What changed, and why it matters
This commit updates several third-party software libraries (dependencies) and adjusts the code that shares QR-code images so it uses the newer library's API. It is a routine maintenance/cleanup change. There is no direct evidence in the commit that it fixes a security vulnerability, but keeping dependencies up to date can remove known bugs in older library versions.
Treat as routine maintenance. Verify the upgraded dependencies do not introduce regressions in QR sharing on supported platforms. Review the changelogs of share_plus, device_info_plus, connectivity_plus, desktop_drop, and camera_macos for any security advisories relevant to the old versions being replaced, and consider documenting any security-relevant fixes in release notes.
Security signals we found
Dependency version bumps may address known issues in older packages, but no specific CVE or advisory is referenced in the commit
share_plus major-version upgrade changes the file-sharing API; old API is deprecated/removed
Removal of multiple dependency_overrides reduces technical debt and potential fork/maintenance risk
No direct code changes to cryptography, wallet signing, or authentication logic
Evidence from the diff
The diff bumps versions in pubspec.template.yaml and pubspec.lock for share_plus (7.0.2 -> 12.0.2), device_info_plus, connectivity_plus, desktop_drop, camera_macos, and flutter-devicelocale. It removes several dependency_overrides (win32, wakelock_windows, bip47, json_rpc_2) and converts Share.shareFiles(…) calls to SharePlus.instance.share(ShareParams(files: [XFile(…)])) across receive-view and FROST QR dialogs. The changes are API migrations and cleanup, with no explicit security claim.
Changed components
pubspec dependency resolutionshare_plus integrationlib/pages/receive_view/addresses/address_card.dartlib/pages/receive_view/addresses/address_qr_popup.dartlib/pages/receive_view/generate_receiving_uri_qr_code_view.dartlib/widgets/dialogs/frost/frost_step_qr_dialog.dartInspect captured patch +88 / −124
diff --git a/lib/pages/receive_view/addresses/address_card.dart b/lib/pages/receive_view/addresses/address_card.dart
index f8b6ec8..0cd361f 100644
--- a/lib/pages/receive_view/addresses/address_card.dart
+++ b/lib/pages/receive_view/addresses/address_card.dart
@@ -132,9 +132,12 @@ class _AddressCardState extends ConsumerState<AddressCard> {
final file = await File("${tempDir.path}/qrcode.png").create();
await file.writeAsBytes(pngBytes);
- await Share.shareFiles([
- "${tempDir.path}/qrcode.png",
- ], text: "Receive URI QR Code");
+ await SharePlus.instance.share(
+ ShareParams(
+ files: [XFile("${tempDir.path}/qrcode.png")],
+ text: "Receive URI QR Code",
+ ),
+ );
}
} catch (e) {
//todo: comeback to this
diff --git a/lib/pages/receive_view/addresses/address_qr_popup.dart b/lib/pages/receive_view/addresses/address_qr_popup.dart
index b4446f5..6af226f 100644
--- a/lib/pages/receive_view/addresses/address_qr_popup.dart
+++ b/lib/pages/receive_view/addresses/address_qr_popup.dart
@@ -58,8 +58,9 @@ class _AddressQrPopupState extends State<AddressQrPopup> {
final RenderRepaintBoundary boundary =
_qrKey.currentContext?.findRenderObject() as RenderRepaintBoundary;
final ui.Image image = await boundary.toImage();
- final ByteData? byteData =
- await image.toByteData(format: ui.ImageByteFormat.png);
+ final ByteData? byteData = await image.toByteData(
+ format: ui.ImageByteFormat.png,
+ );
final Uint8List pngBytes = byteData!.buffer.asUint8List();
if (shouldSaveInsteadOfShare) {
@@ -67,7 +68,8 @@ class _AddressQrPopupState extends State<AddressQrPopup> {
final dir = Directory("${Platform.environment['HOME']}");
if (!dir.existsSync()) {
throw Exception(
- "Home dir not found while trying to open filepicker on QR image save",
+ "Home dir not found while trying to open filepicker on QR image"
+ " save",
);
}
final path = await FilePicker.platform.saveFile(
@@ -107,9 +109,11 @@ class _AddressQrPopupState extends State<AddressQrPopup> {
final file = await File("${tempDir.path}/qrcode.png").create();
await file.writeAsBytes(pngBytes);
- await Share.shareFiles(
- ["${tempDir.path}/qrcode.png"],
