Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
58/100 average clarity
68Strong · 80–100
321Adequate · 60–79
302Thin · 40–59
88Opaque · 0–39
26security candidates with opaque commit messaging
This commit adds a new 'session reset' command to the BitBox02 hardware wallet's USB protocol. It lets the host computer cleanly reset the device connection if a previous operation was interrupted, instead of leaving the device stuck mid-t…
New USB control command added to host-wallet protocolReset path cancels async task, resets Noise state, unlocks USB processing, and clears output queueU2F UI ownership check prevents reset from interrupting an active U2F workflow
This is a routine Python code refactor. It moves an existing 'reset session' command from one internal class to another and adds a version check so older firmware simply skips it. There is no security bug being fixed here; it is purely org…
This commit fixes a bug in the BitBox02 hardware wallet where unplugging the USB cable at the wrong moment could leave a half-finished operation running. If the device stayed powered and a new host reconnected, the new host's first message…
Fixes cross-session state confusion on USB reconnectAdds explicit session reset command to cancel stale async workflowsResets Noise cryptographic session to prevent old-key encrypted responses
This commit adds a new recovery-word entry screen for the upcoming BitBox03 hardware wallet. It is a large feature patch: it introduces a dedicated BIP39 wordlist keyboard, a new recovery-words review screen, and changes how the device han…
New UI workflow distinguishes 'back' from 'cancel' during seed restoration, reducing accidental aborts.Cancel actions still require an explicit confirmation prompt before the restore is abandoned.Wordlist keyboard disables keys that cannot lead to a valid BIP39 word, preventing invalid-word compositions at the widget level.
This commit improves the BitBox02 hardware wallet's Ethereum token-approval screen. When a user signs an ERC20 token transfer, the device now also shows the token's smart-contract address if the token symbol is ambiguous (the same ticker, …
UI hardening: adds contract-address confirmation for ERC20 tokens with ambiguous or unknown symbolsRegistry validation: rejects payment requests for tokens not present in the firmware's ERC20 registryBuild-time ambiguity detection: generates a sorted list of units shared by multiple contracts
This commit relaxes a version check in the BitBox02 bootloader upgrade code. Previously, the firmware installer required that a stage0 bootloader descriptor's version exactly matched the currently expected image version. Now it accepts des…
Strict version equality check removed from bootloader descriptor parsingChange located in bootloader upgrade / firmware installer verification pathNo bounds, length, or pointer validation changes observed
This commit hardens the BitBox02 firmware so it stops trusting that incoming text strings are valid UTF-8 or plain ASCII. It replaces risky C string copies with length-checked, UTF-8-aware helpers, rejects non-ASCII characters at UI bounda…
Replaced snprintf-based string copies with length-bounded UTF-8-aware copiesAdded explicit length parameter to memory_set_device_name and reject embedded/invalid nullsAdded printable-ASCII enforcement at Rust UI boundary before C rendering
This commit fixes a coding guideline violation in the BitBox02 factory setup code. A 32-byte buffer that receives output from a Rust function was not initialized to zeroes before use. The accompanying documentation now explicitly requires …
Uninitialized stack buffer used as output buffer for Rust/C FFI callDefensive zero-initialization added to prevent use of stale stack data on error or partial write pathsProject coding guidelines updated to mandate zero-initialization for rust_util_bytes_mut buffers
This commit fixes a display behavior issue during startup of the BitBox02 hardware wallet. Previously, when the device turned on, the screen's reset pin was left in a state that could allow leftover images or text from an earlier session t…
Information disclosure via residual display content during bootOLED reset pin sequencing hardeningDefense against stale/misleading UI state before verified firmware initializes display
This commit trims the BitBox02 factory-setup firmware image by switching stored root attestation public keys from 65-byte uncompressed to 33-byte compressed secp256k1 keys, and by using a smaller static secp256k1 verification context inste…
Change in trusted public-key table format and derivation logicSwitch to static/no-precomp secp256k1 verification contextAddition of secp256k1 self-test at boot
