://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 \
&& cd qt5 \
+ && git reset --hard dc2ac680fa9d0ef7b0d9520859593d13951bedea \
&& perl init-repository --module-subset=default,-qtwebengine \
&& PATH=${HOST_PATH} ./configure -v -developer-build -release \
-xplatform android-clang \
diff --git a/Dockerfile.linux b/Dockerfile.linux
index 1e08748..588a5a3 100644
--- a/Dockerfile.linux
+++ b/Dockerfile.linux
@@ -190,18 +190,8 @@ RUN rm /usr/lib/x86_64-linux-gnu/libX11.a && \
rm /usr/lib/x86_64-linux-gnu/libX11-xcb.a && \
git clone https://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 && \
cd qt5 && \
- git clone https://code.qt.io/qt/qtbase.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtdeclarative.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtgraphicaleffects.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtimageformats.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtmultimedia.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtquickcontrols.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtquickcontrols2.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtsvg.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qttools.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qttranslations.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtx11extras.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtxmlpatterns.git -b ${QT_VERSION} --depth 1 && \
+ git reset --hard dc2ac680fa9d0ef7b0d9520859593d13951bedea && \
+ git submodule update --init --depth 1 qtbase qtdeclarative qtgraphicaleffects qtimageformats qtmultimedia qtquickcontrols qtquickcontrols2 qtsvg qttools qttranslations qtx11extras qtxmlpatterns && \
sed -ri s/\(Libs:.*\)/\\1\ -lexpat/ /usr/local/lib/pkgconfig/fontconfig.pc && \
sed -ri s/\(Libs:.*\)/\\1\ -lz/ /usr/local/lib/pkgconfig/freetype2.pc && \
sed -ri s/\(Libs:.*\)/\\1\ -lXau/ /usr/local/lib/pkgconfig/xcb.pc && \
diff --git a/Dockerfile.windows b/Dockerfile.windows
index 2c760c6..1e21895 100644
--- a/Dockerfile.windows
+++ b/Dockerfile.windows
@@ -23,17 +23,8 @@ RUN make -j$THREADS -C /depends HOST=x86_64-w64-mingw32 NO_QT=1
RUN git clone https://code.qt.io/qt/qt5.git -b ${QT_VERSION} --depth 1 && \
cd qt5 && \
- git clone https://code.qt.io/qt/qtbase.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtdeclarative.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtgraphicaleffects.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtimageformats.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtmultimedia.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtquickcontrols.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtquickcontrols2.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtsvg.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qttools.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qttranslations.git -b ${QT_VERSION} --depth 1 && \
- git clone https://code.qt.io/qt/qtxmlpatterns.git -b ${QT_VERSION} --depth 1 && \
+ git reset --hard dc2ac680fa9d0ef7b0d9520859593d13951bedea && \
+ git submodule update --init --depth 1 qtbase qtdeclarative qtgraphicaleffects qtimageformats qtmultimedia qtquickcontrols qtquickcontrols2 qtsvg qttools qttranslations qtxmlpatterns && \
./configure --prefix=/depends/x86_64-w64-mingw32 -xplatform win32-g++ \
-device-option CROSS_COMPILE=/usr/bin/x86_64-w64-mingw32- \
-I $(pwd)/qtbase/src/3rdparty/angle/include \
Why this scored 66/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.