Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

23Projects watched
16913Commits captured
16841AI analyses
83High-risk findings · 30d
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

16841 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 47 · Thin
LL Lightning LabsLND BitcoinLightning Network

docs: update release notes

This commit only updates the release notes document. It adds a one-line description mentioning that a new feature for handling BOLT 12 invoice errors was added. There are no code changes, no bug fixes, and no security-related content in th…

5fcdc16aby bitromortac+4−01 file
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
KS KeystoneKeystone 3 firmware BitcoinHardware wallets

test(zcash): restore v1 PCZT end-to-end coverage

This commit only adds and updates test code for the Zcash cryptocurrency support in the Keystone 3 firmware. It restores an end-to-end test that exercises version 1 PCZT (Partially Created Zcash Transaction) handling for older Orchard tran…

75b69553by Adam Tucker+74−82 files
No security note in commit
Informational 13 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

feat: Add master fingerprint calculation.

This commit adds a new build-time tooling feature for Trezor firmware: it calculates a single 'master fingerprint' that summarizes all the individual firmware image fingerprints produced during a reproducible build. It also improves the ex…

No memory-unsafe code addedNo cryptographic primitives implemented; uses standard hashlib.sha256No privilege escalation, authentication bypass, or secret exposure observed
eb5b3f4cby Andrew Kozlik+439−579 files
No security note in commit
Low 35 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

fix: build-docker.sh: fix --no-init usage

This commit fixes a build script used to create Trezor firmware inside Docker. Previously, when reusing an existing build environment, the script could silently build old source code instead of the requested branch or tag. It also now corr…

Silent stale-source build risk under --no-initAnnotated tag dereference fix prevents tag-vs-commit mismatchEnvironment drift check prevents building with outdated toolchain/environment
6307fc7bby Andrew Kozlik+24−11 file
No security note in commit
Informational 15 AI analysisMessage 77 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

feat: build-docker.sh: skip bitcoin-only variants for targets that do not have one

This commit changes a build script so that when building only Bitcoin-only firmware variants, it skips targets like boardloader, bootloader, and secure monitor that do not have such variants. It is a build-logic convenience fix with no app…

fd6e136bby Andrew Kozlik+11−01 file
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

fix: build-docker.sh: build T1B1 firmware only for firmware target

This commit fixes a CI/build script inefficiency. The build script was building the same T1B1 (original Trezor) firmware twice because it ignored the requested build target. The fix makes the legacy T1B1 firmware build run only when the 'f…

17890ebfby Andrew Kozlik+7−22 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

build: silence udevCheckHook in nix-shell, there are no udev rules to check

This commit adds a single build configuration line to the project's Nix shell environment. It simply stops a harmless informational message ('Using udevCheckHook') from being printed during setup, because there are no udev device rules pre…

41692dc2by Andrew Kozlik+2−01 file
No security note in commit
Informational 15 AI analysisMessage 63 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: update nixpkgs

This commit is a routine maintenance update to the Nix package set used for building and development. It also includes minor formatting cleanups in unrelated files, such as removing now-unnecessary type-checker suppression comments and an …

85ea63c0by M1nd3r+13−215 files
No security note in commit
Informational 15 AI analysisMessage 98 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): remove SDL error suppression

This commit removes a single environment variable that was hiding SDL (Simple DirectMedia Layer) log messages during automated tests. It is a cleanup change with no apparent security relevance.

ab211a4fby M1nd3r+0−11 file
No security note in commit
Informational 19 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(deps): update astroid, pydantic, and pylint

This is a routine dependency update for development tools used by the Trezor firmware project. It bumps versions of astroid, pydantic, and pylint to support Python 3.14, and makes small compatibility changes in a custom pylint plugin. Ther…

Routine dependency bump for development toolingNo changes to firmware, cryptography, or wallet logicNo vendor mention of CVE, advisory, or security fix
50df0d20by M1nd3r+42−1663 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this