Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This update fixes a way that people with limited access to a Bitcoin node could make fake log entries appear real. Normally, the node cleans up special characters in log messages but was leaving newlines alone. A clever user could slip a n…
Log injection / log forgery via embedded newlines in untrusted inputInput from restricted RPC users reaching log output without newline escapingControl-character escaping bypass due to explicit newline exception
This commit fixes a one-word typo in a comment inside a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually calls 'walletcreatefundedpsbt'. No code behavior changes, and there is no sec…
This commit fixes a typo in a comment within a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually exercises 'walletcreatefundedpsbt'. No code behavior changes, and there is no security…
This commit is a documentation-only update. It adds a single line to Bitcoin Core's list of implemented BIPs, noting that BIP 461 (a technique for making ECDSA signatures smaller and deterministic) has been implemented since version 0.17.0…
This patch fixes a bug in Bitcoin Core's `sendall` wallet command. If a user typed a bech32 address in uppercase letters, the command would fail with a confusing 'below dust threshold' error instead of sending the funds. The fix compares d…
Functional bug in RPC command causing unexpected transaction failureCase-sensitivity mismatch between user input and canonical address encodingNo memory safety, cryptographic, or authorization issue evident
This commit fixes a flaky automated test in Bitcoin Core. The test was checking the maximum transaction fee rate by creating a transaction at the exact boundary, which sometimes failed because the real transaction size could be slightly sm…
No production code changedTest-only changeNo memory safety, cryptography, consensus, or authorization changes
This is a build-system maintenance update for Bitcoin Core's reproducible build environment (Guix). It updates the Guix time-machine commit and several dependency versions, and temporarily disables some test suites that fail when building …
No direct security-relevant code change in Bitcoin Core consensus, wallet, or P2P layers.Dependency version bumps (git-minimal, linux-headers, python-lief, python-minimal) are routine build-environment updates.Disabling third-party package test suites reduces build-time test coverage but does not alter Bitcoin Core's own test or release binaries.
This change makes three Bitcoin command-line tools (bitcoin-tx, bitcoin-util, and bitcoin-wallet) automatically pick the fastest SHA-256 hashing implementation available on the computer, such as hardware-accelerated versions on modern CPUs…
This is a one-line fix in Bitcoin Core's network code. It changes how the size of a list of block headers is converted to a signed integer inside a loop. Previously, if the list was empty, the conversion could trigger undefined-behavior wa…
UndefinedBehaviorSanitizer integer sanitizer warning addressedImplicit signed/unsigned conversion in loop counterUnsigned integer wraparound on empty vector size
This change fixes a Bitcoin Core wallet bug where the `importprunedfunds` RPC command could only re-import transactions that sent money to the wallet, not transactions that spent money from it. After this fix, both incoming and outgoing tr…
Logic bug in wallet transaction import scopeIncorrect balance possible after removing and re-importing spending transactionFix routes import through existing involvement check (IsMine + IsFromMe)
This commit adds a new Bitcoin Core wallet startup option called -maxfeerate. It lets users set a maximum fee rate (fee per unit of transaction size) that the wallet will allow when creating or broadcasting transactions. Previously, the wa…
New wallet startup option -maxfeerate to cap transaction fee rateNew transaction error type MAX_FEE_RATE_EXCEEDEDBroadcastTransaction now checks both max absolute fee and max fee rate
This Bitcoin Core update fixes a wallet-signing quirk. When a user chose the SIGHASH_SINGLE signature mode, an input that had no matching output index would sign essentially nothing meaningful. That signature could then stay valid even if …
Funds-redirection footgun from SIGHASH_SINGLE signatures with no committed outputInconsistent guard between SignTransaction and SignPSBTInput pathsFix centralizes the guard in the low-level signature creator to cover future signing paths
This change updates Bitcoin Core's I2P (Invisible Internet Project) privacy network settings to use newer, stronger encryption for the published 'leaseset' that describes how other peers can contact a node. The old setting included ElGamal…
Cryptographic algorithm update (ElGamal to MLKEM-768)Use of I2P 'legacy' encryption type removedConfiguration-only change in network privacy layer
This change fixes a labeling bug in Bitcoin Core's first-run disk-space warning. The estimate was stored in GiB (binary gigabytes, 1024-based) but displayed as GB (decimal gigabytes, 1000-based), and for pruned nodes it showed the full-cha…