- text: "Receive URI QR Code",
+ await SharePlus.instance.share(
+ ShareParams(
+ files: [XFile("${tempDir.path}/qrcode.png")],
+ text: "Receive URI QR Code",
+ ),
);
}
} catch (e) {
@@ -123,20 +127,10 @@ class _AddressQrPopupState extends State<AddressQrPopup> {
return StackDialogBase(
child: Column(
children: [
- Text(
- "todo: custom label",
- style: STextStyles.pageTitleH2(context),
- ),
- const SizedBox(
- height: 8,
- ),
- Text(
- widget.addressString,
- style: STextStyles.itemSubtitle(context),
- ),
- const SizedBox(
- height: 16,
- ),
+ Text("Address", style: STextStyles.pageTitleH2(context)),
+ const SizedBox(height: 8),
+ Text(widget.addressString, style: STextStyles.itemSubtitle(context)),
+ const SizedBox(height: 16),
Center(
child: RepaintBoundary(
key: _qrKey,
@@ -150,9 +144,7 @@ class _AddressQrPopupState extends State<AddressQrPopup> {
),
),
),
- const SizedBox(
- height: 16,
- ),
+ const SizedBox(height: 16),
Row(
children: [
Expanded(
@@ -167,15 +159,13 @@ class _AddressQrPopupState extends State<AddressQrPopup> {
Assets.svg.share,
width: 20,
height: 20,
- color: Theme.of(context)
- .extension<StackColors>()!
- .buttonTextSecondary,
+ color: Theme.of(
+ context,
+ ).extension<StackColors>()!.buttonTextSecondary,
),
),
),
- const SizedBox(
- width: 16,
- ),
+ const SizedBox(width: 16),
Expanded(
child: PrimaryButton(
width: 170,
@@ -187,9 +177,9 @@ class _AddressQrPopupState extends State<AddressQrPopup> {
Assets.svg.arrowDown,
width: 20,
height: 20,
- color: Theme.of(context)
- .extension<StackColors>()!
- .buttonTextPrimary,
+ color: Theme.of(
+ context,
+ ).extension<StackColors>()!.buttonTextPrimary,
),
),
),
diff --git a/lib/pages/receive_view/generate_receiving_uri_qr_code_view.dart b/lib/pages/receive_view/generate_receiving_uri_qr_code_view.dart
index 203e0a0..adeb67c 100644
--- a/lib/pages/receive_view/generate_receiving_uri_qr_code_view.dart
+++ b/lib/pages/receive_view/generate_receiving_uri_qr_code_view.dart
@@ -16,8 +16,8 @@ import 'dart:ui' as ui;
// import 'package:document_file_save_plus/document_file_save_plus.dart';
import 'package:file_picker/file_picker.dart';
import 'package:flutter/material.dart';
-import 'package:flutter_riverpod/flutter_riverpod.dart';
import 'package:flutter/rendering.dart';
+import 'package:flutter_riverpod/flutter_riverpod.dart';
import 'package:flutter_svg/svg.dart';
import 'package:path_provider/path_provider.dart';
import 'package:share_plus/share_plus.dart';
@@ -139,9 +139,12 @@ class _GenerateUriQrCodeViewState extends ConsumerState<GenerateUriQrCodeView> {
final file = await File("${tempDir.path}/qrcode.png").create();
await file.writeAsBytes(pngBytes);
- await Share.shareFiles([
- "${tempDir.path}/qrcode.png",
- ], text: "Receive URI QR Code");
+ await SharePlus.instance.share(
+ ShareParams(
+ files: [XFile("${tempDir.path}/qrcode.png")],
+ text: "Receive URI QR Code",
+ ),
+ );
}
} catch (e) {
//todo: comeback to this
diff --git a/lib/widgets/dialogs/frost/frost_step_qr_dialog.dart b/lib/widgets/dialogs/frost/frost_step_qr_dialog.dart
index 949e2fe..81f3400 100644
--- a/lib/widgets/dialogs/frost/frost_step_qr_dialog.dart
+++ b/lib/widgets/dialogs/frost/frost_step_qr_dialog.dart
@@ -7,7 +7,6 @@ import 'package:flutter/material.dart';
import 'package:flutter/rendering.dart';
import 'package:flutter_svg/flutter_svg.dart';
import 'package:path_provider/path_provider.dart';
-
import 'package:share_plus/share_plus.dart';
import '../../../notifications/show_flush_bar.dart';
@@ -94,9 +93,11 @@ class _FrostStepQrDialogState extends State<FrostStepQrDialog> {
final file = await File("${tempDir.path}/qrcode.png").create();
await file.writeAsBytes(pngBytes);
- await Share.shareFiles(
- ["${tempDir.path}/qrcode.png"],
- text: "Receive URI QR Code",
+ await SharePlus.instance.share(
+ ShareParams(
+ files: [XFile("${tempDir.path}/qrcode.png")],
+ text: "Receive URI QR Code",
+ ),
);
}
} catch (e) {
@@ -124,21 +125,18 @@ class _FrostStepQrDialogState extends State<FrostStepQrDialog> {
Text(
widget.myName,
style: STextStyles.w600_16(context).copyWith(
- color: Theme.of(context)
- .extension<StackColors>()!
