Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

24Projects watched
18178Commits captured
17450AI analyses
103High-risk findings · 30d
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

17450 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 77 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(localization): updating fixtures [no changelog]

This commit only updates the expected visual test snapshots (called fixtures) used by Trezor's automated UI tests. It does not change any firmware, application, or security code. The updated hashes reflect expected changes in on-screen tex…

f542da29by Michal Kazda+205−2051 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

slight menu optimization for long menus

This is a tiny performance tweak in the COLDCARD wallet's menu drawing code. It changes one loop bound so the device only redraws the visible menu items instead of also iterating over off-screen items. There is no security-relevant change …

9ff3f5c4by scgbckbone+1−11 file
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

test nits

This commit only touches test helper code in the COLDCARD firmware repository. It fixes small test issues: allowing PSBT parsing from string input, validating a setting name in a hobble-mode test, and correctly setting sequence numbers and…

f5a1ef32by scgbckbone+17−104 files
No security note in commit
Low 29 AI analysisMessage 60 · Adequate
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

testing: block_h bumped for SSSP too, when CCC overrides SSSP block

This commit fixes a bookkeeping bug in the COLDCARD firmware's transaction-signing logic. When two optional security features—SSSP (a spending velocity limit) and CCC (a policy that can override SSSP)—are both active, the block-height trac…

State-synchronization fix between two policy enforcement featuresRegression test added for override interactionNo mention of CVE, advisory, or security disclosure in commit or diff
841e4433by scgbckbone+60−44 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

testing: cope with bitcoin core v30

This commit only updates the project's automated test harness to work with newer versions of Bitcoin Core (specifically version 30). It changes how tests detect Bitcoin Core's version, handle removed legacy wallet features, and adjust an e…

38616234by scgbckbone+11−62 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

docs: index all docs and fix drift vs firmware

This commit is purely a documentation update. It adds missing entries to the docs index, updates outdated examples and menu trees, fixes a broken filename reference in a code comment, and corrects factual details (such as supported models …

8e3bbfdfby scgbckbone+139−8315 files
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

credit

This commit only adds a thank-you credit to an upcoming release changelog. It does not change any source code, firmware behavior, or fix anything by itself. The actual bugfix it references (ignoring an unexpected 'bkpw' field in backups) w…

f9b65ce9by Peter D. Gray+1−01 file
No security note in commit
High 72 AI analysisMessage 73 · Adequate
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

Don't restore cached backup password (bkpw) from backup file

This update fixes a security flaw in how the COLDCARD wallet restores its settings from a backup file. Previously, a tampered backup could secretly set the password used for future backups, letting an attacker who later gets physical acces…

Tampered-backup password fixationBackup restore integrity hardeningCached secret import prevention
8d71040aby Dmitry Monakhov+7−01 file
Vendor flagged security relevance
Informational 15 AI analysisMessage 86 · Strong
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

Bump requests from 2.32.4 to 2.33.0 in /testing

This is an automated dependency update by Dependabot that bumps the Python 'requests' library used only in the project's testing environment from version 2.32.4 to 2.33.0. It changes one line in a test requirements file. There is no indica…

5feae87eby dependabot[bot]+1−11 file
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

README.md update build repro steps (were misordered before)

This commit only updates the README.md file to correct the order of steps for building a reproducible copy of the COLDCARD firmware. It changes documentation text: adding a step to change into the firmware directory, updating the example r…

0949c0acby scgbckbone+5−31 file
No security note in commit
Moderate 66 AI analysisMessage 28 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

bundle small fixes

This is a large bundle of bug fixes for the COLDCARD hardware wallet firmware. Most changes fix user-interface crashes ('yikes'), incorrect error messages, or policy edge cases rather than a single critical vulnerability. The most security…

HSM mode now disables NFC and Virtual Disk peripherals to reduce USB/NFC attack surfaceSingle-Signer Spending Policy unlock no longer accepts a zero-secret bypass PIN as the 'main PIN'OP_RETURN and non-standard scripts are no longer hidden as 'null-data' during transaction review
c36eac23by scgbckbone+1486−28548 files
Vendor flagged security relevance
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this