Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This update fixes a way that people with limited access to a Bitcoin node could make fake log entries appear real. Normally, the node cleans up special characters in log messages but was leaving newlines alone. A clever user could slip a n…
Log injection / log forgery via embedded newlines in untrusted inputInput from restricted RPC users reaching log output without newline escapingControl-character escaping bypass due to explicit newline exception
This commit fixes a one-word typo in a comment inside a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually calls 'walletcreatefundedpsbt'. No code behavior changes, and there is no sec…
This commit fixes a typo in a comment within a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually exercises 'walletcreatefundedpsbt'. No code behavior changes, and there is no security…
This commit is a documentation-only update. It adds a single line to Bitcoin Core's list of implemented BIPs, noting that BIP 461 (a technique for making ECDSA signatures smaller and deterministic) has been implemented since version 0.17.0…
This patch fixes a bug in Bitcoin Core's `sendall` wallet command. If a user typed a bech32 address in uppercase letters, the command would fail with a confusing 'below dust threshold' error instead of sending the funds. The fix compares d…
Functional bug in RPC command causing unexpected transaction failureCase-sensitivity mismatch between user input and canonical address encodingNo memory safety, cryptographic, or authorization issue evident
This commit fixes a flaky automated test in Bitcoin Core. The test was checking the maximum transaction fee rate by creating a transaction at the exact boundary, which sometimes failed because the real transaction size could be slightly sm…
No production code changedTest-only changeNo memory safety, cryptography, consensus, or authorization changes
This is a build-system maintenance update for Bitcoin Core's reproducible build environment (Guix). It updates the Guix time-machine commit and several dependency versions, and temporarily disables some test suites that fail when building …
No direct security-relevant code change in Bitcoin Core consensus, wallet, or P2P layers.Dependency version bumps (git-minimal, linux-headers, python-lief, python-minimal) are routine build-environment updates.Disabling third-party package test suites reduces build-time test coverage but does not alter Bitcoin Core's own test or release binaries.
This change makes three Bitcoin command-line tools (bitcoin-tx, bitcoin-util, and bitcoin-wallet) automatically pick the fastest SHA-256 hashing implementation available on the computer, such as hardware-accelerated versions on modern CPUs…
This is a one-line fix in Bitcoin Core's network code. It changes how the size of a list of block headers is converted to a signed integer inside a loop. Previously, if the list was empty, the conversion could trigger undefined-behavior wa…
UndefinedBehaviorSanitizer integer sanitizer warning addressedImplicit signed/unsigned conversion in loop counterUnsigned integer wraparound on empty vector size
This change fixes a Bitcoin Core wallet bug where the `importprunedfunds` RPC command could only re-import transactions that sent money to the wallet, not transactions that spent money from it. After this fix, both incoming and outgoing tr…
Logic bug in wallet transaction import scopeIncorrect balance possible after removing and re-importing spending transactionFix routes import through existing involvement check (IsMine + IsFromMe)
This commit adds a new Bitcoin Core wallet startup option called -maxfeerate. It lets users set a maximum fee rate (fee per unit of transaction size) that the wallet will allow when creating or broadcasting transactions. Previously, the wa…
New wallet startup option -maxfeerate to cap transaction fee rateNew transaction error type MAX_FEE_RATE_EXCEEDEDBroadcastTransaction now checks both max absolute fee and max fee rate
This Bitcoin Core update fixes a wallet-signing quirk. When a user chose the SIGHASH_SINGLE signature mode, an input that had no matching output index would sign essentially nothing meaningful. That signature could then stay valid even if …
Funds-redirection footgun from SIGHASH_SINGLE signatures with no committed outputInconsistent guard between SignTransaction and SignPSBTInput pathsFix centralizes the guard in the low-level signature creator to cover future signing paths
This change updates Bitcoin Core's I2P (Invisible Internet Project) privacy network settings to use newer, stronger encryption for the published 'leaseset' that describes how other peers can contact a node. The old setting included ElGamal…
Cryptographic algorithm update (ElGamal to MLKEM-768)Use of I2P 'legacy' encryption type removedConfiguration-only change in network privacy layer
This change fixes a labeling bug in Bitcoin Core's first-run disk-space warning. The estimate was stored in GiB (binary gigabytes, 1024-based) but displayed as GB (decimal gigabytes, 1000-based), and for pruned nodes it showed the full-cha…
This is a wallet bug, not a theft or remote-code bug. When a Bitcoin Core user turns on the optional 'avoidpartialspends' or 'avoid_reuse' setting, an output group rejected during coin selection could be counted twice as 'discarded.' That …
Logic error causing double-counting of discarded UTXO groupsCan trigger false 'insufficient funds' failure in coin selectionAffects avoidpartialspends / avoid_reuse wallets only
This is a documentation-only fix in a tutorial file. It changes two shell examples from using '>>' (append to file) to '>' (overwrite file). If a user followed the old instructions and ran the same command twice, the file would contain two…
