What changed, and why it matters
This commit is a routine build configuration change. It sets up proper Android release signing (so the app can be published on app stores) and updates the app's package name and copyright strings across Android, iOS, macOS, and Windows from placeholder/example values to the real project identity (MAGIC Grants / Skylight Wallet). There is no security vulnerability here.
No security action required. Ensure key.properties and the Android keystore file are excluded from version control (e.g., listed in .gitignore) and stored securely in CI/CD secrets or build environments.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff adds a release signing configuration to android/app/build.gradle.kts that reads keystore credentials from an external key.properties file, and switches the release build type from debug signing to release signing. It also updates PRODUCT_BUNDLE_IDENTIFIER values from com.example.moneroLightWallet to org.magicgrants.skylight on iOS/macOS, and updates Windows resource file company/copyright strings from com.example to MAGIC Grants. No code logic, permissions, network handling, or cryptographic implementation is changed. The keystore secrets are not committed; they are loaded from a local properties file.
Changed components
Android build configuration (android/app/build.gradle.kts)iOS bundle identifier (ios/Runner.xcodeproj/project.pbxproj)macOS bundle identifier (macos/Runner.xcodeproj/project.pbxproj, macos/Runner/Configs/AppInfo.xcconfig)Windows application metadata (windows/runner/Runner.rc)Inspect captured patch +31 / −13
diff --git a/android/app/build.gradle.kts b/android/app/build.gradle.kts
index ba6eafc..6a323d5 100644
--- a/android/app/build.gradle.kts
+++ b/android/app/build.gradle.kts
@@ -1,3 +1,6 @@
+import java.util.Properties
+import java.io.FileInputStream
+
plugins {
id("com.android.application")
id("kotlin-android")
@@ -5,6 +8,12 @@ plugins {
id("dev.flutter.flutter-gradle-plugin")
}
+val keystoreProperties = Properties()
+val keystorePropertiesFile = rootProject.file("key.properties")
+if (keystorePropertiesFile.exists()) {
+ keystoreProperties.load(FileInputStream(keystorePropertiesFile))
+}
+
android {
namespace = "org.magicgrants.skylight"
compileSdk = flutter.compileSdkVersion
@@ -32,11 +41,20 @@ android {
multiDexEnabled = true
}
+ signingConfigs {
+ create("release") {
+ keyAlias = keystoreProperties["keyAlias"] as String
+ keyPassword = keystoreProperties["keyPassword"] as String
+ storeFile = keystoreProperties["storeFile"]?.let { file(it) }
+ storePassword = keystoreProperties["storePassword"] as String
+ }
+ }
+
buildTypes {
release {
// TODO: Add your own signing config for the release build.
// Signing with the debug keys for now, so `flutter run --release` works.
- signingConfig = signingConfigs.getByName("debug")
+ signingConfig = signingConfigs.getByName("release")
}
}
}
diff --git a/ios/Runner.xcodeproj/project.pbxproj b/ios/Runner.xcodeproj/project.pbxproj
index 99f978d..a988bc6 100644
--- a/ios/Runner.xcodeproj/project.pbxproj
+++ b/ios/Runner.xcodeproj/project.pbxproj
@@ -368,7 +368,7 @@
"$(inherited)",
"@executable_path/Frameworks",
);
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_OBJC_BRIDGING_HEADER = "Runner/Runner-Bridging-Header.h";
SWIFT_VERSION = 5.0;
@@ -384,7 +384,7 @@
CURRENT_PROJECT_VERSION = 1;
GENERATE_INFOPLIST_FILE = YES;
MARKETING_VERSION = 1.0;
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet.RunnerTests;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight.RunnerTests;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_ACTIVE_COMPILATION_CONDITIONS = DEBUG;
SWIFT_OPTIMIZATION_LEVEL = "-Onone";
@@ -401,7 +401,7 @@
CURRENT_PROJECT_VERSION = 1;
GENERATE_INFOPLIST_FILE = YES;
MARKETING_VERSION = 1.0;
