AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 66 Monero

Dockerfiles: pin Qt to a commit hash

Public commit record

What the developer wrote

Authored by Thomas

76/100 · Adequate
Dockerfiles: pin Qt to a commit hash

Qt was cloned with -b ${QT_VERSION} --depth 1 but, unlike every other
dependency in these files, never reset to a commit, so a moved upstream
tag would silently change the Qt source built into the release.

Pin the qt5 superproject to its v5.15.19-lts-lgpl commit and let it
resolve the submodules (git submodule update on linux/windows,
init-repository on android), so only the qt5 hash is hardcoded. qt5
records the exact submodule commits, and the relative .gitmodules URLs
keep the fetches on https.

Follow-up to #4613.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This change tightens how the Monero GUI's build containers fetch the Qt user-interface library. Previously, the build scripts downloaded Qt using only a version tag (like 'v5.15.19-lts-lgpl'), which could silently point to different code if Qt's maintainers ever moved or re-created that tag. Now the scripts reset the downloaded Qt source to a specific, fixed commit hash, so every release build uses the exact same Qt code. This is a supply-chain hardening fix: it prevents a malicious or accidental tag change from slipping modified Qt code into Monero's official wallets.

Recommended action

Treat this as a positive security hardening commit. Verify that the pinned commit `dc2ac680fa9d0ef7b0d9520859593d13951bedea` corresponds to the intended Qt v5.15.19-lts-lgpl release and that submodule URLs remain on `https://` (as the commit message states). No immediate user action is required; downstream release builders should rebuild containers to incorporate the pinned source.

Security signals we found

01

Supply-chain / build-integrity hardening

02

Pinning dependency to immutable commit hash instead of mutable tag

03

Prevents tag-rewriting or tag-squatting attacks on upstream Qt repository

04

Reduces non-determinism in release build inputs

05

Follow-up to prior hardening PR #4613

Risk score

Why this scored 66/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 13/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.