No security signal: change is limited to documentationNo code changes to Bitcoin Core binaries, RPC, wallet, or consensus logicNo cryptographic, network, or privilege-boundary implications
This is a large internal code reorganization (refactor) in Bitcoin Core. It creates a new BlockTemplateManager class that takes over block-template creation, block submission, and tip-waiting helpers that were previously spread across seve…
Large refactor touching mining, RPC, interfaces, and test shutdown pathsNew object lifetime dependency: BlockTemplateManager holds references to mempool, chainman, and notifications; explicit reset ordering added in Shutdown/InitAndLoadChainstate/test setupsRemoval of early-init node.mining interface; BlockTemplateManager is now created after chainstate load, with a comment that it must exist before setChainstateLoaded(true) unblocks IPC waiters
This commit adds the first implementation of BIP352 (Silent Payments) to Bitcoin Core. Silent Payments are a new type of privacy-preserving Bitcoin address that lets someone receive payments without publicly revealing a fixed address. The …
New cryptographic feature implementation (BIP352 Silent Payments)Extensive use of secp256k1 silentpayments moduleInput public key extraction from P2PKH, P2WPKH, P2SH-P2WPKH, and P2TR inputs
This update fixes a wallet database loading bug where a damaged or tampered Bitcoin wallet file could cause the program to read past the end of a stored extended public key (xpub). The patch makes the loader check the stored xpub length be…
Out-of-bounds read in wallet descriptor cache deserializationASan container-overflow triggered by malformed on-disk recordMissing length validation between record size prefix and fixed-size decoder
This commit adds a new wallet RPC called listrawtransactions to Bitcoin Core. It is a feature addition that lets users list every transaction their wallet knows about, including internal transfers and consolidations that the existing listt…
No security-relevant bug fix or vulnerability patch is present in the diff.New RPC exposes additional wallet transaction metadata, but only to callers already authorized for wallet RPCs.Code is a refactor of existing gettransaction logic into shared helpers; no new cryptographic, network, or consensus code.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 11/100
This commit updates the version of the GNU C library (glibc) used in Bitcoin Core's reproducible build system (Guix) from one specific 2.31 snapshot to a newer 2.31 snapshot. It changes a commit hash and its corresponding cryptographic hash in a build manifest. There is no direct evidence in the commit that this fixes a specific security vulnerability; it appears to be a routine dependency refresh within the same glibc release branch.
Lower-priorityguix: switch to upstream osslsigncode packageby fanquake · 2bf97e81 · Mar 17, 2026 · 1 fileMessage 45 · ThinInformational 14Details
Commit message · fanquake
guix: switch to upstream osslsigncode package
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 14/100
This change removes a custom Guix package definition for osslsigncode (a Windows code-signing tool) and instead uses the version already maintained in upstream Guix. It is a build-system maintenance cleanup, not a security fix. The old custom package had a workaround for tests that would fail after the year 2025, but that workaround is being removed because the upstream Guix package presumably handles it. There is no direct evidence in the commit of a vulnerability or attack.
Lower-priorityci: use LIEF 0.17.5 in lint jobby fanquake · feea2a85 · Mar 17, 2026 · 2 filesMessage 57 · ThinInformational 15Details
Commit message · fanquake
ci: use LIEF 0.17.5 in lint job
57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100
This commit updates a Python library used only in Bitcoin Core's continuous integration lint job from version 0.16.6 to 0.17.5, and removes a now-unneeded build compatibility patch. It does not change any code that runs in the Bitcoin Core software itself or affect how the network operates.
Lower-priorityguix: switch to upstream python-lief packageby fanquake · a7524f57 · Mar 17, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · fanquake
guix: switch to upstream python-lief package
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100
This commit removes a custom-built copy of the python-lief package from Bitcoin Core's Guix build manifest and switches to using the upstream Guix package instead. It is a build-system maintenance change that reduces custom code. There is no indication of a security vulnerability being fixed.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 17/100
This commit changes how Bitcoin Core's Guix build system obtains a Python cryptography helper library called oscrypto. Previously, Bitcoin Core maintained its own custom package definition and a patch that forced oscrypto to use a specific OpenSSL library path. Now it uses the standard upstream package from the Guix distribution. This is primarily a build-maintenance simplification. It is not a direct fix for a known vulnerability, but it removes a local patch and custom package, which could slightly change what code is compiled into release builds.
AI review queuedguix: drop CMake workaroundby fanquake · dc0ddab3 · Mar 17, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · fanquake
guix: drop CMake workaround
We are now using 3.31.x.
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit removes a temporary build-script workaround that was only needed for older versions of CMake on Apple macOS builds. It is a routine cleanup with no security relevance.
