What changed, and why it matters
This commit changes the F-Droid build script to add the '--enforce-lockfile' flag when Flutter downloads its package dependencies. In plain terms, it tells the build tool: 'only install the exact versions of dependencies recorded in the lockfile, and fail if the lockfile is missing or out of sync.' This is a supply-chain hardening measure. It reduces the risk that a build silently picks up a newer, potentially malicious or buggy version of a dependency, but it is not a fix for a known active vulnerability.
No immediate user action is required. Developers should ensure pubspec.lock is committed and kept in sync with pubspec.yaml, and verify that F-Droid reproducible builds still succeed with the stricter flag.
Security signals we found
Adds --enforce-lockfile to flutter pub get, enforcing deterministic dependency resolution
Prevents silent drift between declared and resolved Flutter package versions during F-Droid builds
Reduces supply-chain attack surface from unexpected dependency version changes
Evidence from the diff
The patch modifies scripts/fdroid-build.sh so that the command ‘$FLUTTER/bin/flutter pub get’ becomes ‘$FLUTTER/bin/flutter pub get –enforce-lockfile’. Flutter’s –enforce-lockfile option causes ‘pub get’ to fail if the pubspec.lock file is absent or does not match pubspec.yaml, preventing unreviewed dependency updates during the F-Droid build. This is a deterministic-build / supply-chain integrity improvement.
Changed components
scripts/fdroid-build.shF-Droid build pipelineFlutter dependency resolution (pub get)Inspect captured patch +1 / −1
diff --git a/scripts/fdroid-build.sh b/scripts/fdroid-build.sh
index 960ff31..37cae93 100755
--- a/scripts/fdroid-build.sh
+++ b/scripts/fdroid-build.sh
@@ -57,7 +57,7 @@ export PUB_CACHE=/tmp/skylight/.pub-cache
export CARGO_HOME=/tmp/skylight-cargo
# cargokit requires an NDK package.xml (absent in unzipped NDKs)
[ -f "$ANDROID_HOME/ndk/$NDK/package.xml" ] || touch "$ANDROID_HOME/ndk/$NDK/package.xml"
-"$FLUTTER/bin/flutter" pub get
+"$FLUTTER/bin/flutter" pub get --enforce-lockfile
bash scripts/pin-rust-toolchain.sh
"$FLUTTER/bin/flutter" build apk --dart-define=DEMO_MODE=true --release --split-per-abi --target-platform="$PLATFORM"
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.