- .customTextButtonEnabledText,
+ color: Theme.of(
+ context,
+ ).extension<StackColors>()!.customTextButtonEnabledText,
),
),
const SizedBox(height: 8),
- Text(
- widget.title,
- style: STextStyles.w600_12(context),
- ),
+ Text(widget.title, style: STextStyles.w600_12(context)),
const SizedBox(height: 8),
RoundedContainer(
- color: Theme.of(context)
- .extension<StackColors>()!
- .textFieldDefaultBG,
+ color: Theme.of(
+ context,
+ ).extension<StackColors>()!.textFieldDefaultBG,
radiusMultiplier: 1,
child: Column(
crossAxisAlignment: CrossAxisAlignment.center,
@@ -146,9 +144,7 @@ class _FrostStepQrDialogState extends State<FrostStepQrDialog> {
ConditionalParent(
condition: Util.isDesktop,
builder: (child) => ConstrainedBox(
- constraints: const BoxConstraints(
- maxWidth: 360,
- ),
+ constraints: const BoxConstraints(maxWidth: 360),
child: child,
),
child: Padding(
@@ -174,10 +170,7 @@ class _FrostStepQrDialogState extends State<FrostStepQrDialog> {
),
),
),
- if (!Util.isDesktop)
- const SizedBox(
- height: 16,
- ),
+ if (!Util.isDesktop) const SizedBox(height: 16),
if (!Util.isDesktop)
Row(
children: [
@@ -190,9 +183,9 @@ class _FrostStepQrDialogState extends State<FrostStepQrDialog> {
Assets.svg.share,
width: 14,
height: 14,
- color: Theme.of(context)
- .extension<StackColors>()!
- .buttonTextSecondary,
+ color: Theme.of(
+ context,
+ ).extension<StackColors>()!.buttonTextSecondary,
),
onPressed: () async {
await _capturePng(false);
diff --git a/pubspec.lock b/pubspec.lock
index e85d3e8..441fae0 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -252,10 +252,10 @@ packages:
dependency: "direct main"
description:
name: camera_macos
- sha256: a0e15729caf4e7c2831b9cd964e8c2e2ea985cd816e56316be03355de44aa743
+ sha256: "64e199368efb0dc12c5298819df98aada4fe2cc50a5d84997f7bf7d94edaa3f8"
url: "https://pub.dev"
source: hosted
- version: "0.0.9"
+ version: "0.1.1"
camera_platform_interface:
dependency: "direct main"
description:
@@ -376,18 +376,18 @@ packages:
dependency: "direct main"
description:
name: connectivity_plus
- sha256: "77a180d6938f78ca7d2382d2240eb626c0f6a735d0bfdce227d8ffb80f95c48b"
+ sha256: "762c99f890ca8bf87f7337236f99edd42793843bc6c3631da294a76653a54bd0"
url: "https://pub.dev"
source: hosted
- version: "4.0.2"
+ version: "7.3.1"
connectivity_plus_platform_interface:
dependency: transitive
description:
name: connectivity_plus_platform_interface
- sha256: cf1d1c28f4416f8c654d7dc3cd638ec586076255d407cef3ddbdaf178272a71a
+ sha256: "3c09627c536d22fd24691a905cdd8b14520de69da52c7a97499c8be5284a32ed"
url: "https://pub.dev"
source: hosted
- version: "1.2.4"
+ version: "2.1.0"
convert:
dependency: "direct main"
description:
@@ -777,18 +777,18 @@ packages:
dependency: "direct main"
description:
name: desktop_drop
- sha256: d55a010fe46c8e8fcff4ea4b451a9ff84a162217bdb3b2a0aa1479776205e15d
+ sha256: aa1e797255bfbc76f9eb5aa4f61e5b68dbf69962ab1be6495816d2f251bc0d1f
url: "https://pub.dev"
source: hosted
- version: "0.4.4"
+ version: "0.7.1"
