Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This change only edits the project's automated continuous-integration (CI) configuration file. It turns on all optional cryptographic modules by default in CI and adds test runs that disable each module one at a time. There is no change to…
No source-code changesNo build-system logic changesCI-only workflow refactor
This commit is a code cleanup (refactor) that splits one internal public-key parsing helper into three clearly named versions. It does not change what keys the public API accepts or rejects, and it adds more tests. There is no security vul…
Refactor only: no change to accepted public-key formats or validation rulesPublic API behavior preserved: 33-byte compressed and 65-byte uncompressed/hybrid still acceptedInternal fixed-size callers now use size-specific parser, reducing risk of accidental hybrid acceptance in future code
This commit only adds new test code to check that a specific Schnorr signing function behaves in a constant-time manner under Valgrind. It does not change any production cryptographic code, so it cannot introduce or fix a security vulnerab…
Only test file src/ctime_tests.c changedNo production cryptographic code modifiedAdds constant-time (CHECKMEM/Valgrind) coverage for schnorrsig_sign_custom
This commit is a code-quality and defensive-programming change. It restructures internal elliptic-curve helper functions so that runtime consistency checks (VERIFY macros) wrap the real implementation and cannot be skipped by an early 'ret…
Defensive restructuring of assertion wrappersAdds missing VERIFY post-conditions on group element outputsNo functional cryptographic change
This commit only adds new test code to check that a specific function behaves correctly when given a buffer of exactly the right size. It does not change any production code, fix a bug, or introduce a vulnerability. It is a routine improve…
This commit only adds a new test case. It checks that a DER signature can be written into a buffer that is exactly the right size, and that writing into a buffer one byte too small fails correctly. There is no change to the actual library …
This commit only adds new test cases to the libsecp256k1 test suite. It does not change any production cryptographic code. The new tests check that the DER signature parser correctly handles an unusual but valid length-encoding format (the…
Adds test coverage for DER long-form length encoding acceptance and rejectionTargets secp256k1_der_read_len boundary conditionsNo changes to src/ecdsa_impl.h or any production parsing logic
This commit only adds new test cases to the project's test suite. It does not change any production parsing code. The tests verify that the existing DER signature parser correctly accepts valid long-form length encodings and rejects invali…
This commit is a straightforward code cleanup: it removes a small internal helper function named secp256k1_get_hash_context() and replaces every call with direct access to the context's hash_ctx field. The behavior is identical; no securit…
This is a routine internal code cleanup: it moves helper functions that convert between group elements and byte strings from one internal file to another, and renames a couple of private-key tweak helpers from 'privkey' to 'seckey'. The pu…
This commit is a simple renaming of internal function names from 'privkey' to 'seckey' to match current project terminology. No behavior of the code changes, and there is no security fix or vulnerability introduced.
This is a small internal cleanup in Bitcoin Core's secp256k1 cryptography library. It replaces a manual secret-key validity check (overflow plus zero) with an existing helper function that does the same thing. The behavior is intended to b…
No security-relevant behavioral change is described or evidentRefactoring only: equivalent overflow-and-zero check via existing helperReturn value logic preserved with added parentheses for warning avoidance
This is a pure code cleanup change: it renames a function parameter from 'ctx' to 'ecmult_gen_ctx' in several internal files and moves the asterisk in pointer declarations for style consistency. No behavior, logic, or security properties o…
This commit fixes an integer overflow bug in the library's internal scratch-space memory allocator. If a caller requested a scratch space with a size near the maximum possible value, adding the allocator's own bookkeeping header could wrap…
This commit is a pure code cleanup: it renames a function parameter from 'ctx' to 'ecmult_gen_ctx' in several related files and moves the asterisk in pointer declarations from the left side to the right side (e.g., 'type* arg' to 'type *ar…
This commit fixes a low-level arithmetic overflow check in a special internal memory-pool helper called 'scratch space'. Because the scratch API is no longer exposed to users, the bug cannot be triggered by normal callers today. The change…
Integer overflow in size calculationPotential heap buffer under-allocationDefensive hardening of internal allocator helper
This commit fixes test-suite bugs, not the cryptographic library itself. Several test cases were using outputs from functions without first checking whether those functions succeeded. In rare cases a failed setup step could leave a value t…
Test-only hardeningMissing return-value checks in test codePotential false-positive test passes on setup failure
This commit is a straightforward code cleanup: it removes a tiny internal helper function called secp256k1_get_hash_context() and replaces every call with direct access to the context's hash_ctx field. The behavior is identical; no securit…
This commit is a routine post-release bookkeeping change. It bumps the project's version number from 0.8.0 to 0.8.1, marks the current code as an unreleased development snapshot, and updates the changelog accordingly. There are no code, cr…
This commit is a routine post-release bookkeeping change. It bumps the project's version number from 0.8.0 to 0.8.1, marks the current code as an unreleased development snapshot, and updates the changelog accordingly. There are no code, cr…
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
Security candidateAdd VERIFY_CHECKs that flags are 0 or 1by John Moffett · ae00c552 · Dec 15, 2025 · 11 filesMessage 78 · AdequateLow 36Details
Commit message · John Moffett
Add VERIFY_CHECKs that flags are 0 or 1
Flags for constant-time masking rely on the values being exactly 0 or 1 rather than 0 or true. Add VERIFY_CHECKs to enforce in VERIFY builds as a preventative measure and add documentation where relevant.
