Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

24Projects watched
17782Commits captured
17251AI analyses
98High-risk findings · 30d
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

17251 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 18 · Opaque
EL ElectrumElectrum BitcoinSoftware wallets

update locale

This commit is a routine update to Electrum's language translation files (locale). It changes one line in one translation file. There is no indication of any security relevance.

c7ec118bby ThomasV+1−11 file
No security note in commit
Low 37 AI analysisMessage 81 · Strong
EL ElectrumElectrum BitcoinSoftware wallets

util.make_aiohttp_session: wrap aiohttp-socks 0.11+ excs to ClientError

This commit fixes a compatibility issue with newer versions of a proxy library used by Electrum. The newer library changed which error types it raises when proxy connections fail. Because Electrum's code was written to catch the old error …

Exception-handling mismatch after dependency updateProxy connection errors could propagate uncaughtPotential denial-of-service via unhandled exception causing task/coroutine termination
cd68b412by SomberNight+21−22 files
No security note in commit
Low 32 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core): set tropic configuration

This commit moves the configuration settings for the Tropic secure chip out of the production-test tool and into the main firmware. At boot, the device now checks whether the Tropic chip's configuration matches the version expected by the …

Boot-time enforcement of expected secure-element configurationVersioned configuration tables for reversible and irreversible Tropic configsUse of a backup slot during configuration update
4a93242cby Martin Pastyřík+9518−53028 files
No security note in commit
Informational 15 AI analysisMessage 68 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Fix Joost's Forgejo username

This commit simply corrects a username in an automated reviewer assignment workflow. It changes one reviewer handle from 'joost_spiral' to 'joostjager' so the right person stays in the rotation. There is no security issue here.

ade3b6bdby Elias Rohrer+1−11 file
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Use Forgejo OIDC for review requests

This commit changes the project's automated reviewer-assignment workflow to stop using a long-lived secret token and instead request a short-lived authentication token from the Forgejo CI service. This is a security-hardening improvement: …

Removal of long-lived repository secret from CI workflowAdoption of OIDC-based short-lived token for API authorizationWorkflow runs in pull_request_target context with no code checkout
57c84bcaby Elias Rohrer+17−81 file
Vendor flagged security relevance
Low 47 AI analysisMessage 50 · Thin
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

external_signer: validate fingerprint from enumerate response

This commit adds a safety check in Bitcoin Core when it talks to an external hardware wallet or signer tool. Previously, the software accepted whatever 'fingerprint' string the external tool returned. Now it requires that fingerprint to be…

Input validation added to externally supplied JSON fieldMissing length and format check on signer fingerprint before useFunctional tests added for malformed fingerprint rejection
4c9de7d5by Kyle 🐆+9−02 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Update upstream CHANGELOG with latest 0.1/0.2 releases

This commit only updates the CHANGELOG.md file to add release notes for versions 0.2.4, 0.1.11, 0.2.3, and 0.1.10. It does not change any source code, build scripts, tests, or configuration. The changelog text describes security fixes that…

CHANGELOG-only commit with no source code changesRelease notes describe prior security fixes: anchor channel reserve underestimates, DoS vulnerabilities, unicode format-character sanitization, weak default randomness in possiblyrandom, panics from malicious invoices/LSPSDateTime/OMNameResolver, RGS memory limits, log spam mitigation, corrupted ChannelManager/ProbabilisticScorer memory allocationSecurity issues attributed to Project Loupe in release notes
d2b3a786by Matt Corallo+214−01 file
Vendor flagged security relevance
Informational 15 AI analysisMessage 0 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

year

This commit only corrects two placeholder release dates in the changelog from the year 2065 to 2026. There are no code changes, no functional changes, and no security relevance.

a9c99a9bby Peter D. Gray+2−21 file
No security note in commit
Informational 19 AI analysisMessage 82 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core/prodtest): Add Tropic tests.

This commit adds new factory-testing commands for the Tropic secure chip inside Trezor devices. It does not change normal wallet behavior or user funds handling. The new commands are only reachable in a special manufacturing test mode (pro…

New prodtest-only CLI commands for Tropic secure-element validationArgument validation and range clamping for iterations, slot counts, and explicit slotsDeterministic PRNG used only for slot selection, not for cryptographic material
e0d8f274by Andrew Kozlik+935−236 files
No security note in commit
Informational 22 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core/prodtest): Reboot Tropic in tropic-set-sensors.

This commit changes a factory/production-test command for the Tropic secure chip inside Trezor devices. The command now reboots the chip after changing sensor settings, makes the sensor-setting argument optional (defaulting to enabling all…

Change in production-test secure-element command behaviorDefault argument now enables all sensors (0x00000000)Conditional erase of ECC/data/MAC slots based on pairing key slot
9bad5744by Andrew Kozlik+60−304 files
No security note in commit
Informational 22 AI analysisMessage 67 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core/prodtest): Add tropic-tests-cleanup.

This commit adds a new factory-test command called tropic-tests-cleanup to the Trezor device's production-test firmware. The command erases leftover test data from secure chip slots so a device is not accidentally shipped with stray data f…

New factory-only CLI command that erases test artifacts from secure-element slots before shippingBroadened counter reinitialization path in the change-PIN flow to handle a depleted counterNo mention of CVE, bug bounty, researcher credit, or advisory in commit or supplied references
dbe34907by Andrew Kozlik+178−255 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this