Bump flutter_libmwc to v0.1.2 (iOS shasum fix)
What changed, and why it matters
This commit updates a single cryptocurrency plugin dependency (flutter_libmwc) to version 0.1.2, with the stated reason being an iOS checksum ('shasum') fix. The actual code changes are not visible because the diff was not provided. A checksum fix normally means a downloaded file's hash was corrected so the build can verify it was not corrupted or tampered with during download. It is a build-integrity issue, not a live vulnerability in the wallet itself, unless the wrong checksum was hiding a malicious replacement. There is no evidence in the supplied materials of malicious intent or a security breach.
Review the upstream flutter_libmwc v0.1.2 release notes and diff to confirm the checksum change corresponds to a legitimate, benign artifact update. Verify the new SHA256/SHA512 hashes against the published iOS binaries before merging into release builds. If the checksum mismatch was unexplained, treat it as a supply-chain incident and investigate whether any prior builds used a mismatched artifact.
Security signals we found
Dependency bump for a crypto plugin
Mentions iOS shasum/checksum correction
No diff content available to assess actual change
No security-related language in commit title or message
Evidence from the diff
The commit bumps the flutter_libmwc submodule or dependency reference from an unspecified previous version to v0.1.2, described as an ‘iOS shasum fix’. Without the diff or the upstream flutter_libmwc changelog, we can only infer that one or more iOS binary/checksum entries were corrected so that build-time integrity verification (SHA sum comparison) succeeds. This is a supply-chain/build-integrity adjacent change. It does not, on its own, indicate a runtime vulnerability in Stack Wallet. The security relevance depends entirely on why the checksum was wrong (e.g., benign re-packaging vs. unexpected artifact substitution), which is not present in the supplied materials.
Changed components
crypto_plugins/flutter_libmwc dependency/submoduleiOS build artifact verificationInspect captured patch +1 / −1
Diff not available from the source API.Why this scored 10/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.