What changed, and why it matters
This commit changes the release workflow to run build commands in a non-login shell instead of a login shell. There is no security issue here. The change likely fixes a build problem caused by the login shell loading environment files or running scripts that interfered with the build container setup.
No security action needed. Treat as a routine CI/CD maintenance change.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch removes the -l flag from bash invocations in five GitHub Actions workflow steps, switching from login shells (bash -lc) to non-login shells (bash -c). A login shell sources profile files such as /etc/profile and ~/.bash_profile, which in containerized build environments can alter PATH, JAVA_HOME, ANDROID_HOME, or other environment variables in ways that break reproducible builds. The non-login shell avoids this extra initialization. This is a build reliability fix, not a security patch.
Changed components
.github/workflows/release.ymlInspect captured patch +5 / −5
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 0f2894b..a415940 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -54,7 +54,7 @@ jobs:
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -lc "flutter pub get && flutter build apk --dart-define=DEMO_MODE=true --release --target-platform android-x64"
+ bash -c "flutter pub get && flutter build apk --dart-define=DEMO_MODE=true --release --target-platform android-x64"
mkdir -p dist
APK="$(ls -1 build/app/outputs/flutter-apk/*.apk | head -n1)"
@@ -98,7 +98,7 @@ jobs:
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -lc "flutter pub get && flutter build apk --dart-define=DEMO_MODE=true --release --target-platform android-arm64"
+ bash -c "flutter pub get && flutter build apk --dart-define=DEMO_MODE=true --release --target-platform android-arm64"
mkdir -p dist
APK="$(ls -1 build/app/outputs/flutter-apk/*.apk | head -n1)"
@@ -142,7 +142,7 @@ jobs:
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -lc "flutter pub get && flutter build apk --dart-define=DEMO_MODE=true --release --target-platform android-arm"
+ bash -c "flutter pub get && flutter build apk --dart-define=DEMO_MODE=true --release --target-platform android-arm"
mkdir -p dist
APK="$(ls -1 build/app/outputs/flutter-apk/*.apk | head -n1)"
@@ -186,7 +186,7 @@ jobs:
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -lc "flutter pub get && flutter build appbundle --dart-define=DEMO_MODE=true --release"
+ bash -c "flutter pub get && flutter build appbundle --dart-define=DEMO_MODE=true --release"
mkdir -p dist
cp -v build/app/outputs/bundle/release/app-release.aab "dist/skylight-wallet-${VERSION}.aab"
@@ -219,7 +219,7 @@ jobs:
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -lc "flutter pub get && ./appimage/build_appimage.sh --version ${VERSION}"
+ bash -c "flutter pub get && ./appimage/build_appimage.sh --version ${VERSION}"
mkdir -p dist
cp -v appimage/skylight-wallet-*.AppImage dist/
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.