What changed, and why it matters
This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is no indication of a security vulnerability being fixed; it is purely a build/maintenance change.
No security action required. Treat as a routine CI/build fix.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The release workflow is updated to (1) run a script that pins the Rust toolchain before building the Linux package, matching the Android job, so that cargokit uses the same toolchain declared in rust-toolchain.toml rather than downloading ‘stable’ mid-build; and (2) install NASM via Chocolatey and add it to PATH on the Windows runner, because webcrypto’s BoringSSL build requires Windows assembly. The pubspec version/build number is also bumped from 411 to 412. No source-code behavior of the wallet application is changed.
Changed components
.github/workflows/release.ymlpubspec.yamlInspect captured patch +11 / −2
### .github/workflows/release.yml
@@ -182,12 +182,15 @@ jobs:
- name: Build Linux packages
run: |
+ # cargokit builds the Rust plugins with `rustup run stable`, and the
+ # image only has the rust-toolchain.toml version, so pin cargokit to it
+ # (as the Android job does) instead of downloading stable mid-build.
VERSION='${{ needs.version.outputs.version }}'
docker run --rm \
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -c "flutter pub get && flutter build linux --release && ./deb/build_deb.sh --version ${VERSION} && ./appimage/build_appimage.sh --version ${VERSION}"
+ bash -c "flutter pub get && bash scripts/pin-rust-toolchain.sh && flutter build linux --release && ./deb/build_deb.sh --version ${VERSION} && ./appimage/build_appimage.sh --version ${VERSION}"
mkdir -p dist
cp -v deb/skylight-wallet-*.deb dist/
@@ -224,6 +227,12 @@ jobs:
- name: Install Inno Setup
run: choco install innosetup -y
+ # webcrypto builds BoringSSL, whose Windows assembly needs NASM.
+ - name: Install NASM
+ run: |
+ choco install nasm -y
+ echo "C:\Program Files\NASM" >> $env:GITHUB_PATH
+
- name: Set up Rust
uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
with:
### pubspec.yaml
@@ -16,7 +16,7 @@ publish_to: "none" # Remove this line if you wish to publish to pub.dev
# https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html
# In Windows, build-name is used as the major, minor, and patch parts
# of the product and file versions while build-number is used as the build suffix.
-version: 2.1.0+411
+version: 2.1.0+412
environment:
sdk: 3.11.5Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.