This is a wallet bug, not a theft or remote-code bug. When a Bitcoin Core user turns on the optional 'avoidpartialspends' or 'avoid_reuse' setting, an output group rejected during coin selection could be counted twice as 'discarded.' That …
Logic error causing double-counting of discarded UTXO groupsCan trigger false 'insufficient funds' failure in coin selectionAffects avoidpartialspends / avoid_reuse wallets only
This is a documentation-only fix in a tutorial file. It changes two shell examples from using '>>' (append to file) to '>' (overwrite file). If a user followed the old instructions and ran the same command twice, the file would contain two…
No security signal: change is limited to documentationNo code changes to Bitcoin Core binaries, RPC, wallet, or consensus logicNo cryptographic, network, or privilege-boundary implications
This is a large internal code reorganization (refactor) in Bitcoin Core. It creates a new BlockTemplateManager class that takes over block-template creation, block submission, and tip-waiting helpers that were previously spread across seve…
Large refactor touching mining, RPC, interfaces, and test shutdown pathsNew object lifetime dependency: BlockTemplateManager holds references to mempool, chainman, and notifications; explicit reset ordering added in Shutdown/InitAndLoadChainstate/test setupsRemoval of early-init node.mining interface; BlockTemplateManager is now created after chainstate load, with a comment that it must exist before setChainstateLoaded(true) unblocks IPC waiters
This commit adds the first implementation of BIP352 (Silent Payments) to Bitcoin Core. Silent Payments are a new type of privacy-preserving Bitcoin address that lets someone receive payments without publicly revealing a fixed address. The …
New cryptographic feature implementation (BIP352 Silent Payments)Extensive use of secp256k1 silentpayments moduleInput public key extraction from P2PKH, P2WPKH, P2SH-P2WPKH, and P2TR inputs
This update fixes a wallet database loading bug where a damaged or tampered Bitcoin wallet file could cause the program to read past the end of a stored extended public key (xpub). The patch makes the loader check the stored xpub length be…
Out-of-bounds read in wallet descriptor cache deserializationASan container-overflow triggered by malformed on-disk recordMissing length validation between record size prefix and fixed-size decoder
This commit adds a new wallet RPC called listrawtransactions to Bitcoin Core. It is a feature addition that lets users list every transaction their wallet knows about, including internal transfers and consolidations that the existing listt…
No security-relevant bug fix or vulnerability patch is present in the diff.New RPC exposes additional wallet transaction metadata, but only to callers already authorized for wallet RPCs.Code is a refactor of existing gettransaction logic into shared helpers; no new cryptographic, network, or consensus code.
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
Lower-priorityrpc: Add in_memory option to dumptxoutset with rollbackby Fabian Jahr · fc736013 · Apr 2, 2026 · 3 filesMessage 50 · ThinInformational 18Details
Commit message · Fabian Jahr
rpc: Add in_memory option to dumptxoutset with rollback
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 18/100
This commit adds a new optional 'in_memory' flag to the Bitcoin Core 'dumptxoutset' RPC command. When enabled, the temporary database used during rollback snapshot creation is kept in RAM instead of written to disk. This is a performance feature, not a security fix. There is no direct evidence in the commit that it addresses a vulnerability, and the change does not appear to introduce an obvious security flaw. The main risk is operational: a user could run out of memory if they enable this on mainnet without sufficient RAM.
Lower-prioritytest: Extend named pipe sqlite tool test to use rollbackby Fabian Jahr · d0fd7189 · Apr 2, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · Fabian Jahr
test: Extend named pipe sqlite tool test to use rollback
72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100
This is a routine test-only change for a developer tool. It extends an existing functional test so that the utxo-to-sqlite helper tool is exercised with a 'rollback' snapshot instead of a 'latest' snapshot, and compares the result against the coinstats index. There is no change to production code, no wallet or node behavior change, and no security issue.
Instead this new approach uses a temporary coins db to roll back the UTXO set.
This new approach also prevents the node from pruning necessary blocks during dumptxoutset execution by using prune locks.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
defensive validation
AI analysis · Low 44/100
This commit changes how the Bitcoin Core 'dumptxoutset' RPC command creates snapshots of older UTXO sets. Previously, it temporarily invalidated a block to roll back the chain, which suspended network activity and could leave the node in a bad state if something went wrong. The new approach copies the UTXO set to a temporary database and rolls it back there, leaving the main chain untouched. It also uses a prune lock to prevent needed blocks from being deleted during the operation. This is a robustness and operational-safety improvement rather than a fix for a remote exploit.