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet.RunnerTests;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight.RunnerTests;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_VERSION = 5.0;
TEST_HOST = "$(BUILT_PRODUCTS_DIR)/Runner.app/$(BUNDLE_EXECUTABLE_FOLDER_PATH)/Runner";
@@ -416,7 +416,7 @@
CURRENT_PROJECT_VERSION = 1;
GENERATE_INFOPLIST_FILE = YES;
MARKETING_VERSION = 1.0;
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet.RunnerTests;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight.RunnerTests;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_VERSION = 5.0;
TEST_HOST = "$(BUILT_PRODUCTS_DIR)/Runner.app/$(BUNDLE_EXECUTABLE_FOLDER_PATH)/Runner";
@@ -547,7 +547,7 @@
"$(inherited)",
"@executable_path/Frameworks",
);
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_OBJC_BRIDGING_HEADER = "Runner/Runner-Bridging-Header.h";
SWIFT_OPTIMIZATION_LEVEL = "-Onone";
@@ -569,7 +569,7 @@
"$(inherited)",
"@executable_path/Frameworks",
);
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_OBJC_BRIDGING_HEADER = "Runner/Runner-Bridging-Header.h";
SWIFT_VERSION = 5.0;
diff --git a/macos/Runner.xcodeproj/project.pbxproj b/macos/Runner.xcodeproj/project.pbxproj
index e38f9cc..49ae26c 100644
--- a/macos/Runner.xcodeproj/project.pbxproj
+++ b/macos/Runner.xcodeproj/project.pbxproj
@@ -385,7 +385,7 @@
CURRENT_PROJECT_VERSION = 1;
GENERATE_INFOPLIST_FILE = YES;
MARKETING_VERSION = 1.0;
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet.RunnerTests;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight.RunnerTests;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_VERSION = 5.0;
TEST_HOST = "$(BUILT_PRODUCTS_DIR)/skylight_wallet.app/$(BUNDLE_EXECUTABLE_FOLDER_PATH)/skylight";
@@ -399,7 +399,7 @@
CURRENT_PROJECT_VERSION = 1;
GENERATE_INFOPLIST_FILE = YES;
MARKETING_VERSION = 1.0;
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet.RunnerTests;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight.RunnerTests;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_VERSION = 5.0;
TEST_HOST = "$(BUILT_PRODUCTS_DIR)/skylight_wallet.app/$(BUNDLE_EXECUTABLE_FOLDER_PATH)/skylight";
@@ -413,7 +413,7 @@
CURRENT_PROJECT_VERSION = 1;
GENERATE_INFOPLIST_FILE = YES;
MARKETING_VERSION = 1.0;
- PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet.RunnerTests;
+ PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight.RunnerTests;
PRODUCT_NAME = "$(TARGET_NAME)";
SWIFT_VERSION = 5.0;
TEST_HOST = "$(BUILT_PRODUCTS_DIR)/skylight_wallet.app/$(BUNDLE_EXECUTABLE_FOLDER_PATH)/skylight";
diff --git a/macos/Runner/Configs/AppInfo.xcconfig b/macos/Runner/Configs/AppInfo.xcconfig
index d99dff7..3a461f8 100644
--- a/macos/Runner/Configs/AppInfo.xcconfig
+++ b/macos/Runner/Configs/AppInfo.xcconfig
@@ -8,7 +8,7 @@
PRODUCT_NAME = skylight_wallet
// The application's bundle identifier
-PRODUCT_BUNDLE_IDENTIFIER = com.example.moneroLightWallet
+PRODUCT_BUNDLE_IDENTIFIER = org.magicgrants.skylight
// The copyright displayed in application information
PRODUCT_COPYRIGHT = Copyright © 2025 com.example. All rights reserved.
diff --git a/windows/runner/Runner.rc b/windows/runner/Runner.rc
index 4b14e5f..497e171 100644
--- a/windows/runner/Runner.rc
+++ b/windows/runner/Runner.rc
@@ -89,11 +89,11 @@ BEGIN
BEGIN
BLOCK "040904e4"
BEGIN
- VALUE "CompanyName", "com.example" "\0"
+ VALUE "CompanyName", "MAGIC Grants" "\0"
VALUE "FileDescription", "skylight_wallet" "\0"
VALUE "FileVersion", VERSION_AS_STRING "\0"
VALUE "InternalName", "skylight_wallet" "\0"
- VALUE "LegalCopyright", "Copyright (C) 2025 com.example. All rights reserved." "\0"
+ VALUE "LegalCopyright", "Copyright (C) 2025 MAGIC Grants. All rights reserved." "\0"
VALUE "OriginalFilename", "skylight_wallet.exe" "\0"
VALUE "ProductName", "skylight_wallet" "\0"
VALUE "ProductVersion", VERSION_AS_STRING "\0"
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.