What changed, and why it matters
This commit fixes a GitHub Actions release workflow that was supposed to sign Android and Linux app files with GPG. Before the fix, the signing command likely failed because it could not unlock the GPG private key without a passphrase. The change passes the GPG passphrase from a GitHub secret into the signing step so the automated signing can complete. It is a build-pipeline fix, not a vulnerability in the wallet application itself.
Verify that secrets.GPG_PASSPHRASE is correctly configured in the repository settings and that release artifacts are now producing valid .asc detached signatures. Review CI logs to confirm signing succeeds and that the secret is masked. Consider whether the GPG passphrase should be rotated if it was previously logged in failed runs.
Security signals we found
GPG signing in CI was non-functional before the fix
Passphrase now supplied from GitHub secret to gpg via file descriptor
No application code changed; only release workflow
Potential risk: passphrase exposed as environment variable in CI step, though standard GitHub Actions masking applies to secrets
Evidence from the diff
The release.yml workflow now injects secrets.GPG_PASSPHRASE into the GPG signing step and feeds it to gpg via –passphrase-fd 0. Previously the workflow invoked gpg –batch –yes –pinentry-mode loopback –detach-sign without supplying a passphrase, which would typically fail in a non-interactive CI environment because the private key could not be unlocked. The patch restores intended release artifact signing for APKs, AABs, and AppImages.
Changed components
.github/workflows/release.ymlInspect captured patch +5 / −3
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 9d8a7f0..a087714 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -114,11 +114,13 @@ jobs:
echo "GPG_KEY_ID=$GPG_KEY_ID" >> $GITHUB_ENV
- name: Sign artifacts with GPG
+ env:
+ GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
# Sign Android APKs
for file in build/app/outputs/flutter-apk/*.apk; do
if [ -f "$file" ]; then
- gpg --batch --yes --pinentry-mode loopback --detach-sign --armor "$file"
+ echo "$GPG_PASSPHRASE" | gpg --batch --yes --pinentry-mode loopback --passphrase-fd 0 --detach-sign --armor "$file"
echo "Signed: $file"
fi
done
@@ -126,7 +128,7 @@ jobs:
# Sign Android App Bundle
for file in build/app/outputs/bundle/release/*.aab; do
if [ -f "$file" ]; then
- gpg --batch --yes --pinentry-mode loopback --detach-sign --armor "$file"
+ echo "$GPG_PASSPHRASE" | gpg --batch --yes --pinentry-mode loopback --passphrase-fd 0 --detach-sign --armor "$file"
echo "Signed: $file"
fi
done
@@ -134,7 +136,7 @@ jobs:
# Sign Linux AppImage
for file in appimage/skylight-wallet-*.AppImage; do
if [ -f "$file" ]; then
- gpg --batch --yes --pinentry-mode loopback --detach-sign --armor "$file"
+ echo "$GPG_PASSPHRASE" | gpg --batch --yes --pinentry-mode loopback --passphrase-fd 0 --detach-sign --armor "$file"
echo "Signed: $file"
fi
done
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.