Also adds basic unit test coverage for prune lock management methods.
60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides an explanatory body✓ Mentions testing or verification
AI analysis · Informational 15/100
This commit adds a new housekeeping function, DeletePruneLock, that lets Bitcoin Core remove a previously created 'prune lock' by name. Prune locks are internal bookkeeping markers that prevent certain block data from being pruned too early. The change also adds unit tests for the new function. There is no indication this fixes a bug or addresses a security issue; it appears to be a normal feature/refactoring addition.
AI review queuedwalletdb: Remove m_mock from SQLiteDatabaseby Ava Chow · 037ea2c7 · Apr 2, 2026 · 4 filesMessage 45 · ThinInformational 12Details
Commit message · Ava Chow
walletdb: Remove m_mock from SQLiteDatabase
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100
This commit is a small internal code cleanup in Bitcoin Core's wallet database code. It removes a special 'mock' flag used only for testing and replaces it with a more general way to pass extra SQLite database options. The change only affects test helper code and how mock (in-memory) wallets are created during tests. There is no indication it fixes a security bug or introduces a security risk.
AI review queuedwallet: Make Mockable{Database,Batch} subclasses of SQLite classesby Ava Chow · 59484e2f · Apr 2, 2026 · 4 filesMessage 95 · StrongInformational 15Details
Commit message · Ava Chow
wallet: Make Mockable{Database,Batch} subclasses of SQLite classes
The mocking functionality of MockableDatabase, MockableBatch, and MockableCursor was not really being used. These are changed to be subclasses of their respective SQLite* classes and will use in-memory SQLite databases so that the tests are more representative of actual database behavior.
MockableCursor is removed as there are no overrides needed in SQLiteCursor for the tests.
95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a test-only refactoring change. It replaces a custom in-memory fake database used in Bitcoin Core's automated tests with a real SQLite database running in memory. There is no change to how actual user wallets work, no bug fix for live code, and no security issue introduced or fixed.
AI review queuedtest: Make duplicating MockableDatabases use cursor and batchby Ava Chow · e7d67c9f · Apr 2, 2026 · 2 filesMessage 95 · StrongInformational 15Details
Commit message · Ava Chow
test: Make duplicating MockableDatabases use cursor and batch
Instead of directly copying the stored records map when duplicating a MockableDatabase, use a Cursor to read the records, and a Batch to write them into the new database. This prepares for using SQLite as the database backend for MockableDatabase.
95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This is a test-only code change. It refactors how a fake in-memory wallet database is copied during unit tests so that the copy uses the same cursor-and-batch interface a real database would use. There is no change to production wallet code, no user-facing behavior change, and no security fix or vulnerability.
AI review queuedbench, wallet: Make WalletMigration's setup WalletBatch scopedby Ava Chow · 964eafb7 · Apr 2, 2026 · 1 fileMessage 77 · AdequateInformational 15Details
Commit message · Ava Chow
bench, wallet: Make WalletMigration's setup WalletBatch scoped
WalletBatch needs to be in a scope so that it is destroyed before the database is closed during migration.
77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Explains rationale or failure mode
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This change fixes a bug in a benchmark test program, not in the main Bitcoin wallet that users run. The benchmark creates a fake wallet to measure how long migration takes, and the fake wallet's database helper object was not being closed before the migration step tried to close the database. That could make the benchmark crash or fail, but it does not affect real wallets or network security.
Lower-prioritywallet, bench: Use TestingSetup in CoinSelection benchmarkby Ava Chow · b69f989d · Apr 2, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Ava Chow
wallet, bench: Use TestingSetup in CoinSelection benchmark
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100
This commit changes only a benchmark test file used to measure wallet coin-selection performance. It swaps a manually created test chain for the standard TestingSetup helper and wraps the code in a wallet namespace. There is no change to production wallet code, consensus rules, networking, or any code that handles real user funds. It is a test-code cleanup with no security relevance.
AI review queueddoc: Discourage trailing doxygen comments, and fix the broken onesby MarcoFalke · facaeb9c · Apr 2, 2026 · 4 filesMessage 50 · ThinInformational 15Details
Commit message · MarcoFalke
doc: Discourage trailing doxygen comments, and fix the broken ones
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit only changes documentation style guidance and moves or converts code comments. It does not alter any program logic, data handling, or network behavior, so it has no security impact.