This commit adds extra safety checks in the BitBox02 Python library for ECDSA signatures used in Bitcoin and Ethereum signing. It now validates that signatures have the correct length, use valid numbers, and use the safer low-S form. It al…
Defensive validation added for ECDSA signature format and low-S encodingRecovery ID range validation added for recoverable signaturesAnti-Klepto verification now rejects malformed/malleable signatures before nonce verification
This commit tweaks how the BitBox02 hardware wallet displays a payment-request memo on screen. It changes the label from 'Memo from\n\nMerchant' to 'Memo from: Merchant' and makes the screen scrollable so long merchant names don't get cut …
No security-relevant signal in commit message or diffUI/UX change only: text formatting and scrollabilityNo memory-safety, cryptographic, or authorization changes observed
This commit is a hardening and size-optimization change for the BitBox02 factory-setup firmware. It stores the 110 built-in root attestation public keys in compressed (33-byte) form instead of uncompressed (65-byte) form, and marks the tab…
Data table moved from writable RAM to read-only flash (const)Public-key table size reduced from 65 to 33 bytes per keyNew Rust helper normalizes compressed/uncompressed keys before hashing
This commit swaps one internal cryptography library for another when computing HMAC-SHA256 in the factory-setup code. The goal is to reduce firmware size by reusing an existing SHA-256 implementation, not to fix a security bug. New test ve…
Cryptographic implementation change in HMAC-SHA256 helperUse of `.unwrap()` on `new_from_slice`, which can panic if key length is unsupported; for HMAC-SHA256 the RustCrypto `new_from_slice` accepts any key length, so this is effectively safe but still a panic pathNo removal of existing call sites; normal firmware still uses `bitcoin_hashes` for other callers
This commit changes how the BitBox02 factory-setup program checks digital signatures. It switches from a dynamically created crypto context to a built-in, read-only verification context, which makes the factory-setup firmware about 35 KB s…
Cryptographic context change in verification pathRemoval of dynamic secp256k1 context creation in factory setupExplicit addition of secp256k1_selftest() to compensate for skipped implicit self-test
This commit is a performance optimization in the BitBox02 factory setup process. It changes how the device picks which trusted root public key to use when verifying an attestation certificate. Previously, the device tried verifying the sig…
No removal of cryptographic verification: rust_secp256k1_verify is still performed after key selection.No change to accepted inputs: any certificate accepted before is still accepted, and any rejected before is still rejected.Identifier comparison uses MEMEQ over the full 32-byte SHA-256 digest, so collision resistance is standard.
This commit is a large feature merge that adds initial support for a new hardware variant, the BitBox03 (STM32U5-based development kit). It introduces new bootloader and firmware binaries, board support crates, vendored Rust dependencies (…
This commit adds a progress bar that appears while the BitBox02 is loading large Ethereum transaction data from a connected computer. It is a user-experience improvement, not a security fix. The code only changes how progress is displayed …
This commit adds a configuration file for OpenOCD, a debugging tool used during hardware development and testing. It tells the debugger how to connect to an STM32U5 test board using a J-Link adapter. There is no change to firmware code, no…
This commit only adds explanatory comments to Python type-stub files describing what happens when an optional anti-klepto host nonce commitment is left out. It does not change any firmware logic, cryptographic code, or default behavior. Th…
Documentation-only change in generated Python stubsMentions anti-klepto / S2C nonce commitment fallback behaviorNo logic, default, or cryptographic implementation change
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
boot or update pathmerge-commit duplicate discount
AI analysis · Low 34/100
This commit improves the Python firmware-flashing tool for BitBox hardware wallets. It adds clearer warnings, requires user confirmation before flashing, detects firmware type automatically instead of relying on filename or a debug flag, and exposes more detailed bootloader error messages. The changes are primarily usability and safety improvements for a developer/testing tool, not a fix for an exploitable device vulnerability.
Detect development bootloaders and automatically classify signed and unsigned firmware inputs.
Confirm the detected combination by default, with -y/--yes for non-interactive use.
Keep --debug as a deprecated no-op for backwards compatibility.