device_info_plus:
dependency: "direct main"
description:
name: device_info_plus
- sha256: a7fd703482b391a87d60b6061d04dfdeab07826b96f9abd8f5ed98068acc0074
+ sha256: b4fed1b2835da9d670d7bed7db79ae2a94b0f5ad6312268158a9b5479abbacdd
url: "https://pub.dev"
source: hosted
- version: "10.1.2"
+ version: "12.4.0"
device_info_plus_platform_interface:
dependency: transitive
description:
@@ -801,11 +801,11 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: ba7d7d87a3772e972adb1358a5ec9a111b514fce
- resolved-ref: ba7d7d87a3772e972adb1358a5ec9a111b514fce
+ ref: "73c4ed946816c5ec032d13a44f8f510e2ced9886"
+ resolved-ref: "73c4ed946816c5ec032d13a44f8f510e2ced9886"
url: "https://github.com/cypherstack/flutter-devicelocale"
source: git
- version: "0.8.1"
+ version: "0.9.0"
digest_auth:
dependency: "direct main"
description:
@@ -1430,7 +1430,7 @@ packages:
source: hosted
version: "4.12.0"
json_rpc_2:
- dependency: "direct overridden"
+ dependency: transitive
description:
name: json_rpc_2
sha256: "82dfd37d3b2e5030ae4729e1d7f5538cbc45eb1c73d618b9272931facac3bec1"
@@ -2013,18 +2013,18 @@ packages:
dependency: "direct main"
description:
name: share_plus
- sha256: "3ef39599b00059db0990ca2e30fca0a29d8b37aae924d60063f8e0184cf20900"
+ sha256: "223873d106614442ea6f20db5a038685cc5b32a2fba81cdecaefbbae0523f7fa"
url: "https://pub.dev"
source: hosted
- version: "7.2.2"
+ version: "12.0.2"
share_plus_platform_interface:
dependency: transitive
description:
name: share_plus_platform_interface
- sha256: "251eb156a8b5fa9ce033747d73535bf53911071f8d3b6f4f0b578505ce0d4496"
+ sha256: "88023e53a13429bd65d8e85e11a9b484f49d4c190abbd96c7932b74d6927cc9a"
url: "https://pub.dev"
source: hosted
- version: "3.4.0"
+ version: "6.1.0"
shelf:
dependency: transitive
description:
@@ -2338,6 +2338,14 @@ packages:
url: "https://pub.dev"
source: hosted
version: "2.3.1"
+ universal_platform:
+ dependency: transitive
+ description:
+ name: universal_platform
+ sha256: "64e16458a0ea9b99260ceb5467a214c1f298d647c659af1bff6d3bf82536b1ec"
+ url: "https://pub.dev"
+ source: hosted
+ version: "1.1.0"
unorm_dart:
dependency: "direct main"
description:
@@ -2466,14 +2474,6 @@ packages:
url: "https://pub.dev"
source: hosted
version: "15.0.2"
- wakelock_platform_interface:
- dependency: transitive
- description:
- name: wakelock_platform_interface
- sha256: "1f4aeb81fb592b863da83d2d0f7b8196067451e4df91046c26b54a403f9de621"
- url: "https://pub.dev"
- source: hosted
- version: "0.3.0"
wakelock_plus:
dependency: "direct main"
description:
@@ -2490,15 +2490,6 @@ packages:
url: "https://pub.dev"
source: hosted
version: "1.4.0"
- wakelock_windows:
- dependency: "direct overridden"
- description:
- path: wakelock_windows
- ref: "2a9bca63a540771f241d688562351482b2cf234c"
- resolved-ref: "2a9bca63a540771f241d688562351482b2cf234c"
- url: "https://github.com/diegotori/wakelock"
- source: git
- version: "0.2.2"
wallet:
dependency: "direct main"
description:
@@ -2572,7 +2563,7 @@ packages:
source: hosted
version: "1.2.1"