PartiallyDownloadedBlock::InitData() intentionally treats duplicate short IDs in a compact block as READ_STATUS_FAILED.
For an honest peer, block-level short-ID collisions are rare enough that failing the compact block early is preferable to spending CPU scanning the mempool or attempting selective recovery.
Remove the old TODO that suggested requesting both collided transactions, since it since it points at unwanted behavior.
48/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context! Contains work-in-progress language
AI analysis · Informational 15/100
This commit only removes a two-line comment (a TODO note) from the source code. No actual code behavior changes. The TODO had suggested a future improvement for handling rare compact-block short-ID collisions, but the developers decided the current behavior—failing early on collisions—is intentional and preferable. It is purely a documentation cleanup.
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100
This commit removes a duplicate documentation marker (///@}) from a header file. It is purely a cosmetic documentation cleanup with no effect on program behavior or security.
fuzz: remove GetDescriptorChecksum from string harness
This function is already strongly fuzzed by other harness. E.g: descriptor_parse calls it several times during parsing and serialization. Also, calling GetDescriptorChecksum with a string of length 32 is not effective to exercise it.
83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100
This commit removes one line from a fuzz test file. Fuzz tests are automated tools that feed random inputs to functions to find crashes or bugs. The change simply stops calling the GetDescriptorChecksum function in this particular test, because other fuzz tests already exercise it more thoroughly. There is no change to any production code, no bug fix, and no security-relevant behavior change in the Bitcoin Core software itself.
kernel: Remove NONNULL annotation from destroy method
No other *_destroy function in the Kernel API carries this annotation. Following the convention set by free(), destroy functions should accept null pointers.
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 21/100
This commit removes a compiler hint telling the destroy function it must never receive a null pointer. The change makes the function behave more like standard free(), which safely accepts null. It is a defensive API-consistency fix, not a fix for an active crash or exploit.
lint: Clarify rmtree/remove_all error message with preferred alternatives
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100
This commit only rewords two lint error messages and fixes a minor code-formatting import line. It does not change any runtime behavior, security checks, or executable code paths in Bitcoin Core. There is no security issue here.
Security candidatecrypto: disable ASan instrumentation of SSE4 SHA256 for GCCby deadmanoz · fedeff7f · Apr 1, 2026 · 1 fileMessage 83 · StrongInformational 18Details
Commit message · deadmanoz
crypto: disable ASan instrumentation of SSE4 SHA256 for GCC
The existing Clang-only no_sanitize("address") guard is extended to also cover GCC. When GCC compiles this file with -fsanitize=address in debug builds, the instrumented inline assembly causes a SEGV during SHA256AutoDetect()'s self-test on CPUs that use the SSE4 code path (i.e. those without SHA-NI support), regardless of optimization level.
The original Clang code placed the attribute between the function declarator and the opening brace. GCC's Attribute Syntax documentation notes that this position in a function definition "may, in future, be permitted," so it is not currently supported. The attribute is moved to the start of the function definition, which is valid form for both GCC and Clang.
The preprocessor guards are restructured so each compiler branch is explicit: __clang__ with __has_feature, and __GNUC__ with __SANITIZE_ADDRESS__.
83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
defensive validationcryptography-sensitive path
AI analysis · Informational 18/100
This is a build-compatibility fix, not a security vulnerability in normal Bitcoin operation. It stops a specific compiler sanitizer (GCC's AddressSanitizer, used only in debug/test builds) from crashing when running SHA-256 self-tests on older CPUs that lack SHA-NI hardware support. The change does not affect production releases or how Bitcoin validates transactions.
AI review queuedqa: Improve error messageby Hodlinator · 257769a7 · Mar 31, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Hodlinator
qa: Improve error message
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This is a tiny quality-of-life change to a test helper. It only makes an error message clearer when a test fails, so developers can see exactly what text was produced. It does not touch Bitcoin's network code, wallet, consensus rules, or any code that runs in production.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Names security-relevant behavior explicitly
Why it was queued
access control
AI analysis · Informational 18/100
This commit only changes the wording of error messages shown when bitcoin-cli fails to log in to the RPC server. It does not fix or introduce any security vulnerability; it is a user-experience improvement that tells users more precisely why authentication failed (missing cookie file, cookie disabled, bad cookie contents, or wrong password).
Type will be used for reading the cookie in next commit.
