What changed, and why it matters
This commit adds a new Linux AppImage build script and packaging files for the Skylight Wallet application, plus a window icon and minor dependency updates. There is no security-relevant code change and no indication of a vulnerability being fixed.
No security action required. As a routine hygiene measure, consider pinning the appimagetool download URL/tag rather than using the 'continuous' release, and verify the pinned hash after each update.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff introduces appimage/AppImageBuilder.yml, appimage/build_appimage.sh, appimage/skylight_wallet.desktop, appimage/.gitignore, linux/launcher_icon.png, and updates linux/CMakeLists.txt and linux/runner/my_application.cc to install and load the icon. The build script downloads appimagetool from a public GitHub release and verifies its SHA256 hash before use. pubspec.lock bumps transitive packages meta and test_api to newer patch versions. No runtime security controls are modified, no secrets are exposed, and no vulnerability is addressed.
Changed components
appimage packaging scriptslinux/CMakeLists.txtlinux/runner/my_application.ccpubspec.lockInspect captured patch +307 / −4
diff --git a/appimage/.gitignore b/appimage/.gitignore
new file mode 100644
index 0000000..27d63e0
--- /dev/null
+++ b/appimage/.gitignore
@@ -0,0 +1,5 @@
+# AppImage build artifacts
+appimagetool-*.AppImage
+AppDir/
+*.AppImage
+.last_build_id
\ No newline at end of file
diff --git a/appimage/AppImageBuilder.yml b/appimage/AppImageBuilder.yml
new file mode 100644
index 0000000..b388ff6
--- /dev/null
+++ b/appimage/AppImageBuilder.yml
@@ -0,0 +1,123 @@
+version: 1
+
+script:
+ # Build the Flutter app first
+ - flutter build linux --release
+ - rm -rf AppDir || true
+ - mkdir -p AppDir/usr/bin
+ - mkdir -p AppDir/usr/lib
+ - mkdir -p AppDir/usr/share/icons/hicolor/512x512/apps
+ - cp -r build/linux/x64/release/bundle/* AppDir/usr/bin/
+ - cp linux/launcher_icon.png AppDir/usr/share/icons/hicolor/512x512/apps/skylight_wallet.png
+
+AppDir:
+ path: ./AppDir
+
+ app_info:
+ id: org.magicgrants.skylight
+ name: skylight_wallet
+ icon: skylight_wallet
+ version: latest
+ exec: usr/bin/skylight_wallet
+ exec_args: $@
+
+ apt:
+ arch: amd64
+ sources:
+ - sourceline: 'deb [arch=amd64] http://archive.ubuntu.com/ubuntu/ jammy main restricted universe multiverse'
+ key_url: 'http://keyserver.ubuntu.com/pks/lookup?op=get&search=0x871920D1991BC93C'
+
+ include:
+ # Core GTK3 and dependencies (based on actual ldd output)
+ - libgtk-3-0
+ - libglib2.0-0
+ - libgdk-pixbuf2.0-0
+ - libcairo2
+ - libcairo-gobject2
+ - libpango-1.0-0
+ - libpangocairo-1.0-0
+ - libpangoft2-1.0-0
+ - libharfbuzz0b
+ - libfribidi0
+
+ # Accessibility
+ - libatk1.0-0
+ - libatk-bridge2.0-0
+ - libatspi2.0-0
+
+ # Graphics and rendering
+ - libepoxy0
+ - libpixman-1-0
+ - libfreetype6
+ - libfontconfig1
+
+ # X11 support
+ - libx11-6
+ - libxcomposite1
+ - libxdamage1
+ - libxext6
+ - libxfixes3
+ - libxi6
+ - libxrandr2
+ - libxrender1
+ - libxcursor1
+ - libxinerama1
+ - libxcb1
+ - libxcb-render0
+ - libxcb-shm0
