What changed, and why it matters
This commit updates dependency versions for Xelis cryptocurrency support in Stack Wallet. It switches from the upstream xelis-flutter-ffi library to a fork maintained by Cypher Stack (the same organization as the wallet), and bumps flutter_rust_bridge from 2.12.0 to 2.13.0. The commit title says 'xelis native assets,' suggesting feature work rather than a security fix. There is no direct evidence in the diff or commit message of a vulnerability or security issue.
Treat as routine dependency/feature update unless additional context emerges. If assessing supply-chain risk, review the differences between the old upstream xelis-flutter-ffi ref and the new Cypher Stack fork ref, and verify the flutter_rust_bridge 2.13.0 changelog for any security advisories. No immediate security action is indicated by this commit alone.
Security signals we found
Dependency source changed from upstream repository to vendor-owned fork
Dependency version bump for flutter_rust_bridge and xelis_flutter FFI
No explicit security fix, CVE reference, or vulnerability description present in commit
No code-level security signals visible in the supplied diff
Evidence from the diff
The diff only touches pubspec.lock and a pubspec.template.yaml. It changes the xelis_flutter git dependency from https://github.com/xelis-project/xelis-flutter-ffi.git at ref 3e5ac06c22956a9113a88a2d38ba82f8787be1c6 (v0.2.0) to https://github.com/cypherstack/xelis-flutter-ffi.git at ref 07a89303aacbeec6386e357287b6fd9fcca77d94 (v0.4.0). It also updates flutter_rust_bridge from 2.12.0 to 2.13.0 and adds flutter_rust_bridge_hooks 2.13.0 as a transitive dependency. No application code, cryptographic logic, or security-sensitive configuration is modified in the visible diff.
Changed components
pubspec.lockscripts/app_config/templates/pubspec.template.yamlxelis_flutter FFI dependencyflutter_rust_bridge transitive dependencyInspect captured patch +16 / −8
diff --git a/pubspec.lock b/pubspec.lock
index 3154cf6..baef70d 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -1128,10 +1128,18 @@ packages:
dependency: transitive
description:
name: flutter_rust_bridge
- sha256: e87d6b9ee934dcd24a128ccb2bd91905d2d5fe5c06245d6a8f5477d4907a437a
+ sha256: ec69331e2335ab4d456c0a9fc700892c2c85b72b9c0cb39df3ecfe8833d5d5c8
url: "https://pub.dev"
source: hosted
- version: "2.12.0"
+ version: "2.13.0"
+ flutter_rust_bridge_hooks:
+ dependency: transitive
+ description:
+ name: flutter_rust_bridge_hooks
+ sha256: "19900fbcaa8ddc2a4f1b13994ef34393eda129ebccc59ceb887a8fd2cf5def3e"
+ url: "https://pub.dev"
+ source: hosted
+ version: "2.13.0"
flutter_secure_storage:
dependency: "direct main"
description:
@@ -2692,11 +2700,11 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: "3e5ac06c22956a9113a88a2d38ba82f8787be1c6"
- resolved-ref: "3e5ac06c22956a9113a88a2d38ba82f8787be1c6"
- url: "https://github.com/xelis-project/xelis-flutter-ffi.git"
+ ref: "07a89303aacbeec6386e357287b6fd9fcca77d94"
+ resolved-ref: "07a89303aacbeec6386e357287b6fd9fcca77d94"
+ url: "https://github.com/cypherstack/xelis-flutter-ffi.git"
source: git
- version: "0.2.0"
+ version: "0.4.0"
xml:
dependency: transitive
description:
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 89fa4f4..66319da 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -38,8 +38,8 @@ dependencies:
## ref: f1da98f8bad8b9ad3645661a23f9efb83e44b0c9
# xelis_flutter:
# git:
-# url: https://github.com/xelis-project/xelis-flutter-ffi.git
-# ref: 3e5ac06c22956a9113a88a2d38ba82f8787be1c6
+# url: https://github.com/cypherstack/xelis-flutter-ffi.git
+# ref: 07a89303aacbeec6386e357287b6fd9fcca77d94
# %%END_ENABLE_XEL%%
# %%ENABLE_FIRO%%
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.