What changed, and why it matters
This commit adds a new automated build step that produces a Flatpak installer for the Linux version of Stack Wallet. It does not change the wallet's code, cryptography, or how user funds are handled. It is a packaging and release-pipeline change, not a security fix or vulnerability.
No security action required. As a routine hardening step, reviewers may verify that the Flatpak manifest's finish-args permissions (network, IPC, X11/Wayland, DRI, D-Bus secrets/notifications) are the minimum necessary for the wallet to function.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit introduces a GitHub Actions job named build-flatpak that depends on the existing Linux build, downloads the pre-built x86_64 tarball, stages it with a desktop icon and Flatpak metadata, installs the Freedesktop Platform/Sdk 24.08 runtime, builds a Flatpak bundle, and uploads it as a release artifact. It also adds four new files under flatpak/: a .desktop entry, an AppStream metainfo.xml, a Flatpak manifest YAML with sandbox permissions, and a wrapper shell script that launches the bundled binary. The release job is updated to include the new Flatpak artifact. No application source code is modified.
Changed components
.github/workflows/build.yamlflatpak/com.cypherstack.stackwallet.desktopflatpak/com.cypherstack.stackwallet.metainfo.xmlflatpak/com.cypherstack.stackwallet.yamlflatpak/stack_wallet.shInspect captured patch +129 / −2
diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml
index e9dd3ed..6a92ed6 100644
--- a/.github/workflows/build.yaml
+++ b/.github/workflows/build.yaml
@@ -484,9 +484,75 @@ jobs:
name: stack_wallet-ios-aarch64-${{ steps.ver.outputs.version }}
path: stack_wallet-ios-aarch64-${{ steps.ver.outputs.version }}.ipa
+ build-flatpak:
+ runs-on: ubuntu-24.04
+ needs: build-linux
+ steps:
+ - uses: actions/checkout@v6
+
+ - name: Set version
+ id: ver
+ run: |
+ if [ "${{ github.ref_type }}" = "tag" ]; then
+ VERSION="${{ github.ref_name }}"
+ VERSION="${VERSION#v}"
+ elif [ -n "${{ inputs.version }}" ]; then
+ VERSION="${{ inputs.version }}"
+ else
+ VERSION="0.0.0-staging.${{ github.run_number }}"
+ fi
+ echo "version=${VERSION}" >> $GITHUB_OUTPUT
+
+ - name: Download Linux bundle
+ uses: actions/download-artifact@v4
+ with:
+ name: stack_wallet-linux-x86_64-${{ steps.ver.outputs.version }}
+
+ - name: Stage bundle and icon
+ run: |
+ tar -xzf "stack_wallet-linux-x86_64-${{ steps.ver.outputs.version }}.tar.gz" -C flatpak/
+ cp asset_sources/icon/stack_wallet/icon.png flatpak/com.cypherstack.stackwallet.png
+
+ - name: Install Flatpak tools
+ run: |
+ sudo apt-get update -q
+ sudo apt-get install -y flatpak flatpak-builder
+
+ - name: Set up Flathub remote
+ run: flatpak remote-add --user --if-not-exists flathub https://flathub.org/repo/flathub.flatpakrepo
+
+ - name: Cache Flatpak SDK
+ uses: actions/cache@v4
+ with:
+ path: ~/.local/share/flatpak
+ key: flatpak-freedesktop-24.08-v1
+
+ - name: Install Flatpak SDK
+ run: |
+ flatpak install --user --noninteractive flathub \
+ org.freedesktop.Platform//24.08 \
+ org.freedesktop.Sdk//24.08
+
+ - name: Build Flatpak
+ run: |
+ flatpak-builder --user --force-clean \
+ --repo=flatpak-repo \
+ build-flatpak flatpak/com.cypherstack.stackwallet.yaml
+
+ - name: Bundle Flatpak
+ run: |
+ flatpak build-bundle flatpak-repo \
+ "stack_wallet-linux-x86_64-${{ steps.ver.outputs.version }}.flatpak" \
+ com.cypherstack.stackwallet
+
+ - uses: actions/upload-artifact@v4
+ with:
+ name: stack_wallet-flatpak-x86_64-${{ steps.ver.outputs.version }}
+ path: stack_wallet-linux-x86_64-${{ steps.ver.outputs.version }}.flatpak
+
release:
if: github.ref_type == 'tag'
- needs: [build-linux, build-android, build-windows, build-macos, build-ios]
+ needs: [build-linux, build-android, build-windows, build-macos, build-ios, build-flatpak]
runs-on: ubuntu-latest
permissions:
contents: write
@@ -503,7 +569,7 @@ jobs:
name=$(basename "$dir")
(cd "$dir" && zip -r "../../release-files/${name}.zip" .)