+
+ # Wayland support
+ - libwayland-client0
+ - libwayland-cursor0
+ - libwayland-egl1
+ - libxkbcommon0
+
+ # System libraries
+ - libdbus-1-3
+ - libblkid1
+ - libmount1
+ - libsystemd0
+
+ # Security and crypto
+ - libsecret-1-0
+ - libgcrypt20
+
+ # Other dependencies from ldd
+ - libgraphite2-3
+ - libjson-glib-1.0-0
+ - libexpat1
+ - libpng16-16
+ - libthai0
+ - libdatrie1
+ - libpcre2-8-0
+
+ exclude:
+ # Exclude very common system libraries that should be on all systems
+ - libc6
+ - libgcc-s1
+ - libstdc++6
+ - libm6
+
+ files:
+ include: []
+ exclude:
+ - usr/share/man
+ - usr/share/doc/*/README.*
+ - usr/share/doc/*/changelog.*
+ - usr/share/doc/*/NEWS.*
+ - usr/share/doc/*/TODO.*
+
+ test:
+ arch-latest:
+ image: appimagecrafters/tests-env:archlinux-latest
+ command: ./AppRun
+ ubuntu-xenial:
+ image: appimagecrafters/tests-env:ubuntu-xenial
+ command: ./AppRun
+ debian-stable:
+ image: appimagecrafters/tests-env:debian-stable
+ command: ./AppRun
+
+AppImage:
+ arch: x86_64
+ update-information: guess
diff --git a/appimage/build_appimage.sh b/appimage/build_appimage.sh
new file mode 100755
index 0000000..c8d7c29
--- /dev/null
+++ b/appimage/build_appimage.sh
@@ -0,0 +1,149 @@
+#!/bin/bash
+# AppImage Build Script for Skylight Wallet
+#
+# Usage: ./build_appimage.sh --version <version>
+#
+# This script builds a Linux AppImage with integrity verification.
+#
+# To update the expected SHA256 hash:
+# 1. Visit: https://github.com/probonopd/go-appimage/releases
+# 2. Download appimagetool-x86_64.AppImage
+# 3. Run: sha256sum appimagetool-x86_64.AppImage
+# 4. Update EXPECTED_SHA256 variable below
+#
+# Or verify manually before first run:
+# wget https://github.com/probonopd/go-appimage/releases/download/continuous/appimagetool-x86_64.AppImage
+# sha256sum appimagetool-x86_64.AppImage
+# # Compare with hash from trusted source
+
+set -e
+
+# Parse command line arguments
+VERSION=""
+while [[ $# -gt 0 ]]; do
+ case $1 in
+ -v|--version)
+ VERSION="$2"
+ shift 2
+ ;;
+ -h|--help)
+ echo "Usage: $0 --version <version>"
+ echo ""
+ echo "Arguments:"
+ echo " -v, --version Version string for the AppImage (required)"
+ echo " -h, --help Show this help message"
+ echo ""
+ echo "Example:"
+ echo " $0 --version 1.0.0"
+ exit 0
+ ;;
+ *)
+ echo "Unknown option: $1"
+ echo "Use --help for usage information"
+ exit 1
+ ;;
+ esac
+done
+
+# Check if version is provided
+if [ -z "$VERSION" ]; then
+ echo "Error: --version is required"
+ echo "Usage: $0 --version <version>"
+ echo "Example: $0 --version 1.0.0"
+ exit 1
+fi
+
+echo "Building AppImage version: $VERSION"
+
+# Get the project root directory (parent of appimage folder)
+PROJECT_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
+cd "$PROJECT_ROOT"
+
+echo "Building Flutter Linux app..."
+flutter build linux --release
+
+echo "Creating AppImage structure..."
+cd appimage
+rm -rf AppDir || true
+mkdir -p AppDir/usr/bin
+mkdir -p AppDir/usr/lib
+mkdir -p AppDir/usr/share/icons/hicolor/512x512/apps
+mkdir -p AppDir/usr/share/applications
+
+# Copy the Flutter bundle
+echo "Copying Flutter bundle..."
