What changed, and why it matters
This commit changes the automated release build script to add `--enforce-lockfile` to a Flutter package command. That flag tells the build tool to use exactly the dependency versions recorded in the project's lock file and not silently upgrade or change packages. It is a supply-chain hardening measure that reduces the chance of an unexpected or malicious package version sneaking into a release build, but it is not a fix for a known active vulnerability.
No immediate action is required. Treat this as a routine hardening improvement. Continue to monitor `pubspec.lock` integrity and review dependency updates through normal change-control processes.
Security signals we found
CI/CD build hardening
Dependency resolution lockfile enforcement
Supply-chain risk reduction
Evidence from the diff
In .github/workflows/release.yml, the Flutter build step now runs flutter pub get --enforce-lockfile instead of flutter pub get. The --enforce-lockfile option ensures that pubspec.lock is respected strictly and that the build fails if the lockfile is out of sync with pubspec.yaml, preventing silent dependency drift or resolution changes during CI builds. No other workflow logic, secrets, build outputs, or source code were modified.
Changed components
.github/workflows/release.ymlFlutter release build pipelineInspect captured patch +1 / −1
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 2d04a8c..5864479 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -150,7 +150,7 @@ jobs:
-w /tmp/skylight \
-e SOURCE_DATE_EPOCH \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -c "cp -a /opt/cargo /tmp/skylight-cargo && export CARGO_HOME=/tmp/skylight-cargo && export PUB_CACHE=/tmp/skylight/.pub-cache && flutter pub get && bash scripts/pin-rust-toolchain.sh && flutter build apk --dart-define=DEMO_MODE=true --release --split-per-abi && flutter build appbundle --dart-define=DEMO_MODE=true --release"
+ bash -c "cp -a /opt/cargo /tmp/skylight-cargo && export CARGO_HOME=/tmp/skylight-cargo && export PUB_CACHE=/tmp/skylight/.pub-cache && flutter pub get --enforce-lockfile && bash scripts/pin-rust-toolchain.sh && flutter build apk --dart-define=DEMO_MODE=true --release --split-per-abi && flutter build appbundle --dart-define=DEMO_MODE=true --release"
mkdir -p dist
cp -v build/app/outputs/flutter-apk/app-arm64-v8a-release.apk "dist/skylight-wallet-${VERSION}-arm64-v8a.apk"
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.