Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…
This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…
New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…
Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …
New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…
Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…
Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…
Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…
UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…
No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…
UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…
Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…
No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…
Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…
Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…
Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…
New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …
Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…
Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…
This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…
Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
AI review queuedminor fixby Omar · dcca96b0 · Jun 28, 2026 · 1 fileMessage 0 · OpaqueInformational 18Details
Commit message · Omar
minor fix
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 18/100
This is a small UI stability fix in the cryptocurrency swap screen. It replaces a forceful 'this widget must exist' access with a safer 'if it exists' check for the receive-amount field. The change prevents the app from crashing if the receive-side widget has not finished building when the user types or changes settings. There is no indication this allows theft of funds, bypass of security checks, or remote exploitation.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 32/100
This is a large routine maintenance commit that upgrades the Flutter framework and many supporting libraries for the Cake Wallet cryptocurrency app. Most changes are build-tool and dependency version bumps, plus replacing automatically generated data-storage code with pre-generated files. Two small behavior changes are included: frozen coins are now preserved when refreshing coin information, and a secure-memory helper is adjusted. The commit does not describe these as security fixes, and there is no evidence of an active vulnerability being patched.
AI review queuedlocale fixby Robert Malikowski · eff46638 · Jun 26, 2026 · 3 filesMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski
locale fix
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit fixes how dates are formatted in the wallet's transaction history so they match the user's selected language/locale. It also slightly reorganizes the buttons shown at the top of the assets/history tabs by moving their definitions into a shared data class. There is no security-relevant change.
Lower-priorityfix observer for history sectionby Robert Malikowski · 117f8e92 · Jun 26, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Robert Malikowski
fix observer for history section
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityadd border around filters buttonby Robert Malikowski · 52b014aa · Jun 26, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Robert Malikowski
add border around filters button
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedfix swap filter checkboxby Robert Malikowski · ba0be28d · Jun 26, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Robert Malikowski
fix swap filter checkbox
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This is a one-line UI bug fix in a Flutter/Dart mobile wallet app. The change corrects which boolean value is checked when deciding what subtitle text and color to show for a swap-history filter checkbox. Previously it used the checkbox's own value; now it uses the app's trade-filter store state. There is no security relevance visible in the commit.
AI review queuedfix today thresholdby Robert Malikowski · 68100967 · Jun 26, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Robert Malikowski
fix today threshold
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit fixes how the app groups transactions on the dashboard. Previously, transactions from the last 24 hours were labeled as 'today'; now only transactions from the current calendar day are labeled 'today'. It is a cosmetic UI change with no security relevance.
AI review queuedfix send/receiveby Robert Malikowski · f7d80c62 · Jun 26, 2026 · 1 fileMessage 28 · OpaqueInformational 19Details
Commit message · Robert Malikowski
fix send/receive
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 19/100
This commit fixes a UI mix-up in the Cake Wallet transaction filter. Previously, the 'Send' filter button was wired to incoming transactions and the 'Receive' button was wired to outgoing transactions, so tapping them would show the wrong list. The patch swaps the labels back to their correct transaction directions. It also fixes a related exchange/trade filter bug where the filter's on/off state was misreported, and makes sure toggling 'all' also updates the exchange filter items. There is no security vulnerability here—just a user-interface bug that could confuse users about which transactions are displayed.
AI review queuedtx history improved layoutby Robert Malikowski · ac60a6ec · Jun 25, 2026 · 21 filesMessage 35 · OpaqueInformational 15Details
Commit message · Robert Malikowski
tx history improved layout
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
This commit is a user-interface redesign of the transaction history screen in the Cake Wallet app. It changes how transaction lists are grouped by date, moves filter and export buttons into a new modal, and adds new UI components for selecting/deselecting filters. There is no indication of any security fix or vulnerability being addressed.
