Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

24Projects watched
17490Commits captured
17117AI analyses
88High-risk findings · 30d
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

17117 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 50 · Thin
LD LedgerLedger Bitcoin app BitcoinHardware wallets

Add testcases with snapshots for multisig k-of-n and several taproot leaves

This commit only adds new test cases and screen snapshots for the Ledger Bitcoin app. It exercises two wallet-registration scenarios: a 2-of-3 multisig wallet and a Taproot wallet with multiple spending paths. There are no changes to the a…

fd75daddby Salvatore Ingala+35−0108 files
No security note in commit
Informational 15 AI analysisMessage 18 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

update translations

This commit only updates the list of translatable text strings in BTCPay Server. It adds, removes, and reorders phrases used by the application's user interface. There are no code logic changes, no security fixes, and no behavior changes.

a27f7a9aby Nicolas Dorier+69−351 file
No security note in commit
Informational 15 AI analysisMessage 68 · Adequate
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

rpc: add OpenRPC discovery alias

This commit adds a new read-only alias 'rpc.discover' that returns the same public API documentation already available via 'getopenrpcinfo'. It also fixes a metadata annotation so amount fields are described as numbers rather than strings.…

ca9ffb8eby willcl-ark+73−393 files
No security note in commit
Low 34 AI analysisMessage 68 · Adequate
EP Elements ProjectCore Lightning BitcoinLightning Network

msggen: new rust types for `sat` and `sat_or_all`

This commit changes how the Core Lightning (CLN) Rust RPC and gRPC libraries represent and serialize amounts. It introduces separate types for satoshi-denominated amounts (AmountSat) versus millisatoshi-denominated amounts (Amount), and ch…

Breaking serialization change: amount fields now emitted as raw u64 instead of suffixed stringsNew AmountSat/AmountSatOrAll types separate sat and msat unitsGenerated gRPC proto types updated for sat-denominated fields
8405796bby daywalker90+1854−159414 files
No security note in commit
Low 30 AI analysisMessage 50 · Thin
KS KeystoneKeystone 3 firmware BitcoinHardware wallets

fix the verifying ps hang on wrong password in btc only multi-sig

This commit fixes a user-interface bug in the Bitcoin-only multi-sig wallet screens of the Keystone 3 hardware wallet firmware. If a user entered the wrong device-unlock password while the lock screen was shown over these multi-sig views, …

UI lock-up / denial of usability on wrong passwordIncorrect routing of password verification result between overlapping viewsMissing handling for SIG_LOCK_VIEW_SCREEN_GO_HOME_PASS in password error path
2037a16aby aaron+20−02 files
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
KS KeystoneKeystone 3 firmware BitcoinHardware wallets

apply the fix for the model overlap issue on proverownership page

This commit fixes a UI bug in the Keystone 3 hardware wallet where a password-entry modal did not fully cover the screen and did not block touch input on empty areas. Because taps could pass through to buttons on the page underneath, a use…

Click-through modal allowing unintended interaction with underlying page buttonsFixed-size modal leaving uncovered screen real estate on lv_layer_topUI-level safety issue in password-entry flow (prove ownership / passphrase screen)
029efbddby aaron+9−11 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
KS KeystoneKeystone 3 firmware BitcoinHardware wallets

update the font charactar

This commit is a routine font update for the Keystone 3 hardware wallet firmware. It adds, removes, and reorders Chinese, Japanese, and Korean font glyphs (for example adding characters meaning 'weak' and 'rights') and updates the correspo…

1efd952cby aaron+1136−9719 files
No security note in commit
Informational 15 AI analysisMessage 68 · Adequate
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

bitcoin: Depend on encoding 1.1.0

This is a routine dependency version bump in a Rust package manifest. The bitcoin crate was already using a feature ('hex') from its internal encoding crate, but the manifest only required version 1.0.0. Since that feature was added in ver…

c719de4cby Tobin C. Harding+1−11 file
No security note in commit
Informational 15 AI analysisMessage 23 · Opaque
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

primitives: Remove todo

This commit only changes a code comment. It replaces a developer TODO note with a short explanation that the code is verbose because it implements a state machine. No code behavior, logic, or security properties changed.

e62e553dby Tobin C. Harding+1−11 file
No security note in commit
Informational 15 AI analysisMessage 60 · Adequate
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

primitives: Bump version to 0.103.0

This commit is a routine release preparation: it bumps the version number of the `bitcoin-primitives` crate from 0.102.0 to 0.103.0, updates related dependency declarations in other crates, refreshes lock files, and adds a changelog entry.…

5612224dby Tobin C. Harding+48−88 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this