Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…
This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…
New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…
Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …
New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…
Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…
Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…
Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…
UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…
No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…
UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…
Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…
No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…
Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…
Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…
Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…
New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …
Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…
Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…
This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…
Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
Lower-priorityfix height of details modal when adding note from send confirmation (#3413)by malik1004x · 5dfae0e1 · Jul 18, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · malik1004x
fix height of details modal when adding note from send confirmation (#3413)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
* feat: add Trezor passphrase support for wallet restoration process
* revert: send page changes
* chore: format code
* chore: format code
* chore: reorganize imports and improve code formatting in send_page.dart [skip ci]
* auto-reformat
* fix: trezor usb device refresh race condition
* fix: ui bugs in relation to trezor
* fix: only show passphrase option for trezor devices
---------
Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com> Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlsigning or wallet pathauthentication path
AI analysis · Low 25/100
This commit adds support for using a passphrase with Trezor hardware wallets when restoring a Monero wallet in Cake Wallet. It also fixes a small race condition when refreshing the list of connected USB devices. There is no clear security vulnerability in the diff itself; it is a feature addition with some minor hardening.
* feat: add Lightning transaction URL support in transaction details view model
* fix: update currency selection logic in WalletAddressListViewModel and ReceivePage
* feat: integrate computed transaction amount and fee getters in TransactionDetailsViewModel, refactor CopyWrapper logic in TransactionDetailsModal
* refactor: apply lint rules
* refactor: apply lint rules and improve LNURL handling with new methods for withdrawal requests and error checks
* auto-reformat
* fix: receive_page regression
* fix: Withdraw lightning to other btc wallet gives LN address
* chore: update .lock files [skip ci]
---------
Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com> Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
86/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100
This is a routine feature and bug-fix update for Cake Wallet's Lightning (Bitcoin layer-2) support. It adds the ability to handle LNURL withdrawal requests, fixes currency selection when receiving Bitcoin vs Lightning, and cleans up transaction-detail display. There is no clear security vulnerability in the diff, but the new network code that calls external Lightning services and parses invoices is a place where future bugs could matter, so it deserves normal review and testing.
* feat: rescan on zkool fix: sending to extracted addresses fix: labeling shielding txs fix: autoshield endless loop fix: autoshield t addr not firing fix: autoshield destinations chore: remove old routes for rescan with zkool other minor fixes/cleanups
* chore: bump zkool2 to latest version fix: reduce amount of taddrs generated fix: derivation path for internal wallets fix: display address in correct hidden/usable spots fix: get wallet db height before it syncs for the first time fix: taddr rotation with passphrase fix: sync progress ui refresh fix: taddress generation not getting capped fix: hidden addresses not being hidden fix: pending transactions not being shown fix: t address cache misses fix: t address rotation not getting refreshed fix: t address high index not being used
* fix: refresh t addresses
* fix: patch rust side to make t addr rotation work
* fix: ui issue in recipient address fix: zcash multiaddress send to show in the ui fix: potential race condition
* minor fixes
* format
* fix: flashing on receive screen
* remove unused 'autoShield'
* review
71/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlcryptography-sensitive pathsigning or wallet path
AI analysis · Low 44/100
This is a large feature commit that replaces Cake Wallet's older Zcash wallet backend (warp_api) with a new library called zkool2. It touches address generation, transaction creation, balance scanning, transparent-address rotation, auto-shielding, and migration of old wallets. The commit message lists many bug fixes, but the code change is broad and partially complete (for example, the rescan method is mostly commented out). There is no direct evidence in the commit of a deliberate security vulnerability, but the size and incomplete state create a higher-than-normal risk of bugs that could lose funds, leak privacy, or produce incorrect balances.
Lower-priorityfix context passed to navigatorby Robert Malikowski · 8616824c · Jul 17, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Robert Malikowski
fix context passed to navigator
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedadd spaceby Robert Malikowski · 07d78b0a · Jul 17, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski
add space
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit fixes a simple Dart syntax error by adding a missing space between the keyword `const` and `BorderRadius.only`. It is a cosmetic/code-correctness change with no security relevance.
AI review queuedmergeby Robert Malikowski · 108363c5 · Jul 17, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski
merge
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit adds a single optional parameter named `bottomText` to a user-interface widget class. It is a straightforward code change with no visible security relevance.
AI review queueddart fixby Robert Malikowski · fa9229ec · Jul 17, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski
dart fix
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is a routine code cleanup of a single Dart file in the Cake Wallet app's buy/sell screen. It changes quote styles on imports, adds 'const' keywords, reformats function bodies, and reorders constructor parameters. There is no change to app behavior, no bug fix, and no security relevance visible in the diff.
