What changed, and why it matters
This commit updates a SHA256 checksum used to verify the appimagetool download during the wallet's build process. The old hash no longer matched the file being downloaded, which would break builds. The change itself is a routine hash correction, but because the commit only changes the hash and does not show the corresponding appimagetool version or release being updated, it is impossible to confirm from the diff alone whether the new hash matches a legitimate upstream release or a tampered one.
Treat this commit as a build-maintenance change that requires independent verification. A maintainer should confirm that 376998aba63bb3a35a02ea3196f77268f8543a35a3b6b7db0dc2181365119b62 matches the SHA256 of the exact appimagetool-947-x86_64.AppImage artifact published by probonopd/go-appimage at the intended release, and that the artifact has not been re-released or replaced unexpectedly. Consider pinning the download URL to a specific release tag and adding a short note in the script documenting the verified release version.
Security signals we found
Modification of a cryptographic integrity check (SHA256 expected hash)
No accompanying version or URL change for the downloaded artifact
Build script downloads and executes a binary from a third-party repository
Supplied materials do not include upstream release notes or artifact metadata
Evidence from the diff
In appimage/build_appimage.sh the EXPECTED_SHA256 for appimagetool-x86_64.AppImage was changed from 5b70a2a… to 376998ab… The filename remains appimagetool-947-x86_64.AppImage. The comment instructs maintainers to verify the hash against the go-appimage GitHub releases page and to update the hash when updating appimagetool. The diff provides no evidence of which upstream release or artifact version the new hash corresponds to, and no independent verification is included in the supplied materials.
Changed components
appimage/build_appimage.shappimagetool download and verification stepInspect captured patch +1 / −1
diff --git a/appimage/build_appimage.sh b/appimage/build_appimage.sh
index 80ad77a..b13fdea 100755
--- a/appimage/build_appimage.sh
+++ b/appimage/build_appimage.sh
@@ -111,7 +111,7 @@ chmod +x AppDir/AppRun
# Expected SHA256 hash - update this when updating appimagetool
# Verify from: https://github.com/probonopd/go-appimage/releases
# Run: sha256sum appimagetool-x86_64.AppImage
-EXPECTED_SHA256="5b70a2a259606ce89ae35433fc2816426defaaedafce8aeab163931a89f7347b"
+EXPECTED_SHA256="376998aba63bb3a35a02ea3196f77268f8543a35a3b6b7db0dc2181365119b62"
APPIMAGETOOL_FILENAME="appimagetool-947-x86_64.AppImage"
# Download appimagetool from go-appimage if not present
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.