BC
← All projectsBitcoin Core

Bitcoin Core

The Bitcoin network's reference node and wallet implementation.

BitcoinSupply chainNormal
Repository coverage

2902 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

254security candidates607second-pass queue2881AI analyses
192commits · 30 days
486commits · 60 days
1502commits · 180 days
2875commits · 365 days
Backfill bands
Aug 5 → Feb 61351 seen45 candidatesComplete
Feb 6 → Jun 61033 seen63 candidatesComplete
Jun 6 → Jul 6281 seen11 candidatesComplete
Jul 6 → Aug 5207 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

70/100 average clarity
939Strong · 80–100
1188Adequate · 60–79
687Thin · 40–59
88Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Antoine Poinsot22422170
Ava Chow15750157064
MarcoFalke41021406074
Lőrinc17721177081
fanquake22719226057
Hennadii Stepanov20914208063
rkrux57957074
Sjors Provoost89889074
Sebastian Falbesoner33733073
David Gumberg55655072
Pieter Wuille95595066
Hodlinator66566076
Analysis record

Published AI watches

Last scanned 20 minutes ago

Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35928: doc: mention -DWITH_ZMQ=ON in macOS build guide

This is a one-line documentation update to the macOS build guide. It adds a note telling users to pass a specific CMake option if they want ZeroMQ notification support. There is no code change and no security impact.

8397e09eby merge-script+1−11 file
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35482: fuzz: exercise the transaction-handling path in process_message(s)

This commit only changes Bitcoin Core's internal fuzz testing code. It makes the fuzz tests exercise more of the transaction-handling code path by toggling Initial Block Download mode and resetting the mempool between test runs. There is n…

No production code modifiedNo consensus, validation, net_processing, or wallet logic changedOnly fuzz test harnesses and test utilities affected
f11dc617by merge-script+105−798 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35914: test, fuzz: Remove unused variables

This commit removes unused variables from Bitcoin Core's test and fuzzing code. It is a cleanup/refactoring change with no effect on the live network software or user funds. It does not fix or introduce any security vulnerability.

d36bf709by merge-script+1−138 files
No security note in commit
Informational 15 AI analysisMessage 93 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35896: refactor: Default uint256::operator==, add operator<=>

This commit is a routine code cleanup in Bitcoin Core. It switches the uint256 equality and comparison operators to use standard C++20 defaults, removes an old custom Compare() helper, and marks an internal assertion-failure function as ne…

ed2c59abby merge-script+99−245 files
No security note in commit
Moderate 62 AI analysisMessage 96 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35872: rpc: avoid descriptor range counter overflow

This update fixes a counting bug in several Bitcoin Core RPC commands that scan descriptors. When a user requested a descriptor range ending at the maximum allowed value (2,147,483,647), the internal counter used a smaller integer type and…

Signed integer overflow in descriptor expansion loopCrash/undefined behavior on maximum-range descriptor scansAuthenticated RPC surface affected (scantxoutset, scanblocks, getdescriptoractivity, utxoupdatepsbt, descriptorprocesspsbt)
b388674aby Ava Chow+3−12 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35842: rpc: Properly make RPCResult::Type::ANY non-test-only

This is a small cleanup and documentation fix for Bitcoin Core's RPC help system. It removes a comment that incorrectly said a certain output type was 'for testing only' and makes the help text properly display those outputs. There is no d…

No memory safety, cryptography, consensus, or authorization changes observedChange is confined to RPC help/schema metadata generationComment-only/type-label change from 'for testing only' to general use
c36ffd87by merge-script+42−364 files
No security note in commit
Informational 15 AI analysisMessage 93 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35895: refactor: Enable clang-tidy rule to reject anon namespace in header

This is a code cleanup change that turns on a static-analysis rule to prevent a specific C++ coding pattern (anonymous namespaces in header files) and updates two headers to comply. It does not change how Bitcoin Core behaves at runtime an…

No security-relevant code changeNo memory safety, cryptography, consensus, or network changesTooling-only refactor (clang-tidy configuration)
c4fbd3c7by merge-script+9−123 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35630: test: Add importdescriptors rpc error test coverage