Lower-prioritywrap in popScope to prevent error on back button pressby Robert Malikowski · 59eb3d79 · Jul 17, 2026 · 1 fileMessage 62 · AdequateTriage 0Details
Commit message · Robert Malikowski
wrap in popScope to prevent error on back button press
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
Lower-priorityfix: Wrong fiat for sent tx from swaps (#3409)by David Adegoke · 3070612f · Jul 17, 2026 · 2 filesMessage 88 · StrongTriage 0Details
Commit message · David Adegoke
fix: Wrong fiat for sent tx from swaps (#3409)
* fix android CI
* fix: wrong fiat amount showing for sent tx from swaps
* fix: use token address to fetch fiat amount for pending send entry
88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI review queueddelete solana sync keys when removing the walletby Omar · c10ce20c · Jul 16, 2026 · 1 fileMessage 45 · ThinLow 47Details
Commit message · Omar
delete solana sync keys when removing the wallet
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 47/100
This commit fixes a cleanup issue in Cake Wallet's Solana support. When a user deleted a Solana wallet, the app left behind leftover 'last synced signature' data stored on the device. This patch now deletes those leftover records when the wallet is removed. It is a privacy/data-hygiene fix rather than a remote hack vulnerability.
Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com> Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 23/100
This commit fixes bugs in how Cake Wallet connects to Ledger hardware wallets. It adds guards so the app doesn't crash or behave oddly when no Ledger connection exists, prevents duplicate connection attempts, improves cleanup when switching wallets, and updates the underlying Ledger Bluetooth/USB library versions. There is no obvious new security vulnerability here; the changes look like stability and reliability improvements for hardware wallet users.
* add incremental sync, parallel fetch for native and spl token, and other improvments on perf and display regarding lagging
81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100
This commit is a routine performance and reliability improvement for Solana wallets in Cake Wallet. It makes transaction syncing faster by only fetching new signatures since the last sync, batches network requests, prevents duplicate refreshes, and fixes a few small UI calculation bugs. There is no clear security vulnerability being patched, and the changes do not appear to introduce one.
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet pathboot or update path
AI analysis · Informational 15/100
This commit is purely a code-formatting cleanup. It adjusts line breaks, indentation, and whitespace across many Dart files but does not change any program logic, add new features, or alter security behavior.
Security candidateReformat the whole codebase with 100 line width (#3403)by Omar Hatem · 16ddc083 · Jul 14, 2026 · 801 filesMessage 58 · ThinInformational 15Details
Commit message · Omar Hatem
Reformat the whole codebase with 100 line width (#3403)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update pathauthentication pathparser or protocol path
AI analysis · Informational 15/100
This commit is a purely cosmetic reformatting of the entire codebase to use a 100-character line width. It adjusts whitespace, line breaks, and indentation across hundreds of files but does not change any program logic, security behavior, or functionality. The only non-formatting change is that the GitHub Actions lint workflow was disabled by commenting it out, which is a CI/process change rather than a product security issue.
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update pathauthentication pathparser or protocol path
AI analysis · Informational 15/100
This is a large automated code reformatting commit. It only changes whitespace, line breaks, indentation, and trailing newlines across hundreds of files. There is no change to program logic, no bug fixes, and no security-related behavior change.
feat: add allowedIp to moonpay signature generation (#3375)
75/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
signing boundary
AI analysis · Low 26/100
This commit updates how Cake Wallet builds payment links for MoonPay, a service that lets users buy or sell cryptocurrency inside the app. The app now asks its own backend server to produce the full signed payment URL, instead of adding the cryptographic signature itself on the device. The backend can now also restrict the link to the user's IP address. The change is a feature/refactor; there is no direct evidence in the commit that it fixes an active security vulnerability.
Remove broken feature request discussion link (#3336)
Remove the extra GitHub issue contact link that pointed to a broken Discussions category.
The repository already has a working Feature request issue template, so the duplicate Feature or Enhancement Request contact link created a confusing entry in the issue creation modal and led users to a failing GitHub Discussions URL.
81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100
This commit fixes a timing bug in how the wallet saves address records. Previously, several save operations were started without waiting for each to finish, which could cause them to overlap or complete out of order. The change makes the code wait for each save step before starting the next one, and also tweaks how address lists are copied to avoid a subtle race where the list could change mid-save. A new network error message is also added to the ignore list, and a CI workflow step is adjusted.
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100
This commit is a routine code-quality and CI housekeeping change. It adds and reorganizes Dart lint rules, creates a custom lint plugin to enforce coding standards (e.g., prefer a verbose print helper, avoid direct HTTP imports, restrict cross-package imports), and updates several tool scripts to use plain print() instead of the app's verbose logger. There is no user-facing security fix or vulnerability patch in the diff.