Warn about combinations expected to fail without blocking deliberate bootloader error tests.
Treat signature-data errors as nonfatal on development devices and fatal on production devices.
Improve bootloader errors and timeout handling, and document and test the flashing matrix.
83/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
signing boundaryupdate trustboot or update path
AI analysis · Informational 23/100
This commit improves a Python helper used by developers to flash firmware onto BitBox hardware wallets. It makes the tool smarter about whether the connected device is a production or development unit, detects signed vs unsigned firmware files automatically, and adds clearer warnings and confirmation prompts. The changes are mostly usability and safety improvements for a developer-facing script, not a fix for a remote attack on user devices.
Security candidateMerge remote-tracking branch 'agent/benma-agent/create-firmware-release'by Marko Bencun · 332cd4d2 · Aug 26, 2026 · 9 filesMessage 50 · ThinInformational 12Details
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathboot or update pathmerge-commit duplicate discount
AI analysis · Informational 12/100
This commit is a merge that adds and updates release-helper scripts for the BitBox02 hardware wallet. It introduces a new script to draft GitHub firmware releases, refactors existing scripts to share a common parser for signed firmware files, and adds type annotations and tests. There is no direct evidence in the diff of a security vulnerability or malicious change; it appears to be routine release-tooling maintenance.
Security candidateExpose bootloader version in device infoby Niklas Dusenlund · 03cae40c · Aug 25, 2026 · 29 filesMessage 68 · AdequateInformational 19Details
Commit message · Niklas Dusenlund
Expose bootloader version in device info
Read and validate the installed stage1 header, then expose its marketing version through the HAL and device info protobuf response.
Keep the field absent for legacy bootloaders and return None from the Python client when unavailable.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
update trustdefensive validationcryptography-sensitive pathboot or update path
AI analysis · Informational 19/100
This commit adds a new read-only field to the BitBox02's device information response so the host app can learn which bootloader version is installed. It does not change how data is signed, encrypted, or authorized. The main security-relevant aspect is that the firmware now reads a small version string from the bootloader area and validates the bootloader header's magic value and length before exposing it. This is a defensive information-disclosure change rather than a vulnerability fix.
AI review queuedMerge remote-tracking branch 'agent/benma-agent/show-eip712-primary-type'by Marko Bencun · 3b1209b3 · Aug 24, 2026 · 2 filesMessage 50 · ThinLow 30Details
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Low 30/100
This update adds an extra confirmation screen when signing Ethereum typed messages (EIP-712). Before the user approves a signature, the device now shows the message's primary type, such as 'Authorize' or 'Revoke'. This helps users notice if a website is asking them to sign a different kind of message than they expect, reducing the risk of being tricked into approving a harmful signature.
AI review queuedMerge remote-tracking branch 'agent/benma-agent/warn-eip712-array-truncation'by Marko Bencun · f3294c66 · Aug 24, 2026 · 1 fileMessage 50 · ThinLow 38Details
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Low 38/100
This change updates how the BitBox02 hardware wallet warns users when displaying very long member names in Ethereum typed-data (EIP-712) array confirmations. It replaces a direct confirmation call with a shared helper that adds a truncation warning screen. The practical effect is to make sure users see a 'Warning' screen before a long field name is shown, reducing the chance that a maliciously crafted field name could hide or spoof important confirmation details.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication pathmerge-commit duplicate discount
AI analysis · Informational 22/100
This commit adds vendored copies of two Rust embedded-crates (cortex-m-rt and its companion macro crate) plus a large auto-generated STM32U5 peripheral access crate to the BitBox02 firmware repository. Vendoring means the project is no longer fetching these libraries from the public crates registry at build time; instead it uses its own frozen copy. The change itself is a build-system/dependency-management refactor. There is no direct evidence in the commit message or diff that this fixes a known security vulnerability, but vendoring can affect how future upstream security patches are applied and the STM32 register definitions are security-relevant because they control hardware protections (TrustZone, debug, flash, etc.).