78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
constant-time or timing behavior
AI analysis · Low 36/100
This commit adds safety checks and documentation to ensure that 'flag' values used in secret-handling code are exactly 0 or 1, not just any 'true' value. These flags control constant-time selection and memory wiping. If a caller passed a different non-zero value, the masking math could behave incorrectly and potentially leak secret information through timing or produce wrong results. The new checks only fire in special VERIFY builds, so they are a defensive hardening measure rather than a fix for an active bug.
Security candidaterefactor: remove ret from secp256k1_ec_pubkey_serializeby kevkevinpal · 3daab83a · Dec 9, 2025 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · kevkevinpal
refactor: remove ret from secp256k1_ec_pubkey_serialize
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This is a tiny internal code cleanup in a Bitcoin cryptography library. It removes an unnecessary intermediate variable and replaces it with direct 'return 1' and 'return 0' statements. The function's behavior is unchanged, and there is no security issue.
Security candidateAdd ARG_CHECKs to ensure "array of pointers" elements are non-NULLby Sebastian Falbesoner · 5a08c1bc · Dec 6, 2025 · 3 filesMessage 62 · AdequateLow 46Details
Commit message · Sebastian Falbesoner
Add ARG_CHECKs to ensure "array of pointers" elements are non-NULL
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Low 46/100
This commit adds safety checks to several Bitcoin libsecp256k1 functions that accept arrays of pointers. Previously, if a caller passed an array containing a NULL (empty) pointer, the code might read from or process an invalid memory location, potentially causing a crash or unpredictable behavior. The new checks reject such inputs cleanly before any processing begins. It is a defensive hardening fix rather than a confirmed exploitable vulnerability.
This change improves separation from CMake build directories, which typically use the "build" prefix.
Additionally, corresponding `.gitignore` entries have been refactored.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit simply renames the Autotools helper directory from 'build-aux' to 'autotools-aux' and updates the related references in build files and .gitignore. It is a build-system housekeeping change with no effect on the cryptographic code or runtime security.
Security candidateuse new `_eckey_pubkey_serialize{33,65}` functions in public APIby Sebastian Falbesoner · adb76f82 · Nov 17, 2025 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Sebastian Falbesoner
use new `_eckey_pubkey_serialize{33,65}` functions in public API
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This is a small internal code cleanup in the Bitcoin Core secp256k1 library. It changes how public keys are converted to bytes in one public function, replacing a single flexible helper with two fixed-size helpers. There is no indication of a security bug being fixed.
Security candidatetest: introduce (mini) unit test frameworkby furszy · 48789daf · Oct 1, 2025 · 6 filesMessage 95 · StrongInformational 15Details
Commit message · furszy
test: introduce (mini) unit test framework
Lightweight unit testing framework, providing a structured way to define, execute, and report tests. It includes a central test registry, a flexible command-line argument parser of the form "--key=value" / "-k=value" / "-key=value" (facilitating future framework extensions), ability to run tests in parallel and accumulated test time logging reports.
So far the supported command-line args are: - "--jobs=<num>" or "-j=<num>" to specify the number of parallel workers. - "--seed=<hex>" to specify the RNG seed (random if not set). - "--iterations=<num>" or "-i=<num>" to specify the number of iterations.
Compatibility Note: To stay compatible with previous versions, the framework also supports the two original positional arguments: the iterations count and the RNG seed (in that order).
95/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
entropy or randomness
AI analysis · Informational 15/100
This commit is a pure test-infrastructure change. It introduces a small internal unit-test framework for the secp256k1 cryptographic library, replacing a long hand-written main() function with a registry of test cases and adding optional parallel test execution. It does not change any cryptographic code, public API, or production behavior, and it does not fix or introduce any security vulnerability.
