Remove debug code and bump buid number
What changed, and why it matters
This commit removes a single line of leftover debug code that was causing a fake incoming-transaction notification to appear every time the wallet home screen loaded. It also bumps the app's build number. There is no obvious security vulnerability in the removed code, but shipping debug notifications in a production build is a quality and trust issue.
No urgent security action is required. Reviewers may want to confirm that no other debug-only code remains in release builds and that the notification service cannot be triggered by untrusted input elsewhere.
Security signals we found
Removal of hard-coded debug notification call
No input validation, injection, or cryptographic changes present
No authentication, authorization, or secret-handling changes present
Evidence from the diff
The change deletes NotificationService().showIncomingTxNotification(1); from initState() in lib/screens/wallet_home.dart and increments the build number in pubspec.yaml from 1.0.4+8 to 1.0.4+9. The deleted line was a hard-coded call that displayed a notification with a fixed transaction ID of 1 whenever the wallet home screen initialized. This appears to be a leftover debugging aid rather than an exploitable flaw.
Changed components
lib/screens/wallet_home.dartpubspec.yamlInspect captured patch +1 / −3
diff --git a/lib/screens/wallet_home.dart b/lib/screens/wallet_home.dart
index fa84e68..61f1864 100644
--- a/lib/screens/wallet_home.dart
+++ b/lib/screens/wallet_home.dart
@@ -162,8 +162,6 @@ class _WalletHomeScreenState extends State<WalletHomeScreen> {
void initState() {
super.initState();
- NotificationService().showIncomingTxNotification(1);
-
WidgetsBinding.instance.addPostFrameCallback((_) {
final Map<String, dynamic>? args =
ModalRoute.of(context)?.settings.arguments as Map<String, dynamic>?;
diff --git a/pubspec.yaml b/pubspec.yaml
index 1c858cb..1a7b780 100644
--- a/pubspec.yaml
+++ b/pubspec.yaml
@@ -16,7 +16,7 @@ publish_to: "none" # Remove this line if you wish to publish to pub.dev
# https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html
# In Windows, build-name is used as the major, minor, and patch parts
# of the product and file versions while build-number is used as the build suffix.
-version: 1.0.4+8
+version: 1.0.4+9
environment:
sdk: 3.10.7
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.