AI review queuedMerge branch 'nickez/st-drivers'by Niklas Dusenlund · badbc84c · Aug 24, 2026 · 92 filesMessage 45 · ThinInformational 15Details
Commit message · Niklas Dusenlund
Merge branch 'nickez/st-drivers'
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
This commit adds the official STMicroelectronics low-level driver package (CMSIS and HAL) for the STM32U5 microcontroller family to the BitBox02 firmware repository. It is a large vendor code import with no functional firmware changes, no bug fixes, and no security patches visible in the diff.
AI review queuedMerge branch 'pr-2049'by Jad · f0f7cb78 · Aug 24, 2026 · 19 filesMessage 28 · OpaqueLow 39Details
Commit message · Jad
Merge branch 'pr-2049'
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit adds new touchscreen keyboard and PIN keypad screens for the BitBox03 hardware wallet, along with changes to how secret text (passphrases, PINs) is read from the on-screen buffer. The most notable security-relevant change is a fix for how the device copies sensitive text: it now reads the LVGL text buffer directly into a zeroizing string, avoiding an intermediate non-zeroized copy that could leave secret characters in memory. The commit also hardens touch handling so that sliding a finger off a key before releasing does not type the key or confirm an action, and it clears stale key selections to prevent accidental double-typing. Most of the rest is UI layout, fonts, and simulator tooling.
Security candidateMerge commit 'refs/pull/2061/head' of https://github.com/BitBoxSwiss/bitbox02-firmwareby Marko Bencun · aa92b419 · Aug 24, 2026 · 2 filesMessage 58 · ThinInformational 15Details
Commit message · Marko Bencun
Merge commit 'refs/pull/2061/head' of https://github.com/BitBoxSwiss/bitbox02-firmware
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
boot or update pathmerge-commit duplicate discount
AI analysis · Informational 15/100
This commit only adds two digital signature files for an already-released firmware version (v9.26.5). These signatures are used by users to independently verify that the published firmware binary matches what a specific signer reviewed. No code, no firmware binary, and no behavior of the device or software is changed. There is no security vulnerability here.
- The graphical simulator starts with the keystore locked; launch with --unlock (requires --preseed) to start it unlocked. Unlocking also retains the BIP39 seed, so user gets no password prompt.
- Entered PINs/passphrases are wrapped in zeroize::Zeroizing, copied straight out of LVGL's buffer. This avoids the intermediate CString of TextareaExt::get_text(), which was dropped without zeroizing.
- Remove the flicker when nav buttons toggle enabled/disabled.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
secret or key materialaccess controlmemory safety
AI analysis · Low 44/100
This commit fixes a security hygiene issue in the BitBox02 firmware's on-screen text-entry code. Previously, when a user typed a PIN or passphrase, the code briefly created an intermediate plain-text copy of the secret that was not securely erased from memory after use. The patch reads the secret directly into a zeroizing container so it is wiped when no longer needed. The same commit also removes a visual flicker on disabled navigation buttons and changes a simulator command-line flag from '--lock' to '--unlock'.
AI review queuedMerge branch 'changelog'by Marko Bencun · eb2831c7 · Aug 24, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Marko Bencun
Merge branch 'changelog'
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit is a routine merge that adds a new version heading (v9.27.0) to the project's CHANGELOG.md file. It contains no code changes, no bug fixes, and no security-related content.
AI review queuedCHANGELOG: mark v9.27.0by Marko Bencun · 2fba75a4 · Aug 24, 2026 · 1 fileMessage 38 · OpaqueInformational 15Details
Commit message · Marko Bencun
CHANGELOG: mark v9.27.0
38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
This commit is a routine changelog update that labels the upcoming firmware release as version 9.27.0. It does not change any source code, configuration, or security behavior. There is no security-relevant content in the diff.
