AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Monero

Build script improvements (#1312)

Public commit record

What the developer wrote

Authored by Dan Miller

76/100 · Adequate
Build script improvements (#1312)

* add secure storage linux deps

Don't install unused deb packages

Use stackwallet-ci image for test action workflow

* Fix container specification

* add -d flag to download libepiccash from GitHub Releases

* ci: use -d flag to download libepiccash instead of building in tests

* Add flutter_libmwc to download scripts

* Update flutter_libmwc to v0.1.0 release

* Add frostdart downloads to build script

* Add build job
✓ Descriptive subject✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit is a routine build-system update for a cryptocurrency wallet app. It adds a new automated build workflow for Linux and Android, updates the Docker image used for builds, and changes some scripts to download pre-built crypto libraries from GitHub Releases instead of compiling them from source. There is no direct evidence in the diff of a security vulnerability, malicious code, or a backdoor. However, switching to downloaded pre-built binaries introduces a supply-chain risk: if the download source or release artifacts are compromised, the build pipeline could incorporate malicious native libraries into the wallet without reviewers seeing the source code change.

Recommended action

Treat this as a build-hygiene review, not an active vulnerability. Reviewers should inspect the per-plugin `download.sh` scripts and the GitHub Releases they pull from to confirm checksum/signature verification is performed. Verify that the new CI secrets handling does not leak decoded values in logs, and audit the `stackwallet/stackwallet-ci:latest` image supply chain. If no verification exists, require adding reproducible checksums or signatures for all downloaded native libraries before relying on `-d` builds for releases.

Security signals we found

01

Build pipeline now downloads pre-built native crypto libraries from external releases rather than compiling from source

02

No visible checksum or signature verification in the added download orchestration scripts

03

New CI workflow decodes base64 secrets (`CHANGE_NOW`, Android keystore) into build files

04

Dockerfile adds Android SDK/NDK and OpenJDK, expanding the container's attack surface

05

Submodules for crypto plugins are referenced but their download/verification logic is not shown in this commit

Risk score

Why this scored 26/100

Our methodology →
Potential impact 5/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.