Security candidatedocs: Improve API docs of _context_set_illegal_callbackby Tim Ruffing · 4d90585f · Sep 22, 2025 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · Tim Ruffing
docs: Improve API docs of _context_set_illegal_callback
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit only changes documentation comments in a header file. It rewords descriptions of error and illegal-argument callbacks, fixes typos, and clarifies wording. No executable code, build system, or API behavior was changed, so it has no security impact on its own.
Security candidatedocs: Clarify that callback can be called more than onceby Tim Ruffing · 895f53d1 · Sep 22, 2025 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · Tim Ruffing
docs: Clarify that callback can be called more than once
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit only changes a documentation comment in a header file. It clarifies that if a user-supplied error callback returns instead of aborting, the API call's results are undefined and the callback may be triggered more than once. No code behavior was changed.
This change fixes: - `-Wuninitialized` in both Autotools and CMake; - `-Wreturn-type` in CMake only.
72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit fixes compiler warnings in build-system tests that detect whether x86_64 assembly can be used. It initializes a variable and adds a return statement to a small test program. These changes do not affect the actual cryptographic code, runtime behavior, or security of the library.
Security candidatedoc: clarify API doc of `secp256k1_ecdsa_recover` return valueby Jonas Nick · 7321bdf2 · Sep 16, 2025 · 1 fileMessage 70 · AdequateInformational 15Details
Commit message · Jonas Nick
doc: clarify API doc of `secp256k1_ecdsa_recover` return value
Co-authored-by: Tim Ruffing <me@real-or-random.org>
70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Names security-relevant behavior explicitly
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit only updates the documentation comments for a function in a header file. It clarifies what the return value of secp256k1_ecdsa_recover means and explains a subtle detail about signature normalization after converting a recoverable signature. No code logic was changed, so there is no security vulnerability or fix here.
Security candidateSplit memclear into two versionsby John Moffett · 399b582a · Sep 8, 2025 · 11 filesMessage 68 · AdequateInformational 24Details
Commit message · John Moffett
Split memclear into two versions
secp256k1_memclear has the side effect of undefining bytes for valgrind checks. In some cases, we may want to zero bytes but allow subsequent reads. So we split memclear into memclear_explicit, which makes no guarantees about the content of the buffer on return, and memzero_explicit, which guarantees zero value on return.
Change the memset in partial_sign to use memzero_explicit.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 24/100
This commit is a code-quality and testing-hardening change inside a widely used cryptographic library. It splits one internal memory-wiping helper into two: one that guarantees zeros (used where the code later reads the buffer) and one that intentionally marks memory as undefined in test builds (used where the buffer should never be read again). The only functional change visible in the diff is replacing a plain memset with the guaranteed-zero helper in one MuSig partial-signing path, which makes the code's intent clearer and avoids a potential test-only false positive. There is no direct evidence this fixes an exploitable vulnerability in production.
doc: mention ctx requirement for `_ellswift_create` (not secp256k1_context_static)
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This is a one-line documentation update. It clarifies that a specific function should not be called with a special read-only context object named secp256k1_context_static. There is no code change and no security fix.
Security candidatedoc: Recommend clang-cl when building on Windowsby Hennadii Stepanov · 7379a5be · Aug 24, 2025 · 175 filesMessage 45 · ThinInformational 15Details
Commit message · Hennadii Stepanov
doc: Recommend clang-cl when building on Windows
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit is a large repository import or merge that brings in the entire libsecp256k1 codebase, including build systems, CI configuration, documentation, and source files. The commit title says it only updates Windows build documentation to recommend clang-cl, but the actual diff shows a wholesale addition of 175 files. There is no code change that fixes or introduces a security vulnerability in the cryptographic library itself.
Move the sha256_tag_test_internal function out of the musig module into tests.c. This makes it available to other modules wishing to verify tagged hashes without needing to duplicate the function.
Change the function signature to expect a const unsigned char and update the tagged hash tests to use static const unsigned char character arrays (where necessary).
Add a comment for each tag. This is done as a convenience for checking the strings against the protocol specifications, where the tags are normally specified as strings.
Update tests in the ellswift and schnorrsig modules to use the sha256_tag_test_internal helper function.
83/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
signing boundary
AI analysis · Informational 15/100
This commit is a test-only cleanup. It moves a helper function that checks SHA256 'tagged hash' setup from one test file to a shared test file, renames it, and updates several test modules to use the shared helper. There are no changes to the actual cryptographic library code that users rely on, and no security bug is fixed or introduced.