done
- find artifacts/ \( -name "*.tar.gz" -o -name "*.zip" -o -name "*.ipa" \) -mindepth 2 -exec mv {} release-files/ \;
+ find artifacts/ \( -name "*.tar.gz" -o -name "*.zip" -o -name "*.ipa" -o -name "*.flatpak" \) -mindepth 2 -exec mv {} release-files/ \;
find artifacts/ -name "*.apk" -mindepth 2 -exec mv {} release-files/ \;
- uses: softprops/action-gh-release@v2
diff --git a/flatpak/com.cypherstack.stackwallet.desktop b/flatpak/com.cypherstack.stackwallet.desktop
new file mode 100644
index 0000000..d5b7d55
--- /dev/null
+++ b/flatpak/com.cypherstack.stackwallet.desktop
@@ -0,0 +1,7 @@
+[Desktop Entry]
+Name=Stack Wallet
+Comment=Open-source non-custodial cryptocurrency wallet
+Exec=stack_wallet
+Icon=com.cypherstack.stackwallet
+Type=Application
+Categories=Finance;
diff --git a/flatpak/com.cypherstack.stackwallet.metainfo.xml b/flatpak/com.cypherstack.stackwallet.metainfo.xml
new file mode 100644
index 0000000..abf3b19
--- /dev/null
+++ b/flatpak/com.cypherstack.stackwallet.metainfo.xml
@@ -0,0 +1,17 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<component type="desktop-application">
+ <id>com.cypherstack.stackwallet</id>
+ <metadata_license>CC0-1.0</metadata_license>
+ <project_license>GPL-3.0-only</project_license>
+ <name>Stack Wallet</name>
+ <summary>Open-source non-custodial cryptocurrency wallet</summary>
+ <description>
+ <p>
+ Stack Wallet is an open-source, non-custodial, privacy-focused
+ cryptocurrency wallet supporting multiple coins.
+ </p>
+ </description>
+ <url type="homepage">https://stackwallet.com</url>
+ <url type="bugtracker">https://github.com/cypherstack/stack_wallet/issues</url>
+ <content_rating type="oars-1.1"/>
+</component>
diff --git a/flatpak/com.cypherstack.stackwallet.yaml b/flatpak/com.cypherstack.stackwallet.yaml
new file mode 100644
index 0000000..3707ccb
--- /dev/null
+++ b/flatpak/com.cypherstack.stackwallet.yaml
@@ -0,0 +1,35 @@
+app-id: com.cypherstack.stackwallet
+runtime: org.freedesktop.Platform
+runtime-version: '24.08'
+sdk: org.freedesktop.Sdk
+command: stack_wallet
+
+finish-args:
+ - --share=network
+ - --share=ipc
+ - --socket=fallback-x11
+ - --socket=wayland
+ - --device=dri
+ - --talk-name=org.freedesktop.secrets
+ - --talk-name=org.freedesktop.Notifications
+
+modules:
+ - name: stack_wallet
+ buildsystem: simple
+ build-commands:
+ # Install the pre-built Flutter bundle under /app/lib/stack_wallet/ so
+ # the binary's $ORIGIN/lib and $ORIGIN/data lookups resolve correctly.
+ - mkdir -p /app/lib/stack_wallet
+ - install -Dm755 bundle/stack_wallet /app/lib/stack_wallet/stack_wallet
+ - cp -r bundle/lib bundle/data /app/lib/stack_wallet/
+ # Wrapper script so the Flatpak command path resolves to the binary.
+ - install -Dm755 stack_wallet.sh /app/bin/stack_wallet
+ - install -Dm644 com.cypherstack.stackwallet.desktop
+ /app/share/applications/com.cypherstack.stackwallet.desktop
+ - install -Dm644 com.cypherstack.stackwallet.metainfo.xml
+ /app/share/metainfo/com.cypherstack.stackwallet.metainfo.xml
+ - install -Dm644 com.cypherstack.stackwallet.png
+ /app/share/icons/hicolor/512x512/apps/com.cypherstack.stackwallet.png
+ sources:
+ - type: dir
+ path: .
diff --git a/flatpak/stack_wallet.sh b/flatpak/stack_wallet.sh
new file mode 100644
index 0000000..db2f325
--- /dev/null
+++ b/flatpak/stack_wallet.sh
@@ -0,0 +1,2 @@
+#!/bin/sh
+exec /app/lib/stack_wallet/stack_wallet "$@"
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.