What changed, and why it matters
This commit adds a Windows build and installer to the project's automated release pipeline. It is a routine CI/CD change with no apparent security relevance.
No security action required. As with any new CI job, routine review of runner permissions and secrets usage is good practice, but the change itself is benign.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit introduces a new build-windows job in .github/workflows/release.yml that runs on windows-latest, installs Flutter, Inno Setup, and Rust, builds the Windows release, creates an installer via windows/installer.iss, and uploads the resulting .exe artifact. The release job is updated to depend on build-windows and to sign and publish the .exe and its detached GPG signature. A new Inno Setup script (windows/installer.iss) is added to package the Flutter build output into a 64-bit Windows installer. No code changes to the application itself are present.
Changed components
.github/workflows/release.ymlwindows/installer.issInspect captured patch +108 / −2
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index b08f8cc..35b1793 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -3,7 +3,7 @@ name: Build and Release
on:
push:
tags:
- - 'v*'
+ - "v*"
workflow_dispatch:
permissions:
@@ -114,6 +114,43 @@ jobs:
dist/*.deb
dist/*.AppImage
+ build-windows:
+ name: Windows (x64)
+ runs-on: windows-latest
+ environment: Release
+ needs: version
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+ with:
+ submodules: recursive
+
+ - name: Set up Flutter
+ uses: subosito/flutter-action@v2
+ with:
+ channel: stable
+ flutter-version: 3.38.7
+
+ - name: Install dependencies
+ run: flutter pub get
+
+ - name: Install Inno Setup and Rust
+ run: choco install innosetup rust -y
+
+ - name: Build Windows release
+ run: flutter build windows --release
+
+ - name: Create installer
+ run: |
+ $version = '${{ needs.version.outputs.version }}'.TrimStart('v')
+ & 'C:\Program Files (x86)\Inno Setup 6\ISCC.exe' /DAppVersion=$version windows\installer.iss
+
+ - name: Upload artifacts
+ uses: actions/upload-artifact@v4
+ with:
+ name: windows-x64
+ path: windows/Output/*.exe
+
release:
name: Sign + Release
runs-on: ubuntu-latest
@@ -122,6 +159,7 @@ jobs:
- version
- build-android
- build-linux-x86_64
+ - build-windows
permissions:
contents: write
steps:
@@ -144,7 +182,7 @@ jobs:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
set -euo pipefail
- find dist -type f \( -name "*.apk" -o -name "*.aab" -o -name "*.deb" -o -name "*.AppImage" \) -print0 | while IFS= read -r -d '' file; do
+ find dist -type f \( -name "*.apk" -o -name "*.aab" -o -name "*.deb" -o -name "*.AppImage" -o -name "*.exe" \) -print0 | while IFS= read -r -d '' file; do
echo "$GPG_PASSPHRASE" | gpg --batch --yes --pinentry-mode loopback --passphrase-fd 0 --detach-sign --armor "$file"
echo "Signed: $file"
done
@@ -168,5 +206,7 @@ jobs:
dist/**/*.deb.asc
dist/**/*.AppImage
dist/**/*.AppImage.asc
+ dist/**/*.exe
+ dist/**/*.exe.asc
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
diff --git a/windows/installer.iss b/windows/installer.iss
new file mode 100644
index 0000000..bae05fc
--- /dev/null
+++ b/windows/installer.iss
@@ -0,0 +1,66 @@
+; Inno Setup Script for Skylight Wallet
+; This script creates a Windows installer with a setup wizard.
+;
+; Usage (from project root):
+; iscc /DAppVersion=1.0.0 windows/installer.iss
+;
+; Requirements:
+; - Inno Setup 6.x (https://jrsoftware.org/isinfo.php)
+; - Flutter Windows build must exist at build\windows\x64\runner\Release\
+
+#ifndef AppVersion
+ #define AppVersion "1.0.0"
+#endif
+
+#define AppName "Skylight Wallet"
+#define AppPublisher "MAGIC Grants"
+#define AppURL "https://github.com/MagicGrants/skylight-wallet"
+#define AppExeName "skylight_wallet.exe"
+
+[Setup]
+; NOTE: The value of AppId uniquely identifies this application.
+; Do not use the same AppId value in installers for other applications.
+AppId={{E8F4B2A1-7D3C-4E5F-9A1B-2C3D4E5F6A7B}
+AppName={#AppName}
+AppVersion={#AppVersion}
+AppVerName={#AppName} {#AppVersion}
+AppPublisher={#AppPublisher}
+AppPublisherURL={#AppURL}
+AppSupportURL={#AppURL}
+AppUpdatesURL={#AppURL}/releases
+DefaultDirName={autopf}\{#AppName}
+DefaultGroupName={#AppName}
+DisableProgramGroupPage=yes
+LicenseFile=..\LICENSE
+OutputDir=Output
+OutputBaseFilename=skylight-wallet-v{#AppVersion}-x64-setup
+SetupIconFile=runner\resources\app_icon.ico
+UninstallDisplayIcon={app}\{#AppExeName}
+Compression=lzma2/max
+SolidCompression=yes
+WizardStyle=modern
+ArchitecturesAllowed=x64compatible
+ArchitecturesInstallIn64BitMode=x64compatible
+PrivilegesRequired=lowest
+PrivilegesRequiredOverridesAllowed=dialog
+
+[Languages]
+Name: "english"; MessagesFile: "compiler:Default.isl"
+Name: "portuguese"; MessagesFile: "compiler:Languages\Portuguese.isl"
+
+[Tasks]
+Name: "desktopicon"; Description: "{cm:CreateDesktopIcon}"; GroupDescription: "{cm:AdditionalIcons}"; Flags: unchecked
+
+[Files]
+; Main application files from Flutter build
+Source: "..\build\windows\x64\runner\Release\{#AppExeName}"; DestDir: "{app}"; Flags: ignoreversion
+Source: "..\build\windows\x64\runner\Release\*.dll"; DestDir: "{app}"; Flags: ignoreversion
+Source: "..\build\windows\x64\runner\Release\data\*"; DestDir: "{app}\data"; Flags: ignoreversion recursesubdirs createallsubdirs
+
+[Icons]
+Name: "{group}\{#AppName}"; Filename: "{app}\{#AppExeName}"
+Name: "{group}\{cm:UninstallProgram,{#AppName}}"; Filename: "{uninstallexe}"
+Name: "{autodesktop}\{#AppName}"; Filename: "{app}\{#AppExeName}"; Tasks: desktopicon
+
+[Run]
+Filename: "{app}\{#AppExeName}"; Description: "{cm:LaunchProgram,{#StringChange(AppName, '&', '&&')}}"; Flags: nowait postinstall skipifsilent
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.