+cp -r ../build/linux/x64/release/bundle/* AppDir/usr/bin/
+
+# Copy icon
+echo "Copying icon..."
+cp ../linux/launcher_icon.png AppDir/usr/share/icons/hicolor/512x512/apps/skylight_wallet.png
+cp ../linux/launcher_icon.png AppDir/skylight_wallet.png
+
+# Copy desktop file
+echo "Creating desktop entry..."
+cp skylight_wallet.desktop AppDir/usr/share/applications/
+cp skylight_wallet.desktop AppDir/
+
+# Create AppRun
+echo "Creating AppRun..."
+cat > AppDir/AppRun << 'EOF'
+#!/bin/bash
+SELF=$(readlink -f "$0")
+HERE=${SELF%/*}
+export PATH="${HERE}/usr/bin/:${HERE}/usr/sbin/:${HERE}/usr/games/:${HERE}/bin/:${HERE}/sbin/${PATH:+:$PATH}"
+export LD_LIBRARY_PATH="${HERE}/usr/lib/:${HERE}/usr/lib/i386-linux-gnu/:${HERE}/usr/lib/x86_64-linux-gnu/:${HERE}/usr/lib32/:${HERE}/usr/lib64/${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH}"
+export XDG_DATA_DIRS="${HERE}/usr/share/${XDG_DATA_DIRS:+:$XDG_DATA_DIRS}"
+EXEC="${HERE}/usr/bin/skylight_wallet"
+exec "${EXEC}" "$@"
+EOF
+
+chmod +x AppDir/AppRun
+
+# Expected SHA256 hash - update this when updating appimagetool
+# Verify from: https://github.com/probonopd/go-appimage/releases
+# Run: sha256sum appimagetool-x86_64.AppImage
+EXPECTED_SHA256="0269abb1084fd4c23198c47a230874f7e5b666c9791b6be72cd3553f64200fbc"
+APPIMAGETOOL_FILENAME="appimagetool-911-x86_64.AppImage"
+
+# Download appimagetool from go-appimage if not present
+if [ ! -f "$APPIMAGETOOL_FILENAME" ]; then
+ echo "Downloading appimagetool (go-appimage)..."
+ wget -q --show-progress "https://github.com/probonopd/go-appimage/releases/download/continuous/$APPIMAGETOOL_FILENAME"
+ chmod +x $APPIMAGETOOL_FILENAME
+fi
+
+# Verify integrity
+echo "Verifying appimagetool integrity..."
+ACTUAL_SHA256=$(sha256sum $APPIMAGETOOL_FILENAME | awk '{print $1}')
+
+if [ "$ACTUAL_SHA256" != "$EXPECTED_SHA256" ]; then
+ echo "⚠ ERROR: SHA256 hash mismatch!"
+ echo "Expected: $EXPECTED_SHA256"
+ echo "Got: $ACTUAL_SHA256"
+ echo ""
+ echo "Either the file is corrupted/tampered, or a new version was released."
+ echo "Verify the hash manually and update EXPECTED_SHA256 in the script if needed."
+ exit 1
+fi
+
+echo "✓ Integrity verified"
+
+# Build the AppImage
+echo "Packaging AppImage..."
+export VERSION
+export ARCH=x86_64
+./$APPIMAGETOOL_FILENAME AppDir
+
+# Clean up temporary files
+echo "Cleaning up..."
+rm -rf AppDir
+
+echo ""
+echo "✓ AppImage created successfully!"