This commit only adds new test cases to Bitcoin Core's functional test suite. It does not change any production wallet, node, or RPC code. The tests verify that the importdescriptors RPC reports errors in the right order, rejects bad times…

465196d0by merge-script+77−11 file
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35180: coins: group private cache helpers

This change is purely a code cleanup: it moves two internal helper functions of a Bitcoin Core cache class into the private section of the class and removes a duplicate 'private:' label. There is no change to what the code does, no bug fix…

c940fd75by merge-script+13−141 file
No security note in commit
Low 29 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35582: rpc: reject null for optional parameters

This Bitcoin Core change tightens how three RPC commands (scantxoutset, scanblocks, deriveaddresses) handle the value null when it is passed for optional parameters. Previously, explicitly passing null could be treated differently from sim…

RPC parameter validation changeNull value handling changeAddition of explicit error checks for missing required contextual parameters
3db96eb5by merge-script+18−75 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

refactor: Enable misc-definitions-in-headers

This commit is a code cleanup: it turns on a clang-tidy style check called 'misc-definitions-in-headers' and suppresses that check around a large inline implementation block in a benchmark header. There is no change to Bitcoin's runtime be…

fa93132dby MarcoFalke+3−02 files
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

refactor: Enable clang-tidy rule to reject anon namespace in header

This commit only changes a linting configuration file for the project's code style checker. It enables a rule that prevents anonymous namespaces from being used in header files, which is a code-quality and build-hygiene practice. There is …

No security-relevant signals in the diff or commit message.Change is purely a static-analysis/linting configuration update.
fa5ca877by MarcoFalke+2−11 file
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

refactor: Use C++20 std::identity over IntIdentity

This commit is a straightforward code cleanup: it replaces a small custom helper named IntIdentity with the standard C++20 std::identity from the <functional> header. The behavior of the ConvertBits function is unchanged; only the implemen…

fafe5042by MarcoFalke+4−111 file
No security note in commit
Informational 15 AI analysisMessage 87 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

test: test the result order of a multiple import request is correct

This commit only adds a new automated test to Bitcoin Core. It checks that when a user asks the wallet to import multiple descriptors at once, the list of results comes back in the same order as the original request, including any error me…

3ac8b806by Pol Espinasa+40−01 file
No security note in commit
Informational 15 AI analysisMessage 87 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

test: test invalid or missing timestamp throws importdescriptors

This commit only adds new automated tests for the Bitcoin Core wallet's importdescriptors RPC. It checks that the command correctly rejects requests with a missing or invalid timestamp. No production wallet code is changed, so this cannot …

No changes to consensus, networking, wallet logic, or cryptographyOnly functional test code is modifiedAdded assertions are for expected error handling paths
e4732bf0by Pol Espinasa+28−11 file
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

refactor: Remove unused #include in common/system

This is a minor code cleanup that removes one unused header file include and swaps another for a more specific one. It does not change any program behavior or fix any security issue.

fa7304f3by MarcoFalke+1−22 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

iwyu: Fix warnings in `src/consensus` and treat them as errors

This commit is a routine code cleanup: it adjusts which C++ header files are included in several consensus-related source files and turns on a stricter compiler hygiene check (Include What You Use, or IWYU) for the src/consensus directory.…

13b53f8bby Hennadii Stepanov+42−79 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

fuzz: don't connman.ReceiveMsgFrom oversized msg

This is a small fix to a Bitcoin Core fuzz test (an automated internal testing harness), not to the live network code. The fuzzer was sometimes creating fake P2P messages larger than the real protocol allows and passing them into a test he…

Test-only fuzz harness hardeningOversized message guard added before ReceiveMsgFrom() in fuzz targetNo change to production P2P message acceptance logic
bb19f1daby Greg Sanders+5−01 file
No security note in commit
Informational 15 AI analysisMessage 97 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

ci: Temporarily remove riscv32 config from GHA matrix

This commit simply removes one failing test configuration (RISC-V 32-bit bare metal) from the project's GitHub Actions CI matrix because it was failing. It is a routine CI maintenance change with no security implications.

fa06ea42by MarcoFalke+0−61 file
No security note in commit
Low 47 AI analysisMessage 90 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

ci: verify cross-build SDK archives

This change adds checksum verification to the build system's downloads of Apple, FreeBSD, NetBSD, and OpenBSD software development kits (SDKs). Before this patch, those SDK archives were downloaded at build time and extracted without confi…