Security candidateble: format pairing code without snprintfby Niklas Dusenlund · 1a02902b · Aug 24, 2026 · 1 fileMessage 68 · AdequateInformational 19Details
Commit message · Niklas Dusenlund
ble: format pairing code without snprintf
Write the bounded six-digit pairing code directly. This makes the range proof explicit and avoids the compiler's truncation warning.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
consensus or confidential-proof validation
AI analysis · Informational 19/100
This commit replaces a standard text-formatting function (snprintf) with a small hand-written loop to display a six-digit Bluetooth pairing code on the BitBox02 hardware wallet screen. The change is described by the author as a cleanup to silence a compiler warning and make the numeric bounds more obvious. There is no direct evidence in the commit that this fixes an exploitable security bug.
Security candidateMerge remote-tracking branch 'agent/benma-agent/bitcoin-time-locks'by Marko Bencun · a6d62b78 · Aug 24, 2026 · 11 filesMessage 50 · ThinLow 32Details
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet pathmerge-commit duplicate discount
AI analysis · Low 32/100
This commit adds support for timestamp-based Bitcoin nLockTime values (values of 500,000,000 or higher) in the BitBox02 hardware wallet. Previously, such locktimes were rejected as invalid. The change also removes the on-screen RBF (Replace-By-Fee) status display from locktime confirmations and updates the Python library to require firmware version 9.27.0 when using timestamp locktimes. It is a feature addition with associated UI changes, not a security fix for a known vulnerability.
Security candidateMerge branch 'release-assertions-v9.26.5'by Marko Bencun · e330bb84 · Aug 24, 2026 · 4 filesMessage 45 · ThinInformational 15Details
Commit message · Marko Bencun
Merge branch 'release-assertions-v9.26.5'
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
boot or update pathmerge-commit duplicate discount
AI analysis · Informational 15/100
This commit adds signed release assertions for BitBox02 firmware version 9.26.5. These are text files plus cryptographic signatures that record the expected SHA-256 hash of the compiled firmware. They are part of the reproducible-build verification process and do not change any firmware code, wallet logic, or device behavior. There is no security vulnerability here.
AI review queuedMerge remote-tracking branch 'agent/benma-agent/btc-signmsg-m45'by Marko Bencun · 3cd5d638 · Aug 24, 2026 · 5 filesMessage 50 · ThinLow 32Details
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Low 32/100
This commit adds the ability to sign Bitcoin messages using keys in the m/45' keypath namespace, which is used by some external services like Unchained and Casa. Previously, message signing only worked for standard Bitcoin address keypaths. The change splits address derivation into a validated and an unvalidated variant, and adds a new keypath check for m/45' paths. It also updates the on-screen message to warn users that the key belongs to an external service, so they don't mistake it for a normal wallet address.
Require firmware 9.4.0 or newer unconditionally for BTC transaction signing. Reject BTC and ETH message signing and ETH transaction signing when firmware predates each workflow's antiklepto support.
Keep Ed25519 workflows and the explicit EIP-712 opt-out unchanged, and bump py-bitbox02 to version 8.0.0 for the breaking change.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing boundary
AI analysis · Low 34/100
This commit updates the BitBox02 Python library so it refuses to sign Bitcoin and Ethereum transactions or messages unless the hardware wallet is running a firmware version that supports the anti-klepto feature. Anti-klepto is a protocol that helps prevent a compromised device from leaking secret key material through biased randomness in signatures. The change removes older, less-protected fallback signing paths and bumps the library version to 8.0.0 because it now requires newer firmware.
Show the memo attribution and recipient on one scrollable line so long authenticated recipient names remain reviewable.
Bump the firmware version to v9.27.2 and gate the updated test vectors at that version, preserving historical transcripts. Regenerate the canonical JSON and document the compatibility rule. Record scrollability in the test UI and cover long SWAPKIT names.
78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidencesigning or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100
This firmware update changes how long merchant or recipient names are shown when approving Bitcoin payments. Instead of breaking the name across two lines, which could be cut off or hidden, the name now appears on a single line that the user can scroll through. This helps users actually see and verify long names like 'SWAPKIT (...)' during payment approval. The change is a usability and anti-spoofing improvement, not a vulnerability fix in the traditional sense, but it does close a small security gap where truncated or wrapped names might mislead a user.
Add a Message type confirmation before traversing typed data so the device transcript binds the host-selected primary type.
