What changed, and why it matters
This commit updates the Android build tooling for the Stack Wallet app. It bumps the Gradle build tool, Android Gradle Plugin, NDK, and adds ProGuard keep/dontwarn rules needed for flutter_secure_storage. These are routine maintenance changes to keep the app building with newer Android tools; there is no direct evidence in the commit of a security vulnerability being fixed.
Treat as routine build maintenance. Verify the updated toolchain and NDK versions compile and pass regression tests. Review whether the flutter_secure_storage dependency version itself is current and whether its upstream release notes mention any security fixes, but that is outside the scope of this diff.
Security signals we found
Build toolchain version bumps (Gradle 8.10.2 -> 8.14, AGP 8.7.0 -> 8.11.1, NDK 28.0.13004108 -> 28.2.13676358)
ProGuard -dontwarn additions for flutter_secure_storage dependencies (com.google.errorprone.annotations, javax.annotation.Nullable, javax.annotation.concurrent.GuardedBy)
No direct code or configuration change that remediates a known CVE or security bug
Evidence from the diff
The diff updates four Android build files: (1) proguard-rules.pro adds -dontwarn rules for error-prone and javax.annotation classes, plus a comment stating these are required for flutter_secure_storage; (2) gradle-wrapper.properties upgrades Gradle from 8.10.2 to 8.14; (3) settings.gradle upgrades the Android Gradle Plugin from 8.7.0 to 8.11.1; (4) the app build.gradle template updates ndkVersion from 28.0.13004108 to 28.2.13676358. No code-level security fix, cryptographic change, or vulnerability patch is visible in the diff.
Changed components
Android build configurationProGuard/R8 obfuscation rulesflutter_secure_storage integration build rulesInspect captured patch +9 / −4
diff --git a/android/app/proguard-rules.pro b/android/app/proguard-rules.pro
index 6a7964e..e1c48c3 100644
--- a/android/app/proguard-rules.pro
+++ b/android/app/proguard-rules.pro
@@ -32,4 +32,9 @@
-keep,allowobfuscation,allowshrinking class * extends com.google.gson.reflect.TypeToken
# required for flutter file_picker
--keep class androidx.lifecycle.DefaultLifecycleObserver
\ No newline at end of file
+-keep class androidx.lifecycle.DefaultLifecycleObserver
+
+# required for flutter_secure_storage
+-dontwarn com.google.errorprone.annotations.**
+-dontwarn javax.annotation.Nullable
+-dontwarn javax.annotation.concurrent.GuardedBy
diff --git a/android/gradle/wrapper/gradle-wrapper.properties b/android/gradle/wrapper/gradle-wrapper.properties
index afa1e8e..e4ef43f 100644
--- a/android/gradle/wrapper/gradle-wrapper.properties
+++ b/android/gradle/wrapper/gradle-wrapper.properties
@@ -2,4 +2,4 @@ distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
zipStoreBase=GRADLE_USER_HOME
zipStorePath=wrapper/dists
-distributionUrl=https\://services.gradle.org/distributions/gradle-8.10.2-all.zip
+distributionUrl=https\://services.gradle.org/distributions/gradle-8.14-all.zip
diff --git a/android/settings.gradle b/android/settings.gradle
index 04c37e5..ebf0856 100644
--- a/android/settings.gradle
+++ b/android/settings.gradle
@@ -18,7 +18,7 @@ pluginManagement {
plugins {
id "dev.flutter.flutter-plugin-loader" version "1.0.0"
- id "com.android.application" version '8.7.0' apply false
+ id "com.android.application" version '8.11.1' apply false
id "org.jetbrains.kotlin.android" version "2.2.20" apply false
}
diff --git a/scripts/app_config/templates/android/app/build.gradle b/scripts/app_config/templates/android/app/build.gradle
index dc1cb23..6a98be4 100644
--- a/scripts/app_config/templates/android/app/build.gradle
+++ b/scripts/app_config/templates/android/app/build.gradle
@@ -15,7 +15,7 @@ android {
namespace "com.place.holder"
compileSdk flutter.compileSdkVersion
// ndkVersion flutter.ndkVersion
- ndkVersion = "28.0.13004108"
+ ndkVersion = "28.2.13676358"
packagingOptions {
pickFirst 'lib/x86/libc++_shared.so'
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.