Prevent artifacts from being committed in monero_c build workflow
What changed, and why it matters
This change stops a GitHub Actions workflow from accidentally including pre-built binary files (called 'artifacts') when it creates automated pull requests. Those binaries were being deleted from the repository and the workflow now removes them before opening a PR. This is a repository hygiene and supply-chain safety fix, not a direct vulnerability in running software.
No immediate user action required. Reviewers should verify that the artifacts directory is properly ignored (e.g., via .gitignore) and that the CI build reproducibly produces the expected libraries elsewhere. Consider adding artifact retention only in CI outputs, not in the source tree.
Security signals we found
Pre-built native binaries removed from source repository
CI workflow now cleans build artifacts before creating pull requests
Potential supply-chain/reproducibility risk from stale or unreviewed artifacts being committed automatically
Evidence from the diff
The commit modifies .github/workflows/build-monero-c.yml to add an ‘rm -rf artifacts’ step before the ‘Create Pull Request’ action. It also deletes four compiled shared-library artifacts (libmonero_libwallet2_api_c.so / monero_libwallet2_api_c.so) for Android and GNU/Linux architectures that had been committed to the repo. The intent is to prevent the create-pull-request action from committing or re-committing build outputs, which could otherwise pollute the repository with untracked or stale binaries and complicate reproducibility and supply-chain verification.
Changed components
.github/workflows/build-monero-c.ymlartifacts/aarch64-linux-android/libmonero_libwallet2_api_c.soartifacts/armv7a-linux-androideabi/libmonero_libwallet2_api_c.soartifacts/x86_64-linux-android/libmonero_libwallet2_api_c.soartifacts/x86_64-linux-gnu/monero_libwallet2_api_c.soInspect captured patch +3 / −0
diff --git a/.github/workflows/build-monero-c.yml b/.github/workflows/build-monero-c.yml
index 4864364..84871b8 100644
--- a/.github/workflows/build-monero-c.yml
+++ b/.github/workflows/build-monero-c.yml
@@ -166,6 +166,9 @@ jobs:
COMMIT_HASH=$(git ls-remote https://github.com/vtnerd/monero_c refs/heads/lwsf | cut -f1)
sed -i "s/resolved-ref: \"[a-f0-9]*\"/resolved-ref: \"${COMMIT_HASH}\"/" pubspec.lock
+ - name: Clean up artifacts
+ run: rm -rf artifacts
+
- name: Create Pull Request
uses: peter-evans/create-pull-request@v8
with:
diff --git a/artifacts/aarch64-linux-android/libmonero_libwallet2_api_c.so b/artifacts/aarch64-linux-android/libmonero_libwallet2_api_c.so
deleted file mode 100644
index 946a8be..0000000
Binary files a/artifacts/aarch64-linux-android/libmonero_libwallet2_api_c.so and /dev/null differ
diff --git a/artifacts/armv7a-linux-androideabi/libmonero_libwallet2_api_c.so b/artifacts/armv7a-linux-androideabi/libmonero_libwallet2_api_c.so
deleted file mode 100644
index 5883370..0000000
Binary files a/artifacts/armv7a-linux-androideabi/libmonero_libwallet2_api_c.so and /dev/null differ
diff --git a/artifacts/x86_64-linux-android/libmonero_libwallet2_api_c.so b/artifacts/x86_64-linux-android/libmonero_libwallet2_api_c.so
deleted file mode 100644
index f05b923..0000000
Binary files a/artifacts/x86_64-linux-android/libmonero_libwallet2_api_c.so and /dev/null differ
diff --git a/artifacts/x86_64-linux-gnu/monero_libwallet2_api_c.so b/artifacts/x86_64-linux-gnu/monero_libwallet2_api_c.so
deleted file mode 100644
index e98cf04..0000000
Binary files a/artifacts/x86_64-linux-gnu/monero_libwallet2_api_c.so and /dev/null differ
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.