flutter-china-deploy
Warn
Audited by Snyk on May 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The included scripts set PUB_HOSTED_URL/FLUTTER_STORAGE_BASE_URL (e.g. https://pub.flutter-io.cn, https://storage.flutter-io.cn) and change the Gradle distribution to https://mirrors.cloud.tencent.com/gradle/gradle-8.10.2-all.zip, all of which are fetched at runtime (via flutter pub get / Gradle) and cause remote packages/binaries to be downloaded and executed as required dependencies.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata