BT
← All projectsBTCPay Server

BTCPay Server

Free, open-source, self-hosted Bitcoin payment processor supporting on-chain and Lightning payments.

BitcoinLightning NetworkPayment infrastructureNormal
Repository coverage

667 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

86security candidates223second-pass queue309AI analyses
82commits · 30 days
124commits · 60 days
320commits · 180 days
640commits · 365 days
Backfill bands
Aug 8 → Feb 9247 seen22 candidatesComplete
Feb 9 → Jun 9197 seen39 candidatesComplete
Jun 9 → Jul 954 seen0 candidatesComplete
Jul 9 → Aug 865 seen16 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

53/100 average clarity
80Strong · 80–100
151Adequate · 60–79
280Thin · 40–59
156Opaque · 0–39
8security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Nicolas Dorier44249227346
Cerberus622290
ndeet111133
rockstardev33612049
Abhijay Jain26610087
Chukwuleta Tobechi25610068
thgO.O32512066
dstrukt625062
Tim522074
Atharva Borade711067
Pavlenex412065
psam21312068
Analysis record

Published AI watches

Last scanned 36 minutes ago

Moderate 67 AI analysisMessage 73 · Adequate
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Merge pull request #7599 from NicolasDorier/fix/invoice-list-store-permissions

This change fixes a permission problem in BTCPay Server's invoice list. Previously, the invoice list page accepted a 'storeid:' search filter or a StoreId parameter that could let a user see invoices from stores they were not supposed to a…

Authorization boundary enforced by scoping query to route-supplied store IDRemoval of user-controlled StoreId from view modelSearch filter 'storeid:' no longer expands the set of stores queried
5ef1b9f8by Nicolas Dorier+31−304 files
No security note in commit
Informational 15 AI analysisMessage 58 · Thin
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Containerize the server settings views into sections (#7501)

This commit is a user-interface redesign, not a security fix. It wraps existing server settings pages into consistent visual sections and adds short explanatory subtitles. No code handling payments, authentication, permissions, or data val…

97357e8cby dstrukt+255−11230 files
No security note in commit
Informational 15 AI analysisMessage 53 · Thin
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Rename global search keywords to aliases (#7586)

This commit simply renames the search feature's 'Keywords' field to 'Aliases' across the BTCPay Server codebase. It is a non-functional refactoring that does not change any security behavior, access controls, or data handling. Backward com…

3af94084by Nicolas Dorier+96−7720 files
No security note in commit
Moderate 58 AI analysisMessage 36 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

fix confirm (#7570)

This commit adds a missing safety check in the API key authorization flow. Previously, if a user clicked a 'confirm' action for an API key that no longer existed, the code would try to use a null (non-existent) key object, which could caus…

Null dereference / NullReferenceException preventedMissing validation of repository return valueUser-facing authorization flow hardening
bd7f91e2by monasco+9−01 file
No security note in commit
Informational 3 AI analysisMessage 0 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Bump libs

This commit simply updates four external software library (NuGet package) versions to newer patch releases. There are no code changes shown, and the commit message gives no indication that any security issue is being fixed. It looks like a…

48c57151by Nicolas Dorier+5−54 files
No security note in commit
Low 35 AI analysisMessage 36 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

fix notfound (#7572)

This commit changes how BTCPay Server handles a missing user when an administrator tries to resend a verification email. Previously, the code threw a generic internal error (ApplicationException), which could expose internal details or pro…

Replaces thrown ApplicationException with NotFound() for missing userReduces information leakage via exception message containing userIdImproves HTTP semantics (404 instead of 500-class error)
491cf201by monasco+1−31 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Add PushNuget.sh

This commit adds a simple build-and-publish helper script for the project's NuGet package. It packages the BTCPayServer.Client library, pushes it to the public NuGet registry using an API key from an environment variable, and creates a mat…

24f5054eby Nicolas Dorier+16−01 file
No security note in commit
Low 36 AI analysisMessage 58 · Thin
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Encode payjoin errors in wallet status messages (#7567)

This commit fixes a potential cross-site scripting (XSS) issue in BTCPay Server's wallet status messages. When a payjoin transaction fails, the server shows a warning message that includes an error string. Previously, that error string was…

HTML content constructed from an external error string without encodingAddition of HtmlEncoder.Default.Encode around user-influenced or third-party error textStatus message rendered as raw Html in the UI
a60f8bf2by Nicolas Dorier+2−11 file
No security note in commit
Low 46 AI analysisMessage 36 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

fix lnurl (#7563)

This commit fixes a bug in BTCPay Server's LNURL feature for pull payments. Previously, if someone requested a LNURL for a pull payment that didn't exist, the code would try to use a null (empty) pull payment object, which could cause the …

Null dereference / missing null check on database/service lookup resultPotential server-side exception (DoS/crash) on crafted LNURL requestInformation disclosure risk if exception details leak stack traces
227912f2by monasco+1−11 file
No security note in commit
Informational 15 AI analysisMessage 63 · Adequate
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Update POS callback authentication guidance (#7566)

This commit only updates user-facing help text in the Point of Sale plugin. It replaces outdated guidance about legacy API keys and Basic authentication with newer guidance about API tokens and the correct REST API endpoint. No code logic,…

045f70a2by Nicolas Dorier+2−22 files
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Fix test

This is a one-line change to a test file. It adjusts an assertion so that the test now expects a database-migrated API key to have a null CreatedAt value instead of a non-null value. There is no production code change and no security relev…

ecfb7990by Nicolas Dorier+1−11 file
No security note in commit
Moderate 56 AI analysisMessage 45 · Thin
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Merge branch 'refact-api-keys'

This commit refactors how BTCPay Server stores and handles API keys. Previously, the secret API key itself was used as the database primary key, meaning the full secret was stored in plaintext and appeared in URLs/revocation endpoints. Now…

API key secrets no longer used as database primary key or in revocation URLsDatabase now stores SHA256 hash of secret rather than plaintext secret for authentication lookupNew ephemeral Key column cleared after 5 minutes by scheduled cleanup
7ec0260bby Nicolas Dorier+368−39129 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 28 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Harden API key storage

This commit changes how BTCPay Server stores and handles API keys. Previously, the secret API key itself was used as the database primary key and was stored in plaintext. After this change, the database stores a one-way hash of the secret,…

Database now stores SHA-256 hash of API key secret instead of the secret itselfAPI key secret is cleared from database after creation via scheduled cleanup jobPublic management ID (akid_*) is separated from the secret
b1294924by Nicolas Dorier+368−39129 files
Vendor flagged security relevance
Low 32 AI analysisMessage 18 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

bump HtmlSanitizer

This commit updates the HtmlSanitizer library to a newer patch version and reorganizes some account email-change tests. The library bump could fix a security bug in how user-supplied HTML is cleaned, but the commit itself does not say it f…

Dependency version bump of an HTML-sanitization library (HtmlSanitizer)Test-only reorganization around account email change flowsNo explicit security advisory, CVE, or vulnerability description in commit message
f8946b83by Nicolas Dorier+17−332 files
No security note in commit
Moderate 58 AI analysisMessage 50 · Thin
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Require current password for account email changes

This commit adds a security check so that when a user tries to change their email address on their account profile, they must enter their current password. Before this change, an attacker who had already hijacked a logged-in session could …

Account-takeover mitigation: email change now requires password re-authenticationNew model property CurrentPassword with DataType.PasswordController now calls CheckPasswordAsync before applying email change
f681ec7eby Nicolas Dorier+74−137 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 28 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Make a signed commit

This commit changes a single word in a build script's status message, from 'if it is possible' to 'whether it is possible'. There is no functional, security, or behavioral change to the software.

e342c62aby Nicolas Dorier+1−11 file
No security note in commit
Low 35 AI analysisMessage 70 · Adequate
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

fix(plugin-manager): use update lookup for installed plugins (#7536)

This commit changes how BTCPay Server's plugin manager asks the plugin directory for update information. Previously, the server fetched the full catalog of plugins and then filtered locally. Now it sends a list of the plugins actually inst…

Reduces information disclosure to external plugin directory by sending only installed/pending plugin list instead of querying full catalogAdds input validation on plugin update response (null entries, missing identifier/version)Improves handling of disabled and pending plugins in update checks
c617a24fby thgO.O+248−685 files
No security note in commit
Informational 15 AI analysisMessage 38 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Fix flaky test

This commit adds one extra wait/check to an automated test that verifies email rules appear in a web page. It is purely a test-stability fix and does not change any production code, user-facing behavior, or security boundary.