Lower-priorityprevent trade.from saving as null + fallback when it does (#3346)by malik1004x · eaa8338a · Jun 25, 2026 · 5 filesMessage 58 · ThinTriage 0Details
Commit message · malik1004x
prevent trade.from saving as null + fallback when it does (#3346)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedimprove address rotation button ui + fix bug when autogenerate is disabled (#3334)by malik1004x · d3a14647 · Jun 25, 2026 · 2 filesMessage 81 · StrongInformational 24Details
Commit message · malik1004x
improve address rotation button ui + fix bug when autogenerate is disabled (#3334)
* improve address rotation button ui + fix bug when autogenerate is disabled
* remove dumbass debug print
* add button show condition
81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100
This commit fixes a UI bug in Cake Wallet's receive page. When the user had turned off automatic address generation, the manual 'rotate address' button could still be shown and pressed, but it would not actually update the displayed receiving address. The fix makes the button's visibility depend on whether rotation is truly available, shows a loading spinner while a new address is being created, and ensures the displayed address is updated after rotation even for non-Electrum wallets. There is no direct evidence of a security vulnerability such as funds being stolen; the issue is primarily a usability/consistency bug.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI review queuedtx history improved layout (wip)by Robert Malikowski · 7c7ddf82 · Jun 24, 2026 · 3 filesMessage 25 · OpaqueInformational 15Details
Commit message · Robert Malikowski
tx history improved layout (wip)
25/100 · OpaqueMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body! Contains work-in-progress language
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is a cosmetic work-in-progress change to the transaction history screen. It adds a shorter version of the transaction list (showing only the first 3 non-date items) for use in a compact layout. There is no security-relevant behavior visible in the diff.
AI review queuedminor fixes [skip ci]by Omar · cda9d09e · Jun 23, 2026 · 2 filesMessage 28 · OpaqueInformational 17Details
Commit message · Omar
minor fixes [skip ci]
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 17/100
This commit adds safety checks before closing on-screen dialogs and showing confirmation messages. It prevents the app from crashing or behaving oddly if a screen is no longer active when a backup finishes saving or a Ledger hardware wallet reconnects. There is no indication this is a security fix, and it does not appear exploitable by an attacker.
Lower-priorityFix desktop qr sizing (#3344)by malik1004x · 2764b46b · Jun 22, 2026 · 2 filesMessage 68 · AdequateTriage 0Details
Commit message · malik1004x
Fix desktop qr sizing (#3344)
* fix qr sizing on desktop
* fix cardsview sizing
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityfix(trezor): use PAYTOADDRESS script_type for external outputs (#3311)by Anipy · 57a3f687 · Jun 18, 2026 · 1 fileMessage 93 · StrongTriage 0Details
Commit message · Anipy
fix(trezor): use PAYTOADDRESS script_type for external outputs (#3311)
* fix(trezor): use PAYTOADDRESS script_type for external outputs
* Apply suggestion from @konstantinullrich
---------
Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com> Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>
93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
fix: avoid UIH2 fingerprint in payjoin receiver input selection (#3304)
Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>
85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI review queuedrefactor: improve locale parsing and normalization in localization ge… (#3330)by Omar Hatem · 29684aff · Jun 17, 2026 · 35 filesMessage 100 · StrongInformational 18Details
Commit message · Omar Hatem
refactor: improve locale parsing and normalization in localization ge… (#3330)
* refactor: improve locale parsing and normalization in localization generation script
* Remove chinese tranditional because it's breaking flutter
* delete retry in case of parallel save [skip ci]
* Improve translation
100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 18/100
This commit is mostly a routine translation and localization update across many languages, plus a small code change that retries deleting a wallet directory a few times if the first attempt fails. There is no clear security vulnerability being fixed. The retry logic is a minor reliability improvement, not a security fix.
Lower-prioritydev: add recovery screen when sqlite db doesn't open (#3179)by cyan · 24150377 · Jun 14, 2026 · 3 filesMessage 81 · StrongTriage 0Details
Commit message · cyan
dev: add recovery screen when sqlite db doesn't open (#3179)
* dev: add recovery screen when sqlite db doesn't open
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Lower-prioritydisable editing coin control from settings (#3284)by malik1004x · 9face62e · Jun 14, 2026 · 8 filesMessage 58 · ThinTriage 0Details
Commit message · malik1004x
disable editing coin control from settings (#3284)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedfix padding on NewWalletTypePage (#3333)by malik1004x · dbbd06aa · Jun 13, 2026 · 1 fileMessage 53 · ThinInformational 15Details
Commit message · malik1004x
fix padding on NewWalletTypePage (#3333)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a routine user-interface layout fix. It changes how the wallet-type list scrolls and adjusts padding on the 'New Wallet Type' screen so the page displays correctly. There is no security-relevant change.
Lower-priorityfix lnurl from scan button (#3332)by malik1004x · 3eaf0731 · Jun 13, 2026 · 2 filesMessage 53 · ThinTriage 0Details
Commit message · malik1004x
fix lnurl from scan button (#3332)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body