What changed, and why it matters
This commit makes two small build-pipeline changes: it pins Windows release builds to a specific older Windows Server 2022 runner image instead of the latest one, and it updates the expected checksum and filename for the AppImage build tool downloaded during Linux release builds. There is no direct evidence in the commit that these changes fix a security vulnerability. The most plausible security-relevant effect is supply-chain risk reduction: pinning the Windows runner avoids unexpected changes from future 'windows-latest' updates, and updating the AppImage tool checksum ensures the downloaded build tool matches a known version. However, the commit message gives no security context, so this is speculative.
Treat as routine build maintenance unless the project later publishes a security advisory. Reviewers may verify the new appimagetool SHA256 against the official go-appimage release page and confirm the windows-2022 runner still receives security updates. No immediate user action is indicated.
Security signals we found
Build pipeline runner pinned from floating 'windows-latest' to specific 'windows-2022' image
AppImage build tool checksum and version updated, maintaining integrity verification
No changes to application source, wallet logic, or runtime dependencies
Commit title and message provide no security rationale or disclosure
Evidence from the diff
The diff modifies .github/workflows/release.yml to change the GitHub Actions runner label from windows-latest to windows-2022, and updates appimage/build_appimage.sh to reference appimagetool-947-x86_64.AppImage with SHA256 5b70a2a259606ce89ae35433fc2816426defaaedafce8aeab163931a89f7347b (previously appimagetool-940 with f9cd2ea644b4a6a8fdd6966642511f0f3c76aa4a81f58c07f102f369d50a5292). Both changes are build-time supply-chain hardening measures. No runtime code, cryptography, wallet logic, or dependency resolution is changed. No CVE, advisory, researcher credit, or vendor security statement is present in the supplied materials.
Changed components
.github/workflows/release.ymlappimage/build_appimage.shInspect captured patch +3 / −3
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index c8ef0a6..0672361 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -199,7 +199,7 @@ jobs:
build-windows:
name: Windows (x64)
- runs-on: windows-latest
+ runs-on: windows-2022
environment: Release
needs: version
steps:
diff --git a/appimage/build_appimage.sh b/appimage/build_appimage.sh
index e6786a9..80ad77a 100755
--- a/appimage/build_appimage.sh
+++ b/appimage/build_appimage.sh
@@ -111,8 +111,8 @@ chmod +x AppDir/AppRun
# Expected SHA256 hash - update this when updating appimagetool
# Verify from: https://github.com/probonopd/go-appimage/releases
# Run: sha256sum appimagetool-x86_64.AppImage
-EXPECTED_SHA256="f9cd2ea644b4a6a8fdd6966642511f0f3c76aa4a81f58c07f102f369d50a5292"
-APPIMAGETOOL_FILENAME="appimagetool-940-x86_64.AppImage"
+EXPECTED_SHA256="5b70a2a259606ce89ae35433fc2816426defaaedafce8aeab163931a89f7347b"
+APPIMAGETOOL_FILENAME="appimagetool-947-x86_64.AppImage"
# Download appimagetool from go-appimage if not present
if [ ! -f "$APPIMAGETOOL_FILENAME" ]; then
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.