What changed, and why it matters
This commit updates the Stack Wallet app to use a newer version of its Tor privacy plugin and switches to prebuilt native assets downloaded from GitHub. There is no direct evidence in the commit of a security vulnerability, but changing how sensitive privacy components are fetched and built is a security-relevant configuration change.
Review the changes between the old and new tor plugin commits (21077186e6bf... and 5586bfa3c48e...) and verify the prebuilt manifest SHA-256 matches the published release artifact. Confirm the prebuilt binaries are reproducible and signed, and that the build pipeline for native assets is trustworthy.
Security signals we found
Dependency version bump for privacy-critical Tor plugin
Switch from source build to prebuilt native asset for Tor component
Prebuilt asset fetched over HTTPS from GitHub release with SHA-256 pin
No commit message or diff explains security fixes or vulnerability details
Evidence from the diff
The diff bumps the tor_ffi_plugin git dependency from ref 21077186e6bf… to 5586bfa3c48e… (version 0.0.1 to 0.1.0) in both pubspec.lock and the pubspec.template.yaml. It also adds a dependency_overrides entry enabling native_build: prebuilt for tor_ffi_plugin, pointing to a GitHub release manifest at https://github.com/cypherstack/tor/releases/download/native-0.1.0/manifest.json with a pinned SHA-256 of 00a988a2c0994dff300bb19493e935b0d4eae2b506d02af9dd69ddad65805a24. The actual contents of the new tor plugin ref or the prebuilt manifest are not shown.
Changed components
pubspec.lockscripts/app_config/templates/pubspec.template.yamltor_ffi_plugin dependency (cypherstack/tor)Tor native prebuilt asset configurationInspect captured patch +8 / −4
diff --git a/pubspec.lock b/pubspec.lock
index baef70d..4d4e8de 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -2402,11 +2402,11 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: "21077186e6bf773ec8a7cd57ef149b2cee5daa7b"
- resolved-ref: "21077186e6bf773ec8a7cd57ef149b2cee5daa7b"
+ ref: "5586bfa3c48e495bc00f9b56fa18869daf768573"
+ resolved-ref: "5586bfa3c48e495bc00f9b56fa18869daf768573"
url: "https://github.com/cypherstack/tor.git"
source: git
- version: "0.0.1"
+ version: "0.1.0"
tuple:
dependency: "direct main"
description:
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 66319da..27220dd 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -67,7 +67,7 @@ dependencies:
# tor_ffi_plugin:
# git:
# url: https://github.com/cypherstack/tor.git
-# ref: 21077186e6bf773ec8a7cd57ef149b2cee5daa7b
+# ref: 5586bfa3c48e495bc00f9b56fa18869daf768573
# %%END_ENABLE_TOR%%
# %%ENABLE_XMR%%
@@ -373,6 +373,10 @@ dependency_overrides:
# %%ENABLE_NATIVE_PREBUILTS%%
#hooks:
# user_defines:
+# tor_ffi_plugin:
+# native_build: prebuilt
+# prebuilt_manifest_url: "https://github.com/cypherstack/tor/releases/download/native-0.1.0/manifest.json"
+# prebuilt_manifest_sha256: "00a988a2c0994dff300bb19493e935b0d4eae2b506d02af9dd69ddad65805a24"
# flutter_libepiccash:
# native_build: prebuilt
# prebuilt_manifest_url: "https://github.com/cypherstack/flutter_libepiccash/releases/download/native-0.3.0/manifest.json"
Why this scored 14/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.