Cover same-shaped requests with distinct primary types, update the end-to-end signing screen expectation, and record the change in the firmware changelog.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 44/100
This commit adds an extra on-device confirmation step when signing Ethereum typed messages (EIP-712). Before walking through the message fields, the BitBox02 now shows the user the 'primary type' (for example 'Authorize' or 'Revoke'). The goal is to prevent a malicious computer program from swapping one message type for another that has the same field shapes, because the device would then bind the user-approved signature to the wrong type. It is a hardening fix rather than a clear-cut vulnerability patch.
Security candidatebtc: support timestamp locktimesby benma's agent · 4a71af37 · Aug 19, 2026 · 11 filesMessage 70 · AdequateLow 32Details
Commit message · benma's agent
btc: support timestamp locktimes
Accept timestamp-based nLockTime values and display the exact signed value in UTC.
Keep confirmation for effective locktimes because they control when a transaction becomes final.
Remove RBF status because replacement is mempool policy, not signed consensus state.
Bitcoin Core's full-RBF policy also makes sequence-derived opt-in status misleading.
Litecoin did not show replacement status, so the per-coin RBF flag is no longer needed.
Document client support and add a BIP388 after(timestamp) vector that finalizes and validates.
defensive validationcryptography-sensitive pathsigning or wallet path
AI analysis · Low 32/100
This commit adds support for timestamp-based Bitcoin transaction locktimes in the BitBox02 hardware wallet. Previously, locktimes at or above 500,000,000 were rejected; now they are accepted and shown to the user as a UTC date and time. The commit also removes the on-screen 'RBF' (Replace-By-Fee) indicator because RBF is a network policy, not a guaranteed property of the signed transaction. This is a normal feature addition with no obvious security bug, though it changes what transaction details users see before signing.
AI review queuedMerge remote-tracking branch 'agent/benma-agent/shared-btc-test-vectors'by Marko Bencun · 50e1f546 · Aug 18, 2026 · 18 filesMessage 60 · AdequateInformational 15Details
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a large merge that adds a new Rust crate called bitbox-test-vectors. It is purely a testing and quality-assurance change: it creates shared Bitcoin transaction test vectors (sample PSBTs and expected firmware behavior) so that the firmware, the Go client library, and the Rust client library can all use the same test data. There is no change to the actual device firmware logic, no new runtime feature, and no fix for a security bug. It is a test-infrastructure improvement.
AI review queuedbump version to v9.27.0by benma's agent · 68a3a43b · Aug 18, 2026 · 1 fileMessage 38 · OpaqueInformational 15Details
Commit message · benma's agent
bump version to v9.27.0
38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit simply updates a version number in a JSON file from v9.26.5 to v9.27.0. There are no code changes, no security fixes, and no functional changes visible in the diff.
Limit the embedded panic handler to bare-metal targets and expose test-only helpers under cfg(test).
Make plain cargo test work without requiring all features.
78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit is a build-system and test-infrastructure fix. It changes Rust conditional-compilation flags so that unit tests can compile and run on a normal computer (host target) instead of only on the embedded device. It also limits the custom panic handler to bare-metal ARM builds and exposes some test-only helper functions under the test configuration. There is no change to runtime security behavior for end users.
AI review queuedMerge remote-tracking branch 'agent/benma-agent/btc-input-relative-fee-warning'by Marko Bencun · 341cc73a · Aug 18, 2026 · 2 filesMessage 50 · ThinLow 32Details
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Low 32/100
This commit improves the user warning shown when a Bitcoin transaction has an unusually high fee. Previously, the device calculated the fee as a percentage of the amount being sent. For transactions that send nothing to an outside recipient (for example, sending everything back to yourself or only carrying an OP_RETURN memo), the denominator was zero, so no percentage warning could be shown and the user might not be alerted if the fee consumed most of the funds. The patch now falls back to comparing the fee against the total value of all transaction inputs, and tells the user whether the warning is based on the send amount or on all inputs. It is a defensive hardening change, not a fix for an active exploit.