AI review queuedguix: update to c5eee3336cc1d10a3cc1c97fde2809c3451624d3by fanquake · 31eb46f0 · Mar 17, 2026 · 6 filesMessage 63 · AdequateInformational 16Details
Commit message · fanquake
guix: update to c5eee3336cc1d10a3cc1c97fde2809c3451624d3
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100
This commit updates the Guix build environment used to create reproducible Bitcoin Core release binaries. It bumps many dependency versions (compiler toolchain, glibc, Python, etc.) and makes the build container's root filesystem writable. There is no direct evidence this fixes a specific security vulnerability in Bitcoin Core itself; it is routine build-system maintenance.
Lower-priorityguix: add --no-same-owner to TAR_OPTIONSby fanquake · 0f323e10 · Mar 17, 2026 · 1 fileMessage 45 · ThinInformational 19Details
Commit message · fanquake
guix: add --no-same-owner to TAR_OPTIONS
So it's used to extract tarballs.
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 19/100
This commit changes the Bitcoin Core Guix build script to add '--no-same-owner' to the TAR_OPTIONS environment variable. This option tells tar not to restore the original file ownership when extracting archives, instead using the current user. The change is intended to make tarball extraction more deterministic and avoid relying on the user running the build being able to assume arbitrary file ownership. It is a hardening/determinism improvement rather than a fix for an active, exploitable vulnerability.
Lower-priorityindex: add explicit early exit in NextSyncBlock() when the input is the chain tipby Hao Xu · db3c25cf · Mar 17, 2026 · 1 fileMessage 81 · StrongInformational 16Details
Commit message · Hao Xu
index: add explicit early exit in NextSyncBlock() when the input is the chain tip
When pindex_prev is the chain tip, return earlier and explicitly rather than mixing it with the reorg case. For more detail, please see PR: https://github.com/bitcoin/bitcoin/pull/32875
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 16/100
This is a small code cleanup in Bitcoin Core's index synchronization logic. It adds an explicit early return when the code has already reached the latest block in the chain, separating that case from the more complex 'block is no longer in the main chain' reorganization handling. The change is primarily about making the code's intent clearer and avoiding unnecessary work, not about fixing a known security bug.
Lower-priorityci: Use arch-appropriate binaries in lint installby will · 55187536 · Mar 17, 2026 · 1 fileMessage 80 · StrongInformational 16Details
Commit message · will
ci: Use arch-appropriate binaries in lint install
Replace the hardcoded x86_64 binary name with $(uname --machine) so the correct binary is downloaded when building the lint container, where at all possible.
80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Informational 16/100
This is a small continuous-integration (CI) maintenance change. It makes the lint setup script download the correct tool versions for the computer architecture it is running on (e.g., ARM instead of only x86_64), and switches curl from silent mode to fail-on-error mode. It is not a security fix for Bitcoin Core itself and does not change any wallet, networking, or consensus code.
Lower-prioritythreading: never require logging from sync.hby Cory Fields · 79467e3e · Mar 16, 2026 · 2 filesMessage 68 · AdequateInformational 15Details
Commit message · Cory Fields
threading: never require logging from sync.h
sync.h is low-level and should not require any other subsystems.
Move the lone remaining logging call to the .cpp. Any cost incurred by an additional function call should be trivial compared to the logging itself.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100
This is a straightforward internal code cleanup: it moves a debug-only logging call out of a low-level threading header file and into a source file. There is no user-facing change, no bug fix, and no security relevance visible in the commit.
Lower-prioritylint: add missing ipc/test to grep_boost_fixture_test_suiteby fanquake · 8864917d · Mar 16, 2026 · 1 fileMessage 60 · AdequateInformational 15Details
Commit message · fanquake
lint: add missing ipc/test to grep_boost_fixture_test_suite
60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100
This commit is a minor linting fix. It adds a new test directory (src/ipc/test) to an internal script that checks whether Bitcoin's C++ test files use a specific Boost test macro correctly. It does not change any production code, wallet logic, networking, or consensus rules. There is no security issue here.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100
This commit is purely cosmetic: it replaces tab characters with spaces in a lint script and removes that script from a list of files exempted from whitespace-format checks. There is no change to Bitcoin's network, wallet, consensus, or cryptographic code, and no security relevance.
Lower-prioritylint: more reuse of SHARED_EXCLUDED_SUBTREESby fanquake · f55c891a · Mar 16, 2026 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · fanquake
lint: more reuse of SHARED_EXCLUDED_SUBTREES
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100
This commit is a minor cleanup of internal linting scripts. It moves one directory path into a shared list so that multiple code-style checkers can reuse it. There is no change to the Bitcoin software that users run, no change to security logic, and no security relevance.
