What changed, and why it matters
This commit changes the Stack Wallet app to download a cryptocurrency library (xelis_flutter) from a different GitHub account and a specific commit hash instead of a numbered release version. On its own, this is a routine dependency update, but it also introduces supply-chain risk: the app now trusts code from a fork controlled by the Stack Wallet team rather than the original xelis-project repository, and it pins an exact commit rather than a tagged release. There is no evidence in the commit that this fixes a known security bug or that the change itself is malicious.
Treat this as a supply-chain hygiene check. Verify that the cypherstack/xelis-flutter-ffi fork is an authorized, auditable mirror or fork of the upstream project. Review the differences between upstream tag v0.1.1 and commit 5dd5c50713160fa15fb06ff44886ae035eed62fd for unexpected or malicious changes. Prefer signed release tags over raw commit hashes for dependencies when possible, and document the reason for switching to a fork.
Security signals we found
Dependency source repository changed from upstream (xelis-project) to vendor-controlled fork (cypherstack)
Dependency ref changed from a version tag (v0.1.1) to a raw commit hash (5dd5c50713160fa15fb06ff44886ae035eed62fd)
No commit message or diff content describes a security fix or vulnerability
No changelog, advisory, or CVE reference present in the supplied materials
Evidence from the diff
The diff updates two files (pubspec.lock and scripts/app_config/templates/pubspec.template) to point the xelis_flutter dependency from https://github.com/xelis-project/xelis-flutter-ffi.git (tag v0.1.1, resolved-ref ee7a5756f5f403e6a371990c2817f38eb21a97b2) to https://github.com/cypherstack/xelis-flutter-ffi.git at commit 5dd5c50713160fa15fb06ff44886ae035eed62fd. The version string remains 0.1.1. No source code of the library is included, so the security properties of the new commit cannot be evaluated from this diff alone. The change is consistent with either a benign fork-and-patch workflow or a supply-chain redirection.
Changed components
pubspec.lockscripts/app_config/templates/pubspec.templatexelis_flutter dependency (xelis-flutter-ffi)Inspect captured patch +5 / −5
diff --git a/pubspec.lock b/pubspec.lock
index f294896..a1b9af3 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -2516,9 +2516,9 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: "v0.1.1"
- resolved-ref: ee7a5756f5f403e6a371990c2817f38eb21a97b2
- url: "https://github.com/xelis-project/xelis-flutter-ffi.git"
+ ref: "5dd5c50713160fa15fb06ff44886ae035eed62fd"
+ resolved-ref: "5dd5c50713160fa15fb06ff44886ae035eed62fd"
+ url: "https://github.com/cypherstack/xelis-flutter-ffi.git"
source: git
version: "0.1.1"
xml:
diff --git a/scripts/app_config/templates/pubspec.template b/scripts/app_config/templates/pubspec.template
index 06f48c2..78f73ad 100644
--- a/scripts/app_config/templates/pubspec.template
+++ b/scripts/app_config/templates/pubspec.template
@@ -29,8 +29,8 @@ dependencies:
xelis_flutter:
git:
- url: https://github.com/xelis-project/xelis-flutter-ffi.git
- ref: v0.1.1
+ url: https://github.com/cypherstack/xelis-flutter-ffi.git
+ ref: 5dd5c50713160fa15fb06ff44886ae035eed62fd
flutter_libsparkmobile:
git:
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.