34ce3589by Nicolas Dorier+1−01 file
No security note in commit
Informational 15 AI analysisMessage 38 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Fix github reports in CI

This commit changes a CI test script so that GitHub Actions can write step summary reports to the correct file path inside a Docker container. It is a build/test infrastructure fix with no apparent security relevance.

4208bf71by Nicolas Dorier+15−11 file
No security note in commit
Moderate 66 AI analysisMessage 85 · Strong
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Validate support URL scheme to prevent stored script injection (#7537)

This commit fixes a stored cross-site scripting (XSS) risk in BTCPay Server's store settings. Merchants can set a 'Support URL' that is shown to customers during checkout. Before this fix, an attacker with access to store settings could en…

Stored XSS via javascript: URI in SupportUrlMissing scheme validation on user-supplied URLGreenfield API and UI controller both patched
a6b81460by Chukwuleta Tobechi+19−33 files
Vendor flagged security relevance
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateInclude API key - permission analysis for improved security (#6771)by Chukwuleta Tobechi · b253df29 · Mar 10, 2026 · 11 filesMessage 96 · StrongInformational 21Details
Commit message · Chukwuleta Tobechi

Include API key - permission analysis for improved security (#6771)

* Include API key - permission analysis for improved security

resolve codderbyte

Remove designer class

fix review feedback

include text translate

avoid string parsion and use Permission directly

use permission against string

include translation and update selecte stores

Include tests for api key permission edit and usage

.Update api key analysis page

include test

delete key usage when deleting api key

* update layout and delete query

96/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
credential or privilege state
AI analysis · Informational 21/100

This commit adds a new feature that tracks which permissions each API key actually uses and shows the owner a dashboard of used, unused, and stale permissions. It is a security-hardening and visibility improvement, not a fix for an active vulnerability. The change also deletes usage records when an API key is removed.

Security candidateCleanup unused namespacesby Nicolas Dorier · 1633275d · Mar 8, 2026 · 372 filesMessage 35 · OpaqueInformational 15Details
Commit message · Nicolas Dorier

Cleanup unused namespaces

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet pathboot or update pathauthentication pathparser or protocol path
AI analysis · Informational 15/100

This commit removes unused C# 'using' statements (imported namespaces) and one unused Razor view import across 372 files. It is a code-cleanup change with no functional modifications. The only non-cleanup hunk is a tiny refactor in GreenfieldInvoiceController.UpdateInvoice that reorders an existing null check and variable assignment without changing behavior.

Security candidateRefactor: User User.GetId instead of using the UserManagerby Nicolas Dorier · be7f3f04 · Mar 8, 2026 · 44 filesMessage 62 · AdequateLow 34Details
Commit message · Nicolas Dorier

Refactor: User User.GetId instead of using the UserManager

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication path
AI analysis · Low 34/100

This is a large internal code cleanup that replaces calls to ASP.NET Core's UserManager for getting the current user's ID with a new direct helper that reads the value from the user's identity claims. Most changes are mechanical refactors across many controllers and views. There are a few small behavior changes worth watching: the new helper returns an empty string instead of "???" for missing users, some places now treat a missing user ID as a validation failure rather than passing it through, and a couple of user-not-found cases now return NotFound instead of throwing an exception. The commit does not describe itself as a security fix and no external advisory is provided.

Security candidateFix PermissionTagHelper to behave in the right scope when in nav barby Nicolas Dorier · d6bec86c · Mar 7, 2026 · 14 filesMessage 50 · ThinLow 49Details
Commit message · Nicolas Dorier

Fix PermissionTagHelper to behave in the right scope when in nav bar

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
credential or privilege stateauthentication path
AI analysis · Low 49/100

This commit fixes how BTCPay Server's navigation bar decides which store's permissions to use when showing or hiding menu items. Previously, the permission checks inside the navigation bar could accidentally use the store from the main page (for example, the server settings page) instead of the store selected in the navigation bar. This could cause menu items to be shown or hidden incorrectly. The change makes the navigation bar temporarily switch to the correct store context while it renders, and removes a caching shortcut that could reuse the wrong permission result. There is no direct evidence in the commit message or diff that this was exploited or reported as a security vulnerability.