Lower-prioritycontrib: fix whitespace issues in scriptsby fanquake · ee8c22eb · Mar 16, 2026 · 5 filesMessage 45 · ThinInformational 15Details
Commit message · fanquake
contrib: fix whitespace issues in scripts
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100
This commit is a code cleanup that fixes inconsistent whitespace (tabs vs. spaces, trailing spaces) in several helper scripts and removes those files from a linting exclusion list. It does not change any program logic, behavior, or security settings.
Lower-prioritycmake, translation: Specify English as target language explicitlyby Hennadii Stepanov · a434d660 · Mar 16, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · Hennadii Stepanov
cmake, translation: Specify English as target language explicitly
Otherwise, "en_US" might be used.
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
AI analysis · Informational 15/100
This is a build-system tweak for Qt translation files. It explicitly tells the translation tool to use English as the target language instead of potentially defaulting to 'en_US'. There is no security issue here—it only affects how translation metadata is generated during compilation.
cmake, translation: Sort messages within contexts alphabetically
This is done in addition to the default sorting of the contexts themselves, further minimizing unnecessary diffs in version control.
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100
This commit changes how Bitcoin Core's user-interface text is sorted in translation files. It adds a build option to sort messages alphabetically within each context, which only affects the order of strings in the generated translation source file. There is no change to program behavior, logic, or security.
cmake, translation: Skip source locations in TS files
Source locations do not contribute to the string's Context on Transifex (used for hash calculation) and only trigger unnecessary diffs in version control.
While the `filename` attribute of the `<location>` element is rendered as "Occurrences" on Transifex, Qt's lupdate tool does not seem to set this attribute consistently.
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100
This commit changes how Bitcoin Core's translation files are generated. It removes source-code file references (line numbers and filenames) from the translation catalog to reduce unnecessary version-control noise. There is no security-relevant change to the running software, wallets, network, or consensus code.
Drop all code related to converting Qt TS files to XLIFF, enabling the build system to handle TS source file directly.
60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100
This commit is a routine build-system cleanup. It removes an intermediate file-format conversion step used for translating the Bitcoin Core user interface into other languages. The project will now use Qt's native .ts translation files directly instead of first converting them to the XLIFF (.xlf) format. There is no security-relevant change here.
This can be reviewed via the git options: --color-moved=dimmed-zebra --color-moved-ws=ignore-all-space
60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100
This commit is a pure code reorganization: it takes the existing logic that handles incoming network address messages and moves it into a new helper function called ProcessAddrs(). No behavior changes, security fixes, or new features are introduced.
Additionally, the slug was updated for the next release.
60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100
This commit is a routine translation workflow update. It changes the file format used for Bitcoin Core's Qt translations from .xlf to .ts and updates the corresponding version slug from 031x to 032x. There is no security relevance.
AI review queuedtest/wallet: ensure FastWalletRescanFilter is updated during scanningby Novo · 92287ae7 · Mar 16, 2026 · 1 fileMessage 95 · StrongInformational 12Details
Commit message · Novo
test/wallet: ensure FastWalletRescanFilter is updated during scanning
The fixed non-range descriptor address ensured that the FastWalletRescanFilter would match all Blocks even if the filter wasn't properly updated. This commit moves the non-range descriptor tx to a different block, so that the filters must be updated after each TopUp for the test to pass.
Co-authored-by: rkrux <rkrux.connect@gmail.com>
95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100
This is a test-only change in Bitcoin Core. It improves a wallet rescan test so that it actually verifies the FastWalletRescanFilter is updated correctly during scanning. The previous test setup accidentally allowed the filter to be stale and still pass because a fixed non-range descriptor address matched every block. There is no change to production wallet code, so this does not directly fix a live security bug.
lint: remove excluded .cpp/.h files from whitespace check
These have been fixed since #32482 and 5d25a82b9a5e54f74cc066599541bc1d3da70988.
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100
This commit removes three source-code files from a linting exclusion list. The lint check in question only enforces whitespace formatting rules. There is no change to Bitcoin Core's runtime behavior, consensus logic, networking, wallet, or any user-facing functionality. It is a pure code-quality tooling cleanup.
Lower-priorityfuzz: set fSuccessfullyConnected in connman harnessby frankomosh · 685a44c6 · Mar 16, 2026 · 1 fileMessage 83 · StrongInformational 15Details
Commit message · frankomosh
fuzz: set fSuccessfullyConnected in connman harness
Without this, NodeFullyConnected() filters out every fuzz-constructed node, making ForEachNode's callback unreachable (0/1.13M branch hits from my end).
83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100
This commit fixes a Bitcoin Core fuzz test harness so that simulated peer nodes are marked as successfully connected. Without this flag, the test's code coverage was poor because the harness filtered out all fake nodes before running important connection-management logic. It is a test-only improvement with no effect on live Bitcoin node behavior or user funds.