Adds cryptographic digest verification for downloaded SDK archivesRemoves unchecked extraction of remote SDK archives in CIHardens CI supply chain for macOS/BSD cross-builds
873550beby Lőrinc+25−126 files
Vendor flagged security relevance
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityRemove unused argument to RemoveStagedby Suhas Daftuar · 01d85200 · Nov 30, 2025 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · Suhas Daftuar

Remove unused argument to RemoveStaged

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This is a routine code cleanup: a function called RemoveStaged had an extra parameter (updateDescendants) that was no longer used, so it was removed from the function definition and every place that called it. There is no security-relevant change here.

Lower-prioritycmake: Make `BUILD_KERNEL_TEST` depend on `BUILD_KERNEL_LIB`by Hennadii Stepanov · fe1815d4 · Nov 30, 2025 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Hennadii Stepanov

cmake: Make `BUILD_KERNEL_TEST` depend on `BUILD_KERNEL_LIB`

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This is a small CMake build-system change. It makes the optional test suite for an experimental library (BUILD_KERNEL_TEST) automatically disabled when the library itself (BUILD_KERNEL_LIB) is not being built. Previously, the test option could be left on independently, which could cause a build configuration error. There is no runtime security issue here.

Lower-prioritycmake: Set `WITH_ZMQ` to `ON` in Windows presetsby Hennadii Stepanov · 49c67285 · Nov 30, 2025 · 3 filesMessage 68 · AdequateInformational 15Details
Commit message · Hennadii Stepanov

cmake: Set `WITH_ZMQ` to `ON` in Windows presets

The "zeromq" feature is already enabled by default in `vcpkg.json`, and
there appears to be no reason to omit this configuration option when
building on Windows.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit changes Bitcoin Core's Windows build configuration so that the optional ZeroMQ notification feature is enabled by default in the Windows CMake presets. It also updates CI and documentation to match. There is no security-relevant code change here; it is purely a build-system consistency fix to align Windows builds with the existing default in the dependency manifest.

Lower-prioritydoc: Add `x86_64-w64-mingw32ucrt` triplet to `depends/README.md`by Hennadii Stepanov · ec8eb013 · Nov 30, 2025 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Hennadii Stepanov

doc: Add `x86_64-w64-mingw32ucrt` triplet to `depends/README.md`

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This is a documentation-only change that adds a new Windows cross-compilation target to the build instructions. It does not modify any executable code, build scripts, or configuration logic. There is no security relevance.

Lower-priorityci: Remove redundant `DEP_OPTS` from “Windows-cross UCRT” jobby Hennadii Stepanov · 48496caa · Nov 30, 2025 · 1 fileMessage 77 · AdequateInformational 15Details
Commit message · Hennadii Stepanov

ci: Remove redundant `DEP_OPTS` from “Windows-cross UCRT” job

GCC-based tools already follow the standard naming convention for the
`x86_64-w64-mingw32ucrt` target.

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
AI analysis · Informational 15/100

This is a minor cleanup to Bitcoin Core's continuous integration (CI) configuration. It removes one redundant line that explicitly set compiler names for a Windows cross-compilation job, because the build system already figures out those names automatically. There is no security relevance.

Lower-priorityci: Make the max number of commits tested explicitby Hodlinator · b5a7a685 · Nov 27, 2025 · 1 fileMessage 92 · StrongInformational 15Details
Commit message · Hodlinator

ci: Make the max number of commits tested explicit

Gives less of a false sense of security.

92/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only renames a GitHub Actions CI job and adds a comment to make clear that the workflow tests a maximum of 6 ancestor commits. There is no code, build, or runtime change, and no security issue is introduced or fixed.

Lower-priorityscript: add SCRIPT_ERR_TAPSCRIPT_EMPTY_PUBKEYby billymcbip · 9d5021a0 · Nov 27, 2025 · 6 filesMessage 58 · ThinInformational 19Details
Commit message · billymcbip

script: add SCRIPT_ERR_TAPSCRIPT_EMPTY_PUBKEY

Empty public keys in tapscript are rejected by consensus rules, independent of SCRIPT_VERIFY_STRICTENC. Add SCRIPT_ERR_TAPSCRIPT_EMPTY_PUBKEY to distinguish this from STRICTENC policy failures currently reported as SCRIPT_ERR_PUBKEYTYPE.