Security candidateDo not add claims twice for cookie authby Nicolas Dorier · e34d8d7d · Mar 6, 2026 · 1 fileMessage 50 · ThinLow 26Details
Commit message · Nicolas Dorier

Do not add claims twice for cookie auth

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 26/100

This commit fixes a small bug where a special permission claim was being added to a user's identity every time it was transformed, instead of only once. Repeated claims are harmless in most cases, but could in theory cause the identity to grow unexpectedly or lead to subtle authorization behavior. The fix checks whether the permission claim already exists before adding it again.

Security candidatePluginize permissionsby Nicolas Dorier · 14837e6c · Mar 6, 2026 · 70 filesMessage 18 · OpaqueModerate 51Details
Commit message · Nicolas Dorier

Pluginize permissions

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
credential or privilege stateauthentication path
AI analysis · Moderate 51/100

This is a large refactoring commit that reworks how permissions are defined and enforced in BTCPay Server so that plugins can register their own permissions. It moves the permission hierarchy out of a hard-coded static class into a runtime service, changes how store context is tracked during requests, and updates authorization handlers. The change is architectural rather than a targeted security fix, but any mistake in the new permission logic could allow users to access stores or functions they should not.

Security candidateDecrease logs about challenged authentication schemesby Nicolas Dorier · 54056a40 · Mar 2, 2026 · 2 filesMessage 55 · ThinInformational 15Details
Commit message · Nicolas Dorier

Decrease logs about challenged authentication schemes

55/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
access control
AI analysis · Informational 15/100

This commit simply turns down the volume on log messages coming from BTCPayServer's security components. It changes the logging level from the default (likely Information/Debug) to Warning, so routine 'authentication scheme challenged' messages no longer fill the logs. There is no code behavior change, no bug fix, and no security vulnerability being patched.

Security candidateRefactor: Move Bitpay stuff in its own pluginby Nicolas Dorier · 39d99f0b · Feb 27, 2026 · 55 filesMessage 57 · ThinLow 35Details
Commit message · Nicolas Dorier

Refactor: Move Bitpay stuff in its own plugin

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 35/100

This commit is a large code refactor that moves BTCPay Server's Bitpay-compatible API from the core application into a separate plugin. It relocates controllers, authentication, models, views, and middleware into a new Plugins/Bitpay folder, updates tests and dependency injection, and replaces the old middleware-based Bitpay API detection with a new endpoint selector policy. The change itself is structural rather than a targeted security fix, but any large refactor of authentication and routing code carries a risk of accidentally changing access-control behavior.

Security candidateRefactor: Move translations classes in its own pluginby Nicolas Dorier · 64d5a893 · Feb 20, 2026 · 26 filesMessage 62 · AdequateInformational 15Details
Commit message · Nicolas Dorier

Refactor: Move translations classes in its own plugin

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit is a routine code reorganization: it moves BTCPay Server's translation/localization code from the core server project into a dedicated 'Translations' plugin. The same dictionary-management features, language-pack download, and localization services are preserved, just relocated. There is no indication of a security fix or vulnerability being addressed.

Security candidateFix: Can't upgrade/downgrade a Lifetime subscription (#7194)by Nicolas Dorier · 41295c17 · Feb 19, 2026 · 2 filesMessage 70 · AdequateInformational 20Details
Commit message · Nicolas Dorier

Fix: Can't upgrade/downgrade a Lifetime subscription (#7194)

Fix #7193

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
update trust
AI analysis · Informational 20/100

This commit fixes a JavaScript crash in the subscription portal. When a user had a lifetime subscription, the page did not show an auto-renewal checkbox, but the script still tried to attach an event listener to it. That caused a browser error that blocked the rest of the page's JavaScript, making it impossible to upgrade or downgrade the subscription. The fix simply checks whether the checkbox exists before attaching the listener. There is no direct security vulnerability here; it is a functional bug with a minor denial-of-service-like effect on the UI.

