Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

24Projects watched
17674Commits captured
17198AI analyses
92High-risk findings · 30d
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

17198 analyses
Highest risk·RSS
Informational 12 AI analysisMessage 57 · Thin
KS KeystoneKeystone 3 firmware BitcoinHardware wallets

refactor(zcash): collapse checked PCZT helpers

This commit is a straightforward code cleanup in the Zcash PCZT (Partially Created Zcash Transaction) handling code. It merges two nearly identical internal helper functions into one shared helper that takes a policy argument, and removes …

No security-relevant logic change: validation order, error handling, and policy enforcement are preserved.No new unsafe code, no new dependencies, no new FFI boundaries, no cryptographic changes.Function visibility changes: `check_parsed_pczt_*` private helpers removed; `check_pczt_cypherpunk_with_policy` is private; public API surface unchanged.
8127079dby Adam Tucker+52−621 file
No security note in commit
Informational 15 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

ci(core): increase individual test timeout for upgrade tests

This commit only increases a test timeout value in a GitHub Actions CI workflow from 60 to 70 seconds. It does not change any firmware code, cryptographic logic, or user-facing behavior. There is no security relevance.

5e4aec49by Martin Milata+1−11 file
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
KS KeystoneKeystone 3 firmware BitcoinHardware wallets

test(zcash): trim legacy v6 rejection comments

This commit only removes explanatory comments from three Zcash test files. No code behavior, logic, or security checks were changed. It is a documentation cleanup inside test code and has no security relevance.

feba63edby Adam Tucker+0−93 files
No security note in commit
Informational 15 AI analysisMessage 95 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

test: Redeclare variable as signed in `util_tests`

This is a minor fix to a unit test file. A test variable was being assigned a negative value in an unsigned container, which caused a silent underflow and made the test assertion technically incorrect. The patch changes the test to check t…

cd2a4bc5by rustaceanrob+1−21 file
No security note in commit
Low 44 AI analysisMessage 45 · Thin
EP Elements Projectlibwally-core BitcoinCryptographic librariesSoftware wallets

update CHANGES.md for release 1.5.5

This commit is just a changelog update for libwally-core version 1.5.5. It mentions that the release 'de-optimizes some memcpy calls on x86 to prevent leaks via extended registers.' That wording suggests a security-sensitive fix, but the a…

Changelog entry describes a security-motivated fixMentions prevention of information leaks via CPU extended registersRelates to secure memory handling of cryptographic secrets
d0ac03baby Jon Griffiths+5−01 file
Vendor flagged security relevance
Informational 15 AI analysisMessage 38 · Opaque
EP Elements Projectlibwally-core BitcoinCryptographic librariesSoftware wallets

Bump version to 1.5.5

This commit is a routine version bump from 1.5.4 to 1.5.5 across build files, documentation, and package metadata. It changes only version strings and the build version constant; no code logic is modified.

78499f00by Jon Griffiths+12−129 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
LL Lightning LabsLND BitcoinLightning Network

sweep: account for aux extra budget when filtering inputs

This commit fixes a bug in LND's transaction sweeping logic that could permanently strand certain custom-channel (asset) outputs. The sweeper's budget filter was ignoring extra funds contributed by an optional 'aux sweeper' helper, so it w…

Denial-of-service / fund stranding: custom-channel outputs could be silently excluded from all future sweepsFee-ratchet interaction: non-fee failures (wallet UTXO collisions) could raise startingFeeRate and trigger the filterMissing budget accounting: filter did not mirror set-construction logic that already used aux extra budget
a9e3e9aeby Jared Tobin+151−43 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
LL Lightning LabsLND BitcoinLightning Network

docs: add release note

This commit only adds a release note describing a previously fixed bug in LND's sweeper logic. It does not change any code, so it cannot introduce or fix a security issue by itself. The described bug relates to fee budgeting for sweeping c…

No code changesDocumentation-only commitReferences a prior bug fix (PR #10897) in release notes
3ae31b76by Jared Tobin+8−01 file
No security note in commit
Informational 15 AI analysisMessage 95 · Strong
KS KeystoneKeystone 3 firmware BitcoinHardware wallets

docs(zcash): fix stale anchor-redaction rationale in the Ironwood sign test

This commit only updates a code comment in a Zcash test file. It corrects an outdated explanation about why an anchor value can be removed during signing. No code behavior was changed, and there is no security issue present in the diff.

5c8da744by Adam Tucker+4−31 file
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
EP Elements Projectlibwally-core BitcoinCryptographic librariesSoftware wallets

ci: re-enable clear tests

This commit only changes the project's continuous integration (CI) configuration. It re-enables a set of tests called 'clear tests' that were previously disabled in automated build pipelines, and adds a compiler warning suppression for an …

1009497bby Jon Griffiths+4−41 file
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this