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
AI analysis · Informational 19/100

This commit only changes the error message/name returned when a tapscript transaction provides an empty public key. The actual consensus rule—rejecting empty public keys in tapscript—already existed. The change makes debugging and testing clearer by giving this failure its own distinct error code instead of reusing a more general one. It does not alter what transactions are accepted or rejected by the network.

Lower-priorityguix: reduce allowed exported symbolsby fanquake · 7b90b4f5 · Nov 27, 2025 · 1 fileMessage 45 · ThinInformational 16Details
Commit message · fanquake

guix: reduce allowed exported symbols

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 16/100

This commit tightens a build-time check used in Bitcoin Core's reproducible Guix build process. It removes several common system symbols (like 'environ' and '_environ') from a list of exports that the build script is allowed to ignore. The change itself does not fix a vulnerability in running Bitcoin Core software; it is a hardening of the release-build verification tooling to catch accidental symbol exports earlier. There is no claim in the commit that this resolves a security bug.

Lower-priorityguix: add bitcoin-qt runtime libs doc in symbol-checkby fanquake · 41e657aa · Nov 27, 2025 · 1 fileMessage 81 · StrongInformational 15Details
Commit message · fanquake

guix: add bitcoin-qt runtime libs doc in symbol-check

libfreetype and libfontconfig are our two remaining runtime libs for
bitcoin-qt. According to #29977 Ubuntu 22.04 should be considered the
baseline for what is supported. Document that.

Closes #29977.

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100

This commit only adds documentation comments to a build script. It lists which versions of two graphics-related system libraries (libfontconfig and libfreetype) are expected on Ubuntu 22.04 for the Bitcoin Qt wallet application. No code behavior was changed, so there is no security issue in this patch itself.

AI review queueddepends: freetype 2.11.1by fanquake · ef4ce19a · Nov 27, 2025 · 2 filesMessage 38 · OpaqueLow 26Details
Commit message · fanquake

depends: freetype 2.11.1

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 26/100

This commit updates the FreeType font-rendering library used in Bitcoin Core's build dependencies from version 2.11.0 to 2.11.1. It changes the download URL, archive format, and verification hash, and adjusts a small build patch. FreeType is a widely used library for drawing text, and newer point releases often include bug fixes. The commit itself does not say whether this fixes a security issue, and no security references were provided.

AI review queuedlog: Use LogWarning for non-critical logsby MarcoFalke · fa45a150 · Nov 27, 2025 · 23 filesMessage 68 · AdequateInformational 15Details
Commit message · MarcoFalke

log: Use LogWarning for non-critical logs

As per doc/developer-notes#logging, LogWarning should be used for severe
problems that do not warrant shutting down the node

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a straightforward logging cleanup. It changes many messages from the generic LogPrintf to a new LogWarning helper, which is designed for severe-but-non-fatal problems. The wording of the messages is mostly unchanged, and no program logic, permissions, or security behavior is modified. It is not a security fix.

AI review queuedlog: Use LogError for fatal errorsby MarcoFalke · fa0018d0 · Nov 27, 2025 · 10 filesMessage 45 · ThinLow 27Details
Commit message · MarcoFalke

log: Use LogError for fatal errors

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 27/100

This commit only changes which logging function is used for error and fatal-condition messages across Bitcoin Core. It replaces generic LogPrintf calls with LogError (and one LogInfo) so that serious problems are more clearly marked in logs. There is no change to program logic, no bug fix, and no security vulnerability being patched.

Lower-prioritycontrib: Avoid outputting binary data to TTYby Hodlinator · e7e51952 · Nov 27, 2025 · 1 fileMessage 45 · ThinInformational 18Details
Commit message · Hodlinator

contrib: Avoid outputting binary data to TTY

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 18/100

A small change to a helper Python script used for building network maps. The script now refuses to write raw binary output directly to a terminal window, because doing so can garble the screen and, in rare cases, cause a terminal to misinterpret control characters. This is a hardening improvement rather than a fix for an active attack.

