This commit removes a security check that verified a Zcash transaction buffer had not been tampered with between the 'check/review' screen and the 'sign' step on a Keystone hardware wallet. Before the change, the device stored a fingerprin…
Removal of a digest-based integrity check on a signing input bufferRenaming of verified_bytes() to checked_bytes() with weakened semanticsCross-language (C/Rust) boundary no longer re-validates buffer contents
This commit is a routine code reorganization: it moves existing test-only helper code from the project's internal test directory into the public `trezorlib` Python package as a new `testing` module. The moved code includes utilities for ha…
This is a one-line comment change in a Zcash test file. It rewords an explanatory note about why a test sample lacks a Sapling bundle. No code behavior changes, no security fix or vulnerability is introduced.
This commit only renames a test-only helper struct and updates comments in unit tests for Zcash PCZT (partially-created transaction) handling. It makes no changes to production code, cryptography, transaction parsing, or wallet behavior. T…
This commit only adds a new automated test to Bitcoin Core. It does not change any production code, so it cannot by itself introduce a vulnerability or fix one. The test checks that an internal database index does not save progress beyond …
New regression test for index/chainstate flush consistencyNo changes to consensus, networking, wallet, or index implementation codeTest-only change with no runtime attack surface
This commit is a straightforward code cleanup in the Zcash PCZT (Partially Created Zcash Transaction) handling code. It merges two nearly identical internal helper functions into one shared helper that takes a policy argument, and removes …
No security-relevant logic change: validation order, error handling, and policy enforcement are preserved.No new unsafe code, no new dependencies, no new FFI boundaries, no cryptographic changes.Function visibility changes: `check_parsed_pczt_*` private helpers removed; `check_pczt_cypherpunk_with_policy` is private; public API surface unchanged.
This commit only increases a test timeout value in a GitHub Actions CI workflow from 60 to 70 seconds. It does not change any firmware code, cryptographic logic, or user-facing behavior. There is no security relevance.
This commit only removes explanatory comments from three Zcash test files. No code behavior, logic, or security checks were changed. It is a documentation cleanup inside test code and has no security relevance.
This commit only rewords a code comment in a Zcash test file. No program logic, behavior, or security properties changed. It is a documentation-only edit.
This is a minor fix to a unit test file. A test variable was being assigned a negative value in an unsigned container, which caused a silent underflow and made the test assertion technically incorrect. The patch changes the test to check t…
This commit is just a changelog update for libwally-core version 1.5.5. It mentions that the release 'de-optimizes some memcpy calls on x86 to prevent leaks via extended registers.' That wording suggests a security-sensitive fix, but the a…
Changelog entry describes a security-motivated fixMentions prevention of information leaks via CPU extended registersRelates to secure memory handling of cryptographic secrets
This commit is a routine version bump from 1.5.4 to 1.5.5 across build files, documentation, and package metadata. It changes only version strings and the build version constant; no code logic is modified.
A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.