What changed, and why it matters
This commit adds the ability to build and release Debian (.deb) packages for the Skylight Wallet Linux app. It also removes an unused import in one Dart source file. There is no security-relevant change: no bug fixes, no vulnerability patches, no permission changes to existing files, and no new risky behavior.
No security action required. Routine build-system change; review the new packaging script for correctness if desired, but it follows standard dpkg-deb practices.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The change extends CI to produce .deb packages alongside existing AppImage builds. A new deb/build_deb.sh script creates a standard Debian package from the Flutter Linux bundle, including control file, wrapper script, desktop entry, and icon. Dockerfile.builder gains the fakeroot package. appimage/build_appimage.sh is refactored to assume the Flutter Linux build was already produced by CI. lib/screens/wallet_home.dart drops an unused notifications_service.dart import. No code logic, cryptography, networking, or permissions are altered in a security-relevant way.
Changed components
.github/workflows/release.ymlDockerfile.builderappimage/build_appimage.shdeb/build_deb.shlib/screens/wallet_home.dartInspect captured patch +188 / −11
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index ce9a364..0a9ffc0 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -195,7 +195,7 @@ jobs:
path: dist/*.aab
build-linux-x86_64:
- name: Linux AppImage (x86_64)
+ name: Linux (x86_64)
runs-on: ubuntu-latest
environment: Release
needs: version
@@ -208,23 +208,26 @@ jobs:
- name: Pull builder image
run: docker pull ghcr.io/magicgrants/skylight-wallet-builder:latest
- - name: Build AppImage (x86_64)
+ - name: Build Linux packages
run: |
VERSION='${{ needs.version.outputs.version }}'
docker run --rm \
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -c "flutter pub get && ./appimage/build_appimage.sh --version ${VERSION}"
+ bash -c "flutter pub get && flutter build linux --release && ./deb/build_deb.sh --version ${VERSION} && ./appimage/build_appimage.sh --version ${VERSION}"
mkdir -p dist
+ cp -v deb/skylight-wallet_*.deb dist/
cp -v appimage/skylight-wallet-*.AppImage dist/
- - name: Upload artifact
+ - name: Upload artifacts
uses: actions/upload-artifact@v4
with:
- name: linux-appimage
- path: dist/*.AppImage
+ name: linux-x86_64
+ path: |
+ dist/*.deb
+ dist/*.AppImage
release:
name: Sign + Release
@@ -259,7 +262,7 @@ jobs:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
set -euo pipefail
- find dist -type f \( -name "*.apk" -o -name "*.aab" -o -name "*.AppImage" \) -print0 | while IFS= read -r -d '' file; do
+ find dist -type f \( -name "*.apk" -o -name "*.aab" -o -name "*.deb" -o -name "*.AppImage" \) -print0 | while IFS= read -r -d '' file; do
echo "$GPG_PASSPHRASE" | gpg --batch --yes --pinentry-mode loopback --passphrase-fd 0 --detach-sign --armor "$file"
echo "Signed: $file"
done
@@ -279,6 +282,8 @@ jobs:
dist/**/*.apk.asc
dist/**/*.aab
dist/**/*.aab.asc
+ dist/**/*.deb
+ dist/**/*.deb.asc
dist/**/*.AppImage
dist/**/*.AppImage.asc
env:
diff --git a/Dockerfile.builder b/Dockerfile.builder
index c78a8bd..b51da72 100644
--- a/Dockerfile.builder
+++ b/Dockerfile.builder
@@ -35,7 +35,8 @@ RUN apt-get update && \
libssl-dev=1.1.1w-0+deb11u4 \
libsecret-1-dev=0.20.4-2 \
libsecret-1-0=0.20.4-2 \
- file=1:5.39-3+deb11u1 && \
+ file=1:5.39-3+deb11u1 \
+ fakeroot=1.25.3-1.1 && \
apt-get clean && \
rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
diff --git a/appimage/build_appimage.sh b/appimage/build_appimage.sh
index 950db3e..e9e9827 100755
--- a/appimage/build_appimage.sh
+++ b/appimage/build_appimage.sh
@@ -59,8 +59,12 @@ echo "Building AppImage version: $VERSION"
PROJECT_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
cd "$PROJECT_ROOT"
-echo "Building Flutter Linux app..."