Lower-prioritytest: move SEQUENCE_LOCKTIME flags to scriptby Sjors Provoost · 592157b7 · Nov 27, 2025 · 2 filesMessage 67 · AdequateInformational 15Details
Commit message · Sjors Provoost

test: move SEQUENCE_LOCKTIME flags to script

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a minor test-code cleanup. It moves four named constants related to BIP68 sequence locktime rules from one test file into the shared test framework library. No production code, consensus rules, or security behavior is changed.

Lower-prioritydoc: Fix typo in init logby MarcoFalke · 22229de7 · Nov 27, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · MarcoFalke

doc: Fix typo in init log

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit fixes a single-word typo in a log message. The phrase 'on non-prune mode' was corrected to 'in non-prune mode'. It has no effect on program behavior, security, or user data.

AI review queuedwallet: Have GetBalance report used amount directly without two callsby Anthony Towns · 81e763f1 · Nov 27, 2025 · 5 filesMessage 50 · ThinInformational 19Details
Commit message · Anthony Towns

wallet: Have GetBalance report used amount directly without two calls

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This is a small internal cleanup in how Bitcoin Core wallets report balances for reused addresses. It does not fix a vulnerability or change user-facing totals; it just computes the 'used' balance in one pass instead of calling the balance function twice and subtracting. There is no security issue visible in the change.

Lower-prioritynet: fix use-after-free with v2->v1 reconnection logicby Eugene Siegel · 167df7a9 · Nov 26, 2025 · 2 filesMessage 73 · AdequateLow 49Details
Commit message · Eugene Siegel

net: fix use-after-free with v2->v1 reconnection logic

CConnman::Stop() resets semOutbound, yet m_reconnections is not
cleared in Stop. Each ReconnectionInfo contains a grant member
that points to the memory that semOutbound pointed to and ~CConnman
will attempt to access the grant field (memory that was already
freed) when destroying m_reconnections. Fix this by calling
m_reconnections.clear() in CConnman::Stop() and add appropriate
annotations.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Low 49/100

This commit fixes a memory-handling bug that occurs when Bitcoin Core shuts down its network connections. A list of pending reconnections held references to a memory resource (semaphore) that was freed during shutdown. When the program later destroyed that list, it could read already-freed memory, which can cause crashes or unpredictable behavior. The fix clears the reconnection list before freeing the underlying resource and adds code annotations to prevent the wrong lock from being held during shutdown.

Lower-prioritytest: check for output to stdout in `TestShell` testby Sebastian Falbesoner · 52230a7f · Nov 26, 2025 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · Sebastian Falbesoner

test: check for output to stdout in `TestShell` test

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only changes a test file. It improves an existing test by checking that a warning message ('TestShell is already running!') is actually printed to the screen when a second TestShell is started. There is no change to Bitcoin Core's production code, no security fix, and no vulnerability.

Lower-prioritycontrib: Count entry differences in asmap-tool diff summaryby Fabian Jahr · fd4ce551 · Nov 26, 2025 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · Fabian Jahr

contrib: Count entry differences in asmap-tool diff summary

Also uses num_addresses from ipaddress instead of calculating it
ourselves.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This is a small cleanup change to a helper script used for comparing internet routing maps (asmap files). It only changes how the tool reports summary statistics: it now counts the number of changed entries separately from the number of affected IP addresses, and uses a built-in library function instead of a manual calculation. There is no security relevance.

Lower-prioritypolicy: Allow any transaction version with < minrelayby Greg Sanders · 1488315d · Nov 26, 2025 · 6 filesMessage 73 · AdequateLow 49Details
Commit message · Greg Sanders

policy: Allow any transaction version with < minrelay

Prior to cluster mempool, a policy was in place that
disallowed non-TRUC transactions from being
TX_RECONSIDERABLE in a package setting if it was below
minrelay. This was meant to simplify reasoning about mempool
trimming requirements with non-trivial transaction
topologies in the mempool. This is no longer a concern
post-cluster mempool, so this is relaxed.