Security candidateMerge pull request #7185 from Abhijay007/feat/updateTranslationsby Abhijay Jain · 0df82d8a · Feb 16, 2026 · 6 filesMessage 73 · AdequateLow 29Details
Commit message · Abhijay Jain

Merge pull request #7185 from Abhijay007/feat/updateTranslations

feat: added ability to update translations

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
boot or update pathmerge-commit duplicate discount
AI analysis · Low 29/100

This commit adds a feature that lets BTCPay Server administrators download and update language translation packs from a GitHub repository. The code fetches JSON translation files over the internet, stores them in the server's database, and tracks whether a newer version is available. There is no clear security bug in the diff, but the design introduces a supply-chain and server-side request risk that should be reviewed carefully.

Security candidateAdd custom textbox for checkout (#7182)by Pavlenex · 9b4b2e41 · Feb 15, 2026 · 8 filesMessage 81 · StrongLow 32Details
Commit message · Pavlenex

Add custom textbox for checkout (#7182)

* Add custom textbox for checkout

* Use overflow-wrap instead of deprecated word-break for checkout text

* Add client-side maxlength to checkout text textarea

81/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
memory safety
AI analysis · Low 32/100

This commit adds a new store setting that lets merchants type a short custom message shown on the checkout page. The text is limited to 500 characters, stored as plain text, and displayed using a safe Vue.js directive that escapes HTML. There is no obvious security bug in the change itself, but it is a new user-controlled text field rendered on a payment page, so it needs careful handling to avoid future misuse (for example, if someone later changes how the text is displayed).

Security candidatePass userHandle to FIDO authby Nicolas Dorier · 69c99a1c · Feb 12, 2026 · 1 fileMessage 50 · ThinLow 33Details
Commit message · Nicolas Dorier

Pass userHandle to FIDO auth

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 33/100

This commit changes the WebAuthn/FIDO login JavaScript so that it now sends an extra piece of information, called the userHandle, to the server when a user logs in with a security key or passkey. The userHandle helps the server identify which account the credential belongs to. Without it, the server may have to guess the account from the credential ID alone, which can cause login failures or, in some FIDO implementations, allow a credential to be associated with the wrong account. The change is small and looks like a correctness fix rather than a full security patch.

Security candidateThrottle API calls with Basic auth (#7177)by Nicolas Dorier · a75b9517 · Feb 12, 2026 · 8 filesMessage 58 · ThinModerate 66Details
Commit message · Nicolas Dorier

Throttle API calls with Basic auth (#7177)

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Moderate 66/100

This change adds speed bumps (rate limiting) to API logins that use username-and-password Basic authentication. It is a hardening fix: before, attackers could make unlimited rapid login attempts through the API; now those attempts are throttled after the account is more than five minutes old. The patch also improves error messages so the server can tell callers exactly why authentication failed, including when they are rate-limited.

Security candidateRefactor : Added missing translations strings for various files (#6897)by Abhijay Jain · bcdd6dc8 · Feb 9, 2026 · 26 filesMessage 81 · StrongInformational 15Details
Commit message · Abhijay Jain

Refactor : Added missing translations strings for various files (#6897)

* refactor : Added missing translation strings to Wallet Management

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* refactor : Added missing translation strings to Store Management

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Refactor : Added missing translation strings to Server Administration

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Refactor : Added missing translation strings to User Account

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Refactor : Added missing translation strings shared components

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Refactor : Added missing translation strings Invoice and Payment

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Refactor : Added missing translation strings other files

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Refactor : Added missing translation strings other missed files

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* refactor: fixed some problematic strings

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Refactor: removed dynamic strings

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* refactor: addressed requested changes

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* refactor : removed public facing page

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* refactor: updated branch and addressed coderabit comments

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* Update default translations and resolve merge conflicts

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* refactor: removed duplicate attributes

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

---------

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
seed or entropy pathsigning or wallet pathboot or update path
AI analysis · Informational 15/100

This commit is a routine internationalization (i18n) refactor. It marks more user-interface text strings in BTCPay Server's web pages as translatable and updates the default translation dictionary. There is no security-relevant change to application logic, access control, cryptography, or data handling.

