Revert incorrect conflict resolution.
What changed, and why it matters
This commit simply removes a GitHub Actions workflow job that automatically packaged and published release files when a new version tag was created. It is a routine revert of a previous merge-conflict resolution and does not change any wallet code, cryptography, or user-facing security behavior.
No security action required. Treat as ordinary CI/CD maintenance. If automated releases are desired, reintroduce the job intentionally rather than through conflict resolution.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff deletes the ‘release’ job from .github/workflows/build.yaml. That job ran only on tag pushes, downloaded build artifacts from prior jobs, zipped Windows artifacts, moved selected archives/APKs/IPAs/Flatpaks into a release-files directory, and created a GitHub release via softprops/action-gh-release. Removing it disables automated release creation; it does not modify source code, build scripts, secrets handling, or permissions beyond the removed job.
Changed components
.github/workflows/build.yamlInspect captured patch +0 / −27
diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml
index d6c04fd..462c524 100644
--- a/.github/workflows/build.yaml
+++ b/.github/workflows/build.yaml
@@ -1655,30 +1655,3 @@ jobs:
name: stack_duo-appimage-x86_64-${{ steps.ver.outputs.version }}.AppImage
path: stack_duo-appimage-x86_64-${{ steps.ver.outputs.version }}.AppImage
- release:
- if: github.ref_type == 'tag'
- needs: [build-linux, build-android, build-windows, build-macos, build-ios, build-flatpak]
- runs-on: ubuntu-latest
- permissions:
- contents: write
- steps:
- - uses: actions/download-artifact@v4
- with:
- path: artifacts
-
- - name: Package artifacts
- run: |
- mkdir -p release-files
- for dir in artifacts/stack_wallet-windows-*/; do
- [ -d "$dir" ] || continue
- name=$(basename "$dir")
- (cd "$dir" && zip -r "../../release-files/${name}.zip" .)
- done
- find artifacts/ \( -name "*.tar.gz" -o -name "*.zip" -o -name "*.ipa" -o -name "*.flatpak" \) -mindepth 2 -exec mv {} release-files/ \;
- find artifacts/ -name "*.apk" -mindepth 2 -exec mv {} release-files/ \;
-
- - uses: softprops/action-gh-release@v2
- with:
- generate_release_notes: true
- files: release-files/*
-
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.