Also corrects ERR/ERROR mismatch in docstring in request.h, and changes to CamelCase to avoid potential collision with Windows headers (https://github.com/bitcoin/bitcoin/pull/34965#issuecomment-4161331392).
95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100
This commit is a simple code cleanup: it renames an internal status type from GenerateAuthCookieResult to AuthCookieResult and changes its value names to CamelCase. It also fixes a typo in a code comment where 'ERROR' was written as 'ERR'. No behavior of the Bitcoin RPC authentication cookie is changed.
Lower-priorityrefactor: Use NodeClock::time_point for m_last_send/recv and m_ping_startby MarcoFalke · fa244b98 · Mar 31, 2026 · 6 filesMessage 97 · StrongInformational 14Details
Commit message · MarcoFalke
refactor: Use NodeClock::time_point for m_last_send/recv and m_ping_start
The two fields represent a time point, not a duration. Also, it is unclear why they use second precision.
Fix both issues by using NodeClock::time_point.
This refactor should not change any behavior.
This resolves the two temporary calls to time_since_epoch() added in the previous commit. However, it adds one new call to time_since_epoch(), which is resolved in the next commit.
97/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 14/100
This is a code cleanup change in Bitcoin Core. It changes how the program stores timestamps for the last time data was sent or received with a network peer, switching from raw second counts to proper clock time points. The commit message explicitly says this should not change behavior, and the diff shows equivalent conversions where the values are used. There is no indication of a security fix or vulnerability.
Lower-priorityrefactor: Use NodeClock::time_point for CNetMessage::m_timeby MarcoFalke · fa2605b2 · Mar 31, 2026 · 4 filesMessage 85 · StrongInformational 15Details
Commit message · MarcoFalke
refactor: Use NodeClock::time_point for CNetMessage::m_time
The field is not a duration, but a time point.
This will add two temporary calls to time_since_epoch(), which are fixed in the next commit.
85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Informational 15/100
This is a straightforward code cleanup (refactor) that changes how message timestamps are represented internally. It does not fix a bug, add a feature, or change network behavior. There is no security relevance.
Lower-prioritytest: mining: add coverage for GBT's "coinbasevalue" result fieldby Sebastian Falbesoner · 12c3c3f8 · Mar 30, 2026 · 1 fileMessage 95 · StrongInformational 15Details
Commit message · Sebastian Falbesoner
test: mining: add coverage for GBT's "coinbasevalue" result field
Add missing test coverage for the `getblocktemplate` RPC call "coinbasevalue" field, specifically that it is set to claim the full block reward.
95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100
This commit only adds a new test to Bitcoin Core's functional test suite. It checks that the getblocktemplate RPC returns a 'coinbasevalue' field equal to the full block reward (subsidy plus fees). There is no change to production code, no bug fix, and no security-relevant behavior change.
Security candidateci, iwyu: Fix warnings in `src/util` and treat them as errorsby Hennadii Stepanov · 8b49e2dd · Mar 30, 2026 · 42 filesMessage 50 · ThinInformational 15Details
Commit message · Hennadii Stepanov
ci, iwyu: Fix warnings in `src/util` and treat them as errors
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100
This commit is a routine code-quality cleanup. It adjusts which C++ header files are included in various source files under src/util and turns on a stricter automated check (IWYU) in the project's continuous integration. There is no functional change to Bitcoin Core's behavior, no bug fix, and no security-relevant change.
AI review queuedrefactor: Move license info into new moduleby Hennadii Stepanov · 6953363b · Mar 30, 2026 · 15 filesMessage 57 · ThinInformational 15Details
Commit message · Hennadii Stepanov
refactor: Move license info into new module
57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a straightforward code cleanup: it moves the functions that generate copyright and license text from one source file to a new dedicated module, then updates the various Bitcoin programs to include that new module. There is no change to what the software does, no bug fix, and no security-relevant behavior change.
Lower-priorityiwyu: Remove workaround for issue that has been fixed upstreamby Hennadii Stepanov · eb750d27 · Mar 30, 2026 · 1 fileMessage 73 · AdequateInformational 15Details
Commit message · Hennadii Stepanov
iwyu: Remove workaround for issue that has been fixed upstream
This was overlooked in bitcoin/bitcoin#34896.
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100
This commit removes a code comment and a special compiler/tooling directive that were only there to work around a bug in a third-party developer tool (include-what-you-use). The actual C++ source code still includes the same header file as before, so program behavior is unchanged. There is no security relevance.