What changed, and why it matters
This commit changes a single dependency version in a Dart package file from a flexible version range (^0.20.2) to an exact pinned version (0.20.2). This is a routine build/dependency management change with no visible security relevance in the commit itself or supplied references.
No security action required. Treat as normal dependency pinning. If investigating supply-chain risk, verify whether `intl` 0.20.2 is the intended secure version and whether the broader project has a policy for pinning dependencies.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff pins the intl package in pubspec.yaml from ^0.20.2 to exactly 0.20.2. This prevents automatic upgrades within the 0.20.x minor range. No code changes, bug fixes, vulnerability patches, or security explanations are present in the commit message or diff.
Changed components
pubspec.yaml dependency specification for intlInspect captured patch +1 / −1
diff --git a/pubspec.yaml b/pubspec.yaml
index 85eb259..2195695 100644
--- a/pubspec.yaml
+++ b/pubspec.yaml
@@ -61,7 +61,7 @@ dependencies:
dart_date: 1.5.3
qr_flutter: 4.1.0
share_plus: 11.1.0
- intl: ^0.20.2
+ intl: 0.20.2
shared_preferences: 2.5.3
http: 1.6.0
workmanager: 0.9.0+3
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.