Security candidateDo not show Server service links on the Dashboard if insuffient permissionsby Nicolas Dorier · f75cdf37 · Jan 26, 2026 · 5 filesMessage 50 · ThinLow 34Details
Commit message · Nicolas Dorier

Do not show Server service links on the Dashboard if insuffient permissions

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
credential or privilege state
AI analysis · Low 34/100

This change hides a dashboard widget called 'Lightning Services' from users who do not have permission to change server settings. Previously, the widget may have been visible to users who lacked those rights, potentially exposing links or information about server-level Lightning services. The fix adds a permission check directly to the widget's HTML wrapper so it only renders for authorized users.

Security candidateFix: CanModifyInvoices permission should include the ability to see the lightning invoices of the storeby Nicolas Dorier · 8f7311bd · Jan 26, 2026 · 1 fileMessage 62 · AdequateModerate 50Details
Commit message · Nicolas Dorier

Fix: CanModifyInvoices permission should include the ability to see the lightning invoices of the store

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
credential or privilege state
AI analysis · Moderate 50/100

This commit fixes a permission inconsistency in BTCPay Server. Previously, a user who had permission to create Lightning invoices for a store might not have had explicit permission to view those same Lightning invoices. The change makes 'view Lightning invoice' a child permission of 'create Lightning invoice', so anyone who can create them can also see them. This is described as a fix, not a new security vulnerability disclosure, and the diff alone does not show an active exploit or a disclosed incident.

Security candidateAdd LUNO exchange as default for ZAR currencyby Nicolas Dorier · d27793dc · Jan 23, 2026 · 9 filesMessage 45 · ThinInformational 17Details
Commit message · Nicolas Dorier

Add LUNO exchange as default for ZAR currency

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 17/100

This commit mainly adds the LUNO exchange as the default source for South African Rand (ZAR) exchange rates in BTCPay Server. It also includes a small hardening fix in another rate provider so that missing bid/ask values don't crash the app, plus a batch of unrelated test reliability improvements. There is no clear security vulnerability being patched.

Security candidateFix flaky CanCreateCrowdfundingAppby Nicolas Dorier · 69cc179f · Jan 21, 2026 · 2 filesMessage 35 · OpaqueInformational 15Details
Commit message · Nicolas Dorier

Fix flaky CanCreateCrowdfundingApp

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit fixes a flaky automated test for the crowdfunding feature. The test previously cleared a date field by directly manipulating the webpage's internal value, which was unreliable. The change makes the test click a visible 'Clear' button instead, and adds an ID to that button so the test can find it. There is no security issue here.

Security candidateRefactor: Move PoS views in PoS plugin folderby Nicolas Dorier · e09133e0 · Jan 20, 2026 · 12 filesMessage 57 · ThinInformational 15Details
Commit message · Nicolas Dorier

Refactor: Move PoS views in PoS plugin folder

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathboot or update path
AI analysis · Informational 15/100

This commit is a straightforward code reorganization: it moves the Point of Sale (PoS) user-interface files from a shared views folder into the dedicated Point of Sale plugin folder, and updates the corresponding file paths in the controller and plugin registration. There is no functional change to how the application behaves, and no security fix or vulnerability is introduced.

Security candidate[Feature] Store-scoped labels + linkedType-scoped LabelManager suggestions (#7050)by thgO.O · 689b9d17 · Jan 20, 2026 · 25 filesMessage 91 · StrongLow 29Details
Commit message · thgO.O

[Feature] Store-scoped labels + linkedType-scoped LabelManager suggestions (#7050)

* feat: allow label manager to scope suggestions by linked type

* fix: render unlabeled payment requests as "Unlabeled" in reports

* feat: apply linked type scoped labels to EditPaymentRequest view

* feat: add store-scoped label tables

* test: cover store-scoped label migration

* feat: add StoreLabelRepository

* feat: support store-scoped LabelManager

* refactor: payment requests use store-scoped labels

* fix: adapt ReservedAddresses to labelmanager event

* refactor: coderabbit nits

* refactor: type-scoped store labels schema with snake_case

* refactor: persist label colors as column

* refactor: cleanup label links and usage

* refactor: simplify label repository ops

* fix: secure label updates and ensure pgcrypto

* test: stabilize CanUpgradeAndDowngrade

* refactor: coderabbit nits

* feat: use snake_case schema and case-insensitive label merge

* test: add playwright coverage for store label casing

* refactor: use snake_case schema and indexed case-insensitive label lookups

91/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
update trustsigning or wallet path
AI analysis · Low 29/100

