ios: use prebuilt frostdart lib (drops frostdart Rust version pin)
What changed, and why it matters
This iOS build change switches the FROST cryptographic library from being compiled from source during app building to being downloaded as a prebuilt binary. It also removes a pinned Rust compiler version. The change itself is a build-system convenience, but it slightly increases supply-chain risk because the app now relies on a prebuilt library whose contents are not rebuilt from public source at build time, and the Rust compiler version is no longer fixed.
Verify the prebuilt frostdart binary is reproducible from source, signed, and published with checksums or attestation. Reintroduce a pinned, audited toolchain if the FROST implementation has known compiler-sensitive behavior. Review the frostdart submodule commit for any relevant upstream changes.
Security signals we found
Build pipeline now downloads prebuilt frostdart binary instead of compiling from source
Rust compiler version pin (1.71.0) removed for iOS builds
Submodule update to crypto_plugins/frostdart without visible source diff
Supply-chain trust boundary shifted from source repository to prebuilt artifact publisher
Evidence from the diff
The commit modifies the iOS build pipeline for the frostdart plugin. It removes a pinned Rust toolchain (1.71.0) from the GitHub Actions workflow and changes scripts/ios/download_all.sh from building frostdart via Cargokit at CocoaPods install time to downloading a prebuilt library using the plugin’s download.sh. The crypto_plugins/frostdart submodule pointer is updated, but no source code diff is shown. There is no direct vulnerability in the diff; the security relevance is indirect: prebuilt binaries shift trust to the binary publisher and remove the reproducible source-build step.
Changed components
iOS build workflow (.github/workflows/build.yaml)iOS dependency download script (scripts/ios/download_all.sh)frostdart crypto plugin submodule (crypto_plugins/frostdart)Inspect captured patch +2 / −7
diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml
index 892dc88..01ec833 100644
--- a/.github/workflows/build.yaml
+++ b/.github/workflows/build.yaml
@@ -387,11 +387,6 @@ jobs:
echo "version=${VERSION}" >> $GITHUB_OUTPUT
echo "build_number=${BUILD_NUMBER}" >> $GITHUB_OUTPUT
- - uses: dtolnay/rust-toolchain@master
- with:
- toolchain: '1.71.0'
- targets: aarch64-apple-ios
-
- uses: dtolnay/rust-toolchain@master
with:
toolchain: stable
diff --git a/scripts/ios/download_all.sh b/scripts/ios/download_all.sh
index 714531e..30259dd 100755
--- a/scripts/ios/download_all.sh
+++ b/scripts/ios/download_all.sh
@@ -10,7 +10,7 @@ PLUGINS_DIR=../../crypto_plugins
(cd "${PLUGINS_DIR}"/flutter_libmwc/scripts/ios && ./download.sh)
-# frostdart iOS is built from source by Cargokit at pod install time
+(cd "${PLUGINS_DIR}"/frostdart/scripts/ios && ./download.sh)
wait
echo "Done"
Why this scored 14/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.