Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

23Projects watched
16913Commits captured
16841AI analyses
83High-risk findings · 30d
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

16841 analyses
Highest risk·RSS
High 70 AI analysisMessage 77 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

docs(core,prodtest): changelog update core v2.12.2 prodtest v0.3.8

This commit is a documentation-only changelog update for the Trezor firmware release 2.12.2 and prodtest 0.3.8. It does not change any code, but it lists several security fixes that are part of this release. The most important ones affect …

Bitcoin external input misidentification in signingBitcoin RBF replacement transaction allows new external outputsSolana hidden instruction parameters not confirmed by user
f7bd2917by PrisionMike+205−2024 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: update releases.json

This commit simply adds firmware version 2.12.2 to a list of released versions in a JSON file. It does not change any code, fix any bug, or alter security behavior. There is nothing here that could directly affect user security.

21b2bf34by PrisionMike+2−11 file
No security note in commit
Informational 3 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: upload signed secmon

This commit replaces a binary file called secmon.bin for the T3W1 hardware model with a different signed version. The change is described as a routine chore to upload a properly signed secure monitor binary. No source code was modified, an…

b5fd9797by PrisionMike+0−01 file
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: update translation signature

This commit simply adds a new approved digital signature for translation data files used by Trezor hardware wallets. It is a routine metadata update with no visible security bug or code change.

0510df27by PrisionMike+7−01 file
No security note in commit
Informational 15 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

docs(core): update changelog for 2.12.3

This commit only updates documentation: it moves a bug-fix note from a draft changelog file into the published changelogs for firmware version 2.12.3. No program code is changed, so this commit by itself cannot introduce or fix a security …

8cd9878cby Martin Milata+24−17 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: update releases.json

This commit simply adds a new firmware version number (2.12.3) and lists which Trezor hardware models it supports in a release metadata file. There is no code change, no bug fix, and no security-related content in the diff.

bdb20d34by Martin Milata+2−11 file
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): sign translations

This commit simply adds a new digital signature entry to a JSON file that records approved translation bundles for the Trezor hardware wallet firmware. There is no code change, no bug fix, and no indication of a security issue. It appears …

8b4afd25by Martin Milata+7−01 file
No security note in commit
Informational 15 AI analysisMessage 47 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): update fixtures

This commit only updates the expected test result hashes in a single file used for automated UI testing. It does not change any firmware, application, or cryptographic code. There is no direct security relevance visible in the commit itsel…

30f0e79dby Martin Milata+842−7681 file
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Handle missing splice tx_signatures on reestablish

This commit fixes a bug in LDK's Lightning channel reconnection logic after a splice (a way to resize a channel's on-chain funds). If one peer had already received the splice signatures but the other had not, and then they disconnected and…

Protocol-state inconsistency on reconnection after splice signature exchangePotential channel stall/force-close due to quiescence not being exited before commitment updateFuzzer-discovered edge case in Lightning splicing retransmission
f93a7f0cby Wilmer Paulino+600−975 files
No security note in commit
Moderate 59 AI analysisMessage 77 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(clear_signing): fix bytes[] and strings[] parsing. [no changelog]

This commit fixes how Trezor firmware parses certain Ethereum transaction data types—specifically arrays of byte blobs (bytes[]) and arrays of strings (string[])—when showing clear signing details on the device screen. Before the fix, the …

Incorrect offset handling in transaction data decoderPotential display of misleading clear-signing informationDouble pointer dereference in dynamic array parsing
6eb57726by PrisionMike+41−91 file
No security note in commit
Informational 13 AI analysisMessage 85 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(clear_signing): remove dead parse_uint256_array and unreachable guards.

This commit removes unused code and unreachable safety checks from the Ethereum clear-signing module. The removed function (parse_uint256_array) was never actually used, and the type-check guards it supported could never be triggered. Ther…

9d516f9fby PrisionMike+4−211 file
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this