+APPIMAGE_FILE=$(ls -1 skylight-wallet-v${VERSION}-*.AppImage 2>/dev/null | head -n1)
+if [ -n "$APPIMAGE_FILE" ]; then
+ echo "Output: $APPIMAGE_FILE"
+ echo "Run with: ./appimage/$APPIMAGE_FILE"
+else
+ echo "Output: Check appimage/ directory for skylight-wallet-v${VERSION}-*.AppImage"
+fi
diff --git a/appimage/skylight_wallet.desktop b/appimage/skylight_wallet.desktop
new file mode 100644
index 0000000..c8c8442
--- /dev/null
+++ b/appimage/skylight_wallet.desktop
@@ -0,0 +1,8 @@
+[Desktop Entry]
+Type=Application
+Name=Skylight Wallet
+Comment=Monero cryptocurrency wallet
+Exec=skylight_wallet
+Icon=skylight_wallet
+Categories=Finance;Network;
+Terminal=false
diff --git a/linux/CMakeLists.txt b/linux/CMakeLists.txt
index 2758fb1..414d384 100644
--- a/linux/CMakeLists.txt
+++ b/linux/CMakeLists.txt
@@ -98,6 +98,10 @@ install(TARGETS ${BINARY_NAME} RUNTIME DESTINATION "${CMAKE_INSTALL_PREFIX}"
install(FILES "${FLUTTER_ICU_DATA_FILE}" DESTINATION "${INSTALL_BUNDLE_DATA_DIR}"
COMPONENT Runtime)
+install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/launcher_icon.png"
+ DESTINATION "${INSTALL_BUNDLE_DATA_DIR}"
+ COMPONENT Runtime)
+
install(FILES "${FLUTTER_LIBRARY}" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
COMPONENT Runtime)
diff --git a/linux/launcher_icon.png b/linux/launcher_icon.png
new file mode 100644
index 0000000..b2f8cb5
Binary files /dev/null and b/linux/launcher_icon.png differ
diff --git a/linux/runner/my_application.cc b/linux/runner/my_application.cc
index 8f54899..332896a 100644
--- a/linux/runner/my_application.cc
+++ b/linux/runner/my_application.cc
@@ -48,6 +48,20 @@ static void my_application_activate(GApplication* application) {
}
gtk_window_set_default_size(window, 1280, 720);
+
+ // Set window icon - construct path relative to executable
+ g_autofree gchar* exe_path = g_file_read_link("/proc/self/exe", nullptr);
+ if (exe_path != nullptr) {
+ g_autofree gchar* exe_dir = g_path_get_dirname(exe_path);
+ g_autofree gchar* icon_path = g_build_filename(exe_dir, "data", "launcher_icon.png", nullptr);
+
+ g_autoptr(GError) icon_error = nullptr;
+ gtk_window_set_icon_from_file(window, icon_path, &icon_error);
+ if (icon_error != nullptr) {
+ g_warning("Failed to set window icon from %s: %s", icon_path, icon_error->message);
+ }
+ }
+
gtk_widget_show(GTK_WIDGET(window));
g_autoptr(FlDartProject) project = fl_dart_project_new();
diff --git a/pubspec.lock b/pubspec.lock
index bdd51b4..b5d1227 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -441,10 +441,10 @@ packages:
dependency: transitive
description:
name: meta
- sha256: e3641ec5d63ebf0d9b41bd43201a66e3fc79a65db5f61fc181f04cd27aab950c
+ sha256: "23f08335362185a5ea2ad3a4e597f1375e78bce8a040df5c600c8d3552ef2394"
url: "https://pub.dev"
source: hosted
- version: "1.16.0"
+ version: "1.17.0"
mime:
dependency: transitive
description:
@@ -855,10 +855,10 @@ packages:
dependency: transitive
description:
name: test_api
- sha256: "522f00f556e73044315fa4585ec3270f1808a4b186c936e612cab0b565ff1e00"
+ sha256: ab2726c1a94d3176a45960b6234466ec367179b87dd74f1611adb1f3b5fb9d55
url: "https://pub.dev"
source: hosted
- version: "0.7.6"
+ version: "0.7.7"
timeago:
dependency: "direct main"
description:
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.