What changed, and why it matters
This commit updates a single Flutter package dependency called flutter_mwebd from version 0.0.1-pre.11 to 0.0.1-pre.12. The change is routine maintenance: it bumps the version number in the project's lock file and in a template used to generate package configuration. The commit message gives no details about what changed in the new version or whether it fixes any security issue. Without access to the upstream package's changelog, we cannot determine if this update addresses a vulnerability.
Review the upstream flutter_mwebd 0.0.1-pre.12 release notes or changelog to determine whether this update contains security fixes. If it does, assess severity and consider expediting the update; if not, treat as normal dependency maintenance.
Security signals we found
Dependency version bump with no stated security rationale
Transitive dependency additions from updated package (code_assets, hooks, record_use)
No CVE, advisory, or security fix mentioned in commit metadata
Evidence from the diff
The diff only modifies version pins for flutter_mwebd in pubspec.lock and scripts/app_config/templates/pubspec.template.yaml. The lock file also gains three transitive dependencies (code_assets, hooks, record_use) pulled in by the newer package version. There are no code changes within the Stack Wallet repository itself, and no security-related explanation is provided in the commit or supplied references.
Changed components
flutter_mwebd dependencypubspec.lockscripts/app_config/templates/pubspec.template.yamlInspect captured patch +27 / −3
diff --git a/pubspec.lock b/pubspec.lock
index 96a4c7e..d0c9d7e 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -329,6 +329,14 @@ packages:
url: "https://pub.dev"
source: hosted
version: "1.1.2"
+ code_assets:
+ dependency: transitive
+ description:
+ name: code_assets
+ sha256: bf394f466ba9205f1812a0433b392d6af280f155f56651eda7c18cc32ed493b8
+ url: "https://pub.dev"
+ source: hosted
+ version: "1.2.1"
code_builder:
dependency: transitive
description:
@@ -1076,10 +1084,10 @@ packages:
dependency: "direct main"
description:
name: flutter_mwebd
- sha256: "14f2a331b2621b78ddf62081ca8a466f6a2b4352a66950fffd68615c14e63edf"
+ sha256: "5556c665252ef675b8d8149c3f63f82fe4467f97f8c0c4a8aa0a646a5b7ead5e"
url: "https://pub.dev"
source: hosted
- version: "0.0.1-pre.11"
+ version: "0.0.1-pre.12"
flutter_native_splash:
dependency: "direct main"
description:
@@ -1319,6 +1327,14 @@ packages:
url: "https://pub.dev"
source: hosted
version: "1.0.1"
+ hooks:
+ dependency: transitive
+ description:
+ name: hooks
+ sha256: "9a62a50b50b769a737bc0a8ff381f333529df3ab746b2f6b02e83760231455ba"
+ url: "https://pub.dev"
+ source: hosted
+ version: "2.0.2"
html:
dependency: "direct main"
description:
@@ -1984,6 +2000,14 @@ packages:
url: "https://pub.dev"
source: hosted
version: "4.1.0"
+ record_use:
+ dependency: transitive
+ description:
+ name: record_use
+ sha256: "2551bd8eecfe95d14ae75f6021ad0248be5c27f138c2ec12fcb52b500b3ba1ed"
+ url: "https://pub.dev"
+ source: hosted
+ version: "0.6.0"
retry:
dependency: transitive
description:
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 37827e9..43a6ab7 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -80,7 +80,7 @@ dependencies:
# %%END_ENABLE_SAL%%
# %%ENABLE_MWEBD%%
-# flutter_mwebd: 0.0.1-pre.11
+# flutter_mwebd: 0.0.1-pre.12
# %%END_ENABLE_MWEBD%%
monero_rpc: ^2.0.0
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.