-flutter build linux --release
+# Check if Flutter build exists
+if [ ! -d "build/linux/x64/release/bundle" ]; then
+ echo "Error: Flutter Linux build not found."
+ echo "Run 'flutter build linux --release' first."
+ exit 1
+fi
echo "Creating AppImage structure..."
cd appimage
diff --git a/deb/.gitignore b/deb/.gitignore
new file mode 100644
index 0000000..7a53327
--- /dev/null
+++ b/deb/.gitignore
@@ -0,0 +1,3 @@
+# Debian package build artifacts
+skylight-wallet_*/
+*.deb
diff --git a/deb/build_deb.sh b/deb/build_deb.sh
new file mode 100755
index 0000000..b1392b5
--- /dev/null
+++ b/deb/build_deb.sh
@@ -0,0 +1,165 @@
+#!/bin/bash
+# Debian Package Build Script for Skylight Wallet
+#
+# Usage: ./build_deb.sh --version <version>
+#
+# This script builds a .deb package from the Linux Flutter build.
+#
+# Requirements:
+# - dpkg-deb (usually pre-installed on Debian/Ubuntu)
+# - fakeroot (optional, for proper ownership without root)
+
+set -e
+
+# Parse command line arguments
+VERSION=""
+while [[ $# -gt 0 ]]; do
+ case $1 in
+ -v|--version)
+ VERSION="$2"
+ shift 2
+ ;;
+ -h|--help)
+ echo "Usage: $0 --version <version>"
+ echo ""
+ echo "Arguments:"
+ echo " -v, --version Version string for the package (required)"
+ echo " -h, --help Show this help message"
+ echo ""
+ echo "Example:"
+ echo " $0 --version 1.0.0"
+ exit 0
+ ;;
+ *)
+ echo "Unknown option: $1"
+ echo "Use --help for usage information"
+ exit 1
+ ;;
+ esac
+done
+
+# Check if version is provided
+if [ -z "$VERSION" ]; then
+ echo "Error: --version is required"
+ echo "Usage: $0 --version <version>"
+ echo "Example: $0 --version 1.0.0"
+ exit 1
+fi
+
+# Strip 'v' prefix if present for package version
+PKG_VERSION="${VERSION#v}"
+
+echo "Building .deb package version: $PKG_VERSION"
+
+# Get the project root directory (parent of deb folder)
+PROJECT_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
+cd "$PROJECT_ROOT"
+
+# Check for dpkg-deb
+if ! command -v dpkg-deb &> /dev/null; then
+ echo "Error: dpkg-deb is required but not installed."
+ echo "Install it with: sudo apt install dpkg"
+ exit 1
+fi
+
+# Check if Flutter build exists
+if [ ! -d "build/linux/x64/release/bundle" ]; then
+ echo "Error: Flutter Linux build not found."
+ echo "Run 'flutter build linux --release' first."
+ exit 1
+fi
+
+echo "Creating Debian package structure..."
+cd deb
+rm -rf skylight-wallet_* || true
+PACKAGE_DIR="skylight-wallet_${PKG_VERSION}_amd64"
+mkdir -p "$PACKAGE_DIR/DEBIAN"
+mkdir -p "$PACKAGE_DIR/usr/lib/skylight-wallet"
+mkdir -p "$PACKAGE_DIR/usr/bin"
+mkdir -p "$PACKAGE_DIR/usr/share/icons/hicolor/512x512/apps"
+mkdir -p "$PACKAGE_DIR/usr/share/applications"
+
+# Create control file
+echo "Creating control file..."
+INSTALLED_SIZE=$(du -sk ../build/linux/x64/release/bundle | cut -f1)
+cat > "$PACKAGE_DIR/DEBIAN/control" << EOF
+Package: skylight-wallet
+Version: $PKG_VERSION
+Section: finance
+Priority: optional
+Architecture: amd64
+Installed-Size: $INSTALLED_SIZE
+Maintainer: Skylight Wallet Developers
+Description: Monero cryptocurrency wallet
+ A light Monero wallet with privacy-focused features.