This commit refactors how BTCPay Server stores labels for payment requests, moving them from a wallet-based graph system into new store-scoped database tables. It also adds a new API endpoint for updating store-scoped labels. The changes are primarily a feature/refactoring effort, but they include security-relevant hardening such as CSRF token validation on the new update endpoint, a check that the target store exists and matches the route, and restrictions preventing deletion or renaming of reserved system label types. A migration copies existing payment-request labels into the new tables and removes the old wallet-graph entries.

Security candidateRefactor: Move crowdfund files into Plugins/Crowdfund (#7112)by Nicolas Dorier · 757ad829 · Jan 16, 2026 · 8 filesMessage 70 · AdequateInformational 19Details
Commit message · Nicolas Dorier

Refactor: Move crowdfund files into Plugins/Crowdfund (#7112)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 19/100

This commit is a code reorganization: it moves the Crowdfund feature's files into a dedicated plugin folder and updates the controller to use newer ASP.NET Core patterns (primary constructor, area routing). It also makes a small change so that looking up a store for an app throws an exception if the store is missing, instead of returning null. There is no clear security fix or vulnerability being patched here.

Security candidateFeature: Cold wallet transaction support via Greenfield API (#7068)by Nicholas Halka · 8a30dd1e · Jan 9, 2026 · 7 filesMessage 91 · StrongLow 32Details
Commit message · Nicholas Halka

Feature: Cold wallet transaction support via Greenfield API (#7068)

* Enables unsigned PSBT transaction creation

Adds support for creating unsigned PSBT transactions, facilitating multisig withdrawal workflows.
Introduces a new API endpoint for broadcasting on-chain transactions.
Enhances transaction creation to allow opting out of server-side signing.

* Update Docs And Tests

* Removes Unused Transaction field from PSBT creation response

91/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 32/100

This commit adds new API features to BTCPay Server so users can create unsigned Bitcoin transactions (PSBTs) and broadcast already-signed transactions through the Greenfield API. It is a feature addition, not a bug fix. The code does not appear to introduce an obvious vulnerability, but it changes how wallet transactions are authorized and signed, which is security-sensitive. There is no vendor statement or external report saying this commit fixes a security issue.

Security candidateFix: PSBT Scan via Camera was not closing the modal dialog when signing a multisig transaction (#7089)by Nicolas Dorier · 1787e9d2 · Jan 9, 2026 · 1 fileMessage 70 · AdequateInformational 18Details
Commit message · Nicolas Dorier

Fix: PSBT Scan via Camera was not closing the modal dialog when signing a multisig transaction (#7089)

Fix #6925

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet pathparser or protocol path
AI analysis · Informational 18/100

This is a small user-interface bug fix. When a user scanned a QR code with their camera to provide a PSBT (a partially signed Bitcoin transaction), the on-screen modal dialog failed to close for multisig transactions because the JavaScript was clicking the wrong button. The patch makes the code click the correct button so the modal closes as expected. There is no security vulnerability here.

Security candidatechore(ci): enforce signature verification before Docker builds (#7077)by Abhijay Jain · 49649f5a · Jan 6, 2026 · 3 filesMessage 100 · StrongInformational 15Details
Commit message · Abhijay Jain

chore(ci): enforce signature verification before Docker builds (#7077)

* chore(ci): enforce GPG signature verification before Docker builds

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* chore(ci): enforce commit signature verification

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

* chore: updated the code

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

---------

Signed-off-by: Abhijay007 <Abhijay007j@gmail.com>

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
signing boundarydefensive validationsigning or wallet path
AI analysis · Informational 15/100

This commit adds a CI safety check that refuses to build Docker images unless the current Git commit has a valid GPG signature. It is a hardening improvement, not a fix for an active vulnerability. There is no indication in the commit or title that it responds to a known security incident.