What changed, and why it matters
This commit only updates documentation and build scripts to remove the miniupnpc library from the list of dependencies. It does not change any actual program code, so it cannot directly introduce or fix a security vulnerability in the software itself. It is a housekeeping change reflecting that the project no longer needs miniupnpc.
No security action required. Treat as a normal dependency-list cleanup. If miniupnpc was removed because of a known vulnerability, that is not stated in this commit and would require separate verification.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff removes miniupnpc from package-install commands in .github/workflows/build.yml, DEPLOY.md, and README.md. No source code, build logic, or configuration files that affect runtime behavior are modified. The change is purely documentation/build-environment hygiene.
Changed components
README.mdDEPLOY.md.github/workflows/build.ymlInspect captured patch +8 / −8
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index 37acfd3..5cd6d42 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -16,7 +16,7 @@ jobs:
with:
submodules: recursive
- name: install dependencies
- run: HOMEBREW_NO_AUTO_UPDATE=1 brew install boost hidapi openssl zmq libsodium miniupnpc unbound protobuf qt5 pkg-config
+ run: HOMEBREW_NO_AUTO_UPDATE=1 brew install boost hidapi openssl zmq libsodium unbound protobuf qt5 pkg-config
- name: build
run: DEV_MODE=ON make release -j3
- name: test qml
@@ -38,7 +38,7 @@ jobs:
- name: update apt
run: sudo apt update
- name: install monero dependencies
- run: sudo apt -y install build-essential cmake libboost-all-dev miniupnpc libunbound-dev graphviz doxygen pkg-config libssl-dev libzmq3-dev libsodium-dev libhidapi-dev libnorm-dev libusb-1.0-0-dev libpgm-dev libprotobuf-dev protobuf-compiler
+ run: sudo apt -y install build-essential cmake libboost-all-dev libunbound-dev graphviz doxygen pkg-config libssl-dev libzmq3-dev libsodium-dev libhidapi-dev libnorm-dev libusb-1.0-0-dev libpgm-dev libprotobuf-dev protobuf-compiler
- name: install monero gui dependencies
run: sudo apt -y install qtbase5-dev qtdeclarative5-dev qml-module-qtqml-models2 qml-module-qtquick-controls qml-module-qtquick-controls2 qml-module-qtquick-dialogs qml-module-qtquick-xmllistmodel qml-module-qt-labs-settings qml-module-qt-labs-platform qml-module-qt-labs-folderlistmodel qttools5-dev-tools qml-module-qtquick-templates2 libqt5svg5-dev libgcrypt20-dev xvfb
- name: build
@@ -80,7 +80,7 @@ jobs:
with:
submodules: recursive
- name: install dependencies
- run: HOMEBREW_NO_AUTO_UPDATE=1 brew install boost hidapi openssl zmq miniupnpc unbound protobuf pkg-config
+ run: HOMEBREW_NO_AUTO_UPDATE=1 brew install boost hidapi openssl zmq unbound protobuf pkg-config
- name: clone qt repo
run: git clone -b "${QT_TAG}" --recursive --depth 1 --shallow-submodules https://github.com/qt/qt5
- name: build qt from source
diff --git a/DEPLOY.md b/DEPLOY.md
index a037be6..660cd2c 100644
--- a/DEPLOY.md
+++ b/DEPLOY.md
@@ -2,7 +2,7 @@
Use macOS 10.12 - 10.13 for better backwards compability.
-1. `HOMEBREW_OPTFLAGS="-march=core2" HOMEBREW_OPTIMIZATION_LEVEL="O0" brew install boost zmq libpgm miniupnpc libsodium expat protobuf@21 libgcrypt hidapi libusb cmake pkg-config && brew link protobuf@21`
+1. `HOMEBREW_OPTFLAGS="-march=core2" HOMEBREW_OPTIMIZATION_LEVEL="O0" brew install boost zmq libpgm libsodium expat protobuf@21 libgcrypt hidapi libusb cmake pkg-config && brew link protobuf@21`
2. Get the latest LTS from here: https://www.qt.io/offline-installers and install
diff --git a/README.md b/README.md
index f921603..315e195 100644
--- a/README.md
+++ b/README.md
@@ -207,15 +207,15 @@ Packaging for your favorite distribution would be a welcome contribution!
- For Debian distributions (Debian, Ubuntu, Mint, Tails...)
- `sudo apt install build-essential cmake miniupnpc libunbound-dev graphviz doxygen pkg-config libssl-dev libzmq3-dev libsodium-dev libhidapi-dev libnorm-dev libusb-1.0-0-dev libpgm-dev libprotobuf-dev protobuf-compiler libgcrypt20-dev libboost-chrono-dev libboost-date-time-dev libboost-filesystem-dev libboost-locale-dev libboost-program-options-dev libboost-regex-dev libboost-serialization-dev libboost-system-dev libboost-thread-dev`
+ `sudo apt install build-essential cmake libunbound-dev graphviz doxygen pkg-config libssl-dev libzmq3-dev libsodium-dev libhidapi-dev libnorm-dev libusb-1.0-0-dev libpgm-dev libprotobuf-dev protobuf-compiler libgcrypt20-dev libboost-chrono-dev libboost-date-time-dev libboost-filesystem-dev libboost-locale-dev libboost-program-options-dev libboost-regex-dev libboost-serialization-dev libboost-system-dev libboost-thread-dev`
- For Gentoo
- `sudo emerge app-arch/xz-utils app-doc/doxygen dev-cpp/gtest dev-libs/boost dev-libs/expat dev-libs/openssl dev-util/cmake media-gfx/graphviz net-dns/unbound net-libs/miniupnpc net-libs/zeromq dev-libs/libsodium dev-libs/hidapi dev-libs/libgcrypt`
+ `sudo emerge app-arch/xz-utils app-doc/doxygen dev-cpp/gtest dev-libs/boost dev-libs/expat dev-libs/openssl dev-util/cmake media-gfx/graphviz net-dns/unbound net-libs/zeromq dev-libs/libsodium dev-libs/hidapi dev-libs/libgcrypt`
- For Fedora
- `sudo dnf install make automake cmake gcc-c++ boost-devel miniupnpc-devel graphviz doxygen unbound-devel pkgconfig openssl-devel libcurl-devel hidapi-devel libusb-devel zeromq-devel libgcrypt-devel`
+ `sudo dnf install make automake cmake gcc-c++ boost-devel graphviz doxygen unbound-devel pkgconfig openssl-devel libcurl-devel hidapi-devel libusb-devel zeromq-devel libgcrypt-devel`
2. Install Qt:
@@ -273,7 +273,7 @@ The executable can be found in the build/release/bin folder.
3. Install [monero](https://github.com/monero-project/monero) dependencies:
- `brew install cmake pkg-config openssl boost unbound hidapi zmq libpgm libsodium miniupnpc expat protobuf libgcrypt`
+ `brew install cmake pkg-config openssl boost unbound hidapi zmq libpgm libsodium expat protobuf libgcrypt`
4. Install Qt:
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.