+ Skylight Wallet provides an easy-to-use interface for
+ managing Monero cryptocurrency.
+Homepage: https://github.com/skylight-wallet/skylight-wallet
+EOF
+
+# Copy the Flutter bundle to lib directory
+echo "Copying Flutter bundle..."
+cp -r ../build/linux/x64/release/bundle/* "$PACKAGE_DIR/usr/lib/skylight-wallet/"
+
+# Create wrapper script in /usr/bin
+echo "Creating launcher script..."
+cat > "$PACKAGE_DIR/usr/bin/skylight-wallet" << 'EOF'
+#!/bin/bash
+INSTALL_DIR="/usr/lib/skylight-wallet"
+export LD_LIBRARY_PATH="$INSTALL_DIR/lib:$LD_LIBRARY_PATH"
+exec "$INSTALL_DIR/skylight_wallet" "$@"
+EOF
+chmod 755 "$PACKAGE_DIR/usr/bin/skylight-wallet"
+
+# Copy icon
+echo "Copying icon..."
+cp ../linux/launcher_icon.png "$PACKAGE_DIR/usr/share/icons/hicolor/512x512/apps/skylight-wallet.png"
+
+# Create desktop file
+echo "Creating desktop entry..."
+cat > "$PACKAGE_DIR/usr/share/applications/skylight-wallet.desktop" << EOF
+[Desktop Entry]
+Type=Application
+Name=Skylight Wallet
+Comment=Monero cryptocurrency wallet
+Exec=skylight-wallet
+Icon=skylight-wallet
+Categories=Finance;Network;
+Terminal=false
+EOF
+
+# Set proper permissions
+echo "Setting permissions..."
+find "$PACKAGE_DIR" -type d -exec chmod 755 {} \;
+find "$PACKAGE_DIR/usr/lib/skylight-wallet" -type f -name "*.so*" -exec chmod 644 {} \;
+chmod 755 "$PACKAGE_DIR/usr/lib/skylight-wallet/skylight_wallet"
+chmod 644 "$PACKAGE_DIR/usr/share/applications/skylight-wallet.desktop"
+chmod 644 "$PACKAGE_DIR/usr/share/icons/hicolor/512x512/apps/skylight-wallet.png"
+chmod 644 "$PACKAGE_DIR/DEBIAN/control"
+
+# Build the .deb package
+echo "Building .deb package..."
+if command -v fakeroot &> /dev/null; then
+ fakeroot dpkg-deb --build "$PACKAGE_DIR"
+else
+ echo "Note: fakeroot not found, using dpkg-deb directly"
+ echo " Install fakeroot for proper file ownership in package"
+ dpkg-deb --build "$PACKAGE_DIR"
+fi
+
+DEB_FILE="${PACKAGE_DIR}.deb"
+
+# Verify the package
+echo "Verifying package..."
+dpkg-deb --info "$DEB_FILE"
+
+# Clean up build directory
+echo "Cleaning up..."
+rm -rf "$PACKAGE_DIR"
+
+echo ""
+echo "✓ Debian package created successfully!"
+echo "Output: deb/$DEB_FILE"
+echo ""
+echo "Install with: sudo dpkg -i deb/$DEB_FILE"
+echo "Remove with: sudo dpkg -r skylight-wallet"
diff --git a/lib/screens/wallet_home.dart b/lib/screens/wallet_home.dart
index 61f1864..5550da1 100644
--- a/lib/screens/wallet_home.dart
+++ b/lib/screens/wallet_home.dart
@@ -2,7 +2,6 @@ import 'dart:math' as math;
import 'package:flutter/material.dart';
import 'package:flutter_svg/flutter_svg.dart';
import 'package:skylight_wallet/models/fiat_rate_model.dart';
-import 'package:skylight_wallet/services/notifications_service.dart';
import 'package:skylight_wallet/services/tor_service.dart';
import 'package:skylight_wallet/widgets/fiat_amount.dart';
import 'package:skylight_wallet/widgets/monero_amount.dart';
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.