In effect, this makes 0-value parent transactions relayable
through the network without the TRUC restrictions and
thus the anti-pinning protections.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Low 49/100

This Bitcoin Core commit relaxes a mempool policy rule. Previously, only a special transaction type called TRUC could be below the minimum relay fee when submitted as part of a package. Now any transaction version can be below that fee if it is part of a package that overall pays enough fees. The change is described by the developers as safe because of the newer cluster mempool design, but it removes one anti-pinning protection and makes zero-fee parent transactions relayable under certain conditions.

Lower-priorityci: clear out space on centos jobby will · e07e5736 · Nov 26, 2025 · 2 filesMessage 98 · StrongInformational 15Details
Commit message · will

ci: clear out space on centos job

Clear out space on the centos job be deleteing unnecessary files.

Raised by #33293 which pointed to a solution like https://github.com/google/oss-fuzz/commit/b7f04d782277638a67bc44865de445977eed4708

Only runs when cache provider (runner) is `gha`, and on the CentOS job.

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
fuzzing or regression evidencedocumentation-only discount
AI analysis · Informational 15/100

This commit adds a GitHub Actions cleanup step that deletes large pre-installed software folders (like .NET, Android SDK, Node modules) on CentOS CI runners to free disk space. It only affects Bitcoin Core's own continuous integration environment and does not change any Bitcoin node code, wallet logic, or network behavior. There is no security issue in the change itself.

Lower-prioritycontrib: rename gen-sdk to gen-sdk.pyby fanquake · 3e01b5d0 · Nov 26, 2025 · 2 filesMessage 60 · AdequateInformational 15Details
Commit message · fanquake

contrib: rename gen-sdk to gen-sdk.py

This puts it in scope for the Python linters.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit simply renames a helper script from gen-sdk to gen-sdk.py and updates the documentation link. The file contents are identical. It is a routine tooling change with no security relevance.

Lower-prioritymacdeploy: disable compression in macOS gen-sdk scriptby fanquake · c1213a35 · Nov 26, 2025 · 4 filesMessage 81 · StrongInformational 15Details
Commit message · fanquake

macdeploy: disable compression in macOS gen-sdk script

Starting with Python 3.11, Pythons gzip might delegate to zlib.
Depending on the OS, i.e Ubuntu vs Fedora, the underlying zlib
implementation might differ, resulting in different output.

For now, or until a better solution exists, disable compression. This
results in the SDK increasing in size to ~157mb. Which is not
unreasonable, to regain determinism (and would be significantly worse
without the previous commit).

See: https://docs.python.org/3/library/gzip.html#gzip.compress

Co-authored-by: stickies-v <stickies-v@protonmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100

This commit changes the macOS SDK packaging script for Bitcoin Core so that it produces an uncompressed .tar archive instead of a .tar.gz archive. The reason is that different Linux distributions use different underlying compression libraries, which can produce slightly different compressed files even from identical input. That breaks reproducible builds (determinism), where everyone expects the exact same output. The uncompressed archive is larger (~157 MB) but byte-for-byte identical across machines. There is no security vulnerability being fixed here.

Lower-prioritycontrib: more selectively pick files for macOS SDKby fanquake · a33d0345 · Nov 26, 2025 · 2 filesMessage 73 · AdequateInformational 18Details
Commit message · fanquake

contrib: more selectively pick files for macOS SDK

Only include what we really need. Skip 100s of mb of manpages,
swiftmodules, modulemaps.
Note that System/Library is only needed for the Qt build.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 18/100

This change trims the macOS software development kit (SDK) archive used to build Bitcoin Core for Mac. Instead of bundling the entire SDK, the script now only includes specific directories needed for compilation. This reduces download size and shrinks the attack surface by leaving out unnecessary files such as Swift modules, module maps, and manpages. It is a hardening and maintainability improvement rather than a fix for a known vulnerability.

AI review queuedtest: Fix "typo" in written invalid contentby MarcoFalke · fad61185 · Nov 26, 2025 · 1 fileMessage 94 · StrongInformational 15Details
Commit message · MarcoFalke

test: Fix "typo" in written invalid content

The appended content is irrelevant, but fix the "typo" to avoid
spellchecker warnings.

94/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a one-word change in a test file. A developer fixed a misspelled string ('invald wallet' to 'invalid_wallet_content') used only to create intentionally corrupted wallet data for a test. It has no effect on the actual Bitcoin Core software that users run.