win32:
- dependency: "direct overridden"
+ dependency: transitive
description:
name: win32
sha256: d7cb55e04cd34096cd3a79b3330245f54cb96a370a1c27adb3c84b917de8b08e
@@ -2583,10 +2574,10 @@ packages:
dependency: transitive
description:
name: win32_registry
- sha256: "21ec76dfc731550fd3e2ce7a33a9ea90b828fdf19a5c3bcf556fa992cfa99852"
+ sha256: "6f1b564492d0147b330dd794fee8f512cec4977957f310f9951b5f9d83618dae"
url: "https://pub.dev"
source: hosted
- version: "1.1.5"
+ version: "2.1.0"
window_size:
dependency: "direct main"
description:
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 61556b0..e6b4fe9 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -173,20 +173,20 @@ dependencies:
devicelocale:
git:
url: https://github.com/cypherstack/flutter-devicelocale
- ref: ba7d7d87a3772e972adb1358a5ec9a111b514fce
- device_info_plus: ^10.1.2
+ ref: 73c4ed946816c5ec032d13a44f8f510e2ced9886
+ device_info_plus: ^12.4.0
keyboard_dismisser: ^3.0.0
another_flushbar: ^1.10.28
tuple: ^2.0.0
flutter_riverpod: ^1.0.3
qr_flutter: ^4.0.0
- share_plus: ^7.0.2
+ share_plus: ^12.0.2
emojis: ^0.9.9
pointycastle: ^4.0.0
package_info_plus: ^8.0.2
lottie: ^3.3.2
file_picker: ^10.3.3
- connectivity_plus: ^4.0.1
+ connectivity_plus: ^7.3.1
isar_community: 3.3.0-dev.2
isar_community_flutter_libs: 3.3.0-dev.2
dropdown_button2: ^2.1.3
@@ -200,7 +200,7 @@ dependencies:
ref: bed60e43e4e509ea45bb097e6caee9f8293ddf98
hex: ^0.2.0
archive: ^4.0.2
- desktop_drop: ^0.4.4
+ desktop_drop: ^0.7.1
nanodart:
git:
url: https://github.com/cypherstack/nanodart
@@ -245,7 +245,7 @@ dependencies:
url: https://github.com/cypherstack/packages.git
path: packages/camera/camera_windows
camera_platform_interface: ^2.8.0
- camera_macos: ^0.0.8
+ camera_macos: ^0.1.1
blockchain_utils: ^3.3.0
on_chain: ^4.0.1
cbor: ^6.3.3
@@ -308,12 +308,9 @@ dependency_overrides:
url: https://github.com/cypherstack/logger
ref: 3c0cba27868ebb5c7d65ebc30a8e6e5342186692
- # required to make devicelocale work
+ # required to make web socket channel work (solana)
web: ^0.5.0
- # needed for dart 3.5+ (at least for now)
- win32: ^5.5.4
-
# coinlib_flutter requires this
coinlib:
git:
@@ -321,24 +318,12 @@ dependency_overrides:
path: coinlib
ref: f0e12dacb6d39e1cb340f0deae178d0fad1d6fd6
- bip47:
- git:
- url: https://github.com/cypherstack/bip47.git
- ref: bdc0c0788d1d6dfb04863a793955f848ba1624a8
-
# bip47 pins a different bitcoindart commit; override to ours
bitcoindart:
git:
url: https://github.com/cypherstack/bitcoindart.git
ref: ea33b1f5d6a701791359a2e180f73866dc667732
- # required for dart 3, at least until a fix is merged upstream
- wakelock_windows:
- git:
- url: https://github.com/diegotori/wakelock
- ref: 2a9bca63a540771f241d688562351482b2cf234c
- path: wakelock_windows
-
# required override for solana, etc
bip39:
git:
@@ -352,7 +337,6 @@ dependency_overrides:
analyzer: ">=8.2.0 <8.4.0"
# xelis override
- json_rpc_2: ^4.0.0
freezed: ^3.1.0
freezed_annotation: ^3.1.0
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.