XMR
← All projectsMonero Project

Monero GUI

Official graphical Monero wallet and its release-build integration.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

138 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

12security candidates46second-pass queue58AI analyses
34commits · 30 days
43commits · 60 days
110commits · 180 days
138commits · 365 days
Backfill bands
Sep 27 → Mar 3127 seen0 candidatesComplete
Mar 31 → Jul 2961 seen8 candidatesComplete
Jul 29 → Aug 287 seen2 candidatesComplete
Aug 28 → Sep 2715 seen1 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

49/100 average clarity
6Strong · 80–100
14Adequate · 60–79
101Thin · 40–59
17Opaque · 0–39
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Thomas636178
selsta81628048
tobtoht2328052
Cole Munz111073
SChernykh10010028
jpk68902046
plowsof403051
наб100081
munzzyy100083
reservedbytes100050
Balló György100068
Analysis record

Published AI watches

Last scanned 35 minutes ago

Moderate 59 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4645

This change fixes a bug in the Monero wallet setup wizard. Previously, when restoring or creating a wallet from seed/keys, the wallet was first saved with a blank or temporary password before the user's chosen password was applied. If appl…

Wallet file created with empty/blank password before user password is appliedFailure to set user password does not prevent wallet file from being savedSensitive on-disk artifact (wallet file) may be protected by weaker credentials than intended
d7c2f13dby tobtoht+14−93 files
No security note in commit
Informational 17 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4687

This commit updates the Monero GUI wallet's message-signing screen so that when a user verifies a signature, the app now reports extra details: whether the signature is valid, which key type was used (spend key, view key, or unknown), and …

UI-only change to signature verification feedbackNo modification to cryptographic verification logicNew method exposes already-existing signature metadata (key type, version, old algorithm flag)
485a102cby tobtoht+50−133 files
No security note in commit
Low 35 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4709

This change adjusts how the Monero GUI wallet stores and passes login credentials for remote daemon connections. Previously, daemon username/password and 'trusted daemon' status were kept as persistent properties on the wallet object and r…

Credential scoping/lifetime reductionRemoval of persistent daemon login state from wallet objectDefense against cross-connection credential reuse
a5c305deby tobtoht+7−63 files
No security note in commit
Informational 19 AI analysisMessage 59 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4693

This commit fixes a display bug in the Monero GUI wallet's transaction history. Previously, when sorting transactions by block height, failed transactions were incorrectly treated like pending ones and shown at the top of the list. The fix…

UI display logic correction for transaction state classificationTightened conditional for treating transactions as pendingNo memory safety, cryptographic, or authorization changes observed
baef8be9by tobtoht+14−52 files
No security note in commit
Informational 15 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4692

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments with multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it …

0f8a1cf4by tobtoht+84−185 files
No security note in commit
Moderate 58 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4690

This update fixes a timing bug in the Monero wallet's send screen. If a user quickly changed or cancelled a payment while a transaction was still being prepared in the background, the wallet could accidentally show or use the wrong transac…

Race condition between asynchronous transaction creation and UI state changesUse-after-free / dangling pointer risk from stale PendingTransaction objectsPotential wrong-transaction confirmation or commit due to stale async result
c72adf62by tobtoht+57−243 files
No security note in commit
Informational 21 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4665

This commit adds a feature that lets users scan a QR code to restore a Monero wallet from its secret keys. The change itself is a feature addition, not a fix for a known vulnerability. There is one minor security-relevant detail: the QR co…

New QR URI parser handles secret keys (secret_view_key, secret_spend_key) and restore heightAddress validation is performed before accepting parsed restore URIScheme changed from monero_wallet: to monero-wallet:
68327c0aby tobtoht+52−13 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

p2pool v4.18.1

This commit simply updates the Monero GUI wallet's built-in downloader to fetch a newer version of the bundled P2Pool mining software (from v4.18 to v4.18.1) and updates the matching file hashes. There is no indication in the commit itself…

8d95b8a4by SChernykh+12−121 file
No security note in commit
Low 34 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Wallet: keep daemon credentials scoped to each connection

This commit changes how the Monero GUI wallet stores and uses login credentials for remote nodes (servers that help the wallet talk to the Monero network). Previously, the wallet kept daemon username/password as persistent wallet-level set…

Credential scoping change: daemon username/password no longer stored as persistent wallet state for connection reuseRemoval of setDaemonLogin() call from QML remote-node selection pathDaemon credentials now captured per-init and passed directly to underlying wallet implementation
10b08b3bby selsta+7−63 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

TransactionHistoryModel: only place pending tx first

This commit fixes a display bug in the Monero GUI wallet's transaction history list. Previously, failed transactions were being shown at the top of the list alongside pending transactions, because any transaction without a confirmed block …

UI presentation bug, not a memory-safety or cryptographic issueNo attacker-controlled input parsing changedNo privilege escalation, authentication, or authorization logic modified
27328f36by selsta+6−51 file
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

History: improve display of transactions with multiple recipients

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments to multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it is…

a3dc3882by selsta+84−185 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Wallet: fix send confirmation stale transaction race

This patch fixes a race condition in the Monero GUI wallet's send screen. If a user quickly changed send details or canceled a transaction while an earlier transaction was still being prepared in the background, the wallet could mix up the…

Race condition between asynchronous transaction creation and UI state changesPotential use of stale PendingTransaction object after cancellation/replacementMemory leak via undisposed PendingTransaction objects on rejection paths
3f2d9794by selsta+57−243 files
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

workflows: fix Windows build

This is a routine GitHub Actions CI fix for the Windows build. It adds the 'rust:p' package to the list of MSYS2 packages installed during the build. There is no security-relevant change visible in the diff.

dc9f980bby selsta+1−11 file
No security note in commit
Moderate 59 AI analysisMessage 45 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

updater: use proxy for signed hash downloads

This change fixes a privacy leak in the Monero GUI wallet's update checker. Previously, when the wallet checked for updates and downloaded the signed list of official file hashes, it did not route that request through the user's configured…

Privacy leak: update metadata fetch bypassed user-configured proxyProxy setting now propagated to signed hash download pathPotential deanonymization of users who rely on proxy for network privacy
5e5ea68fby selsta+19−67 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

p2pool v4.18

This commit simply updates the Monero GUI's built-in downloader to fetch a newer version (4.18) of the bundled P2Pool mining software. It changes download URLs and the expected file hashes to match the new release. There is no indication o…

ddd080e3by SChernykh+12−121 file
No security note in commit
Moderate 58 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Transfer: disable offline signing for hardware wallets

This commit removes the 'Sign (offline)' button for hardware wallets in the Monero GUI wallet. The change prevents users from attempting an unsupported operation that could lead to failed or unsafe transactions when using a Ledger/Trezor-l…

UI control disabled for hardware-wallet-backed walletsReported by external party (zkao / zkSecurity)Prevents use of an operation likely unsupported by hardware wallet signing flow
66fab82cby selsta+1−11 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: simplify restore QR scanner layout

This commit is a straightforward user-interface cleanup in the Monero wallet restore wizard. It replaces a third radio-button option ('Restore from QR Code') with a dedicated QR scan button, simplifying the layout. There is no security-rel…

88324856by selsta+14−151 file
No security note in commit
Low 27 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: support key-based monero-wallet restore QR codes

This commit adds a feature to the Monero GUI wallet that lets users scan a QR code to restore a wallet from its secret keys. The change itself is a feature addition, not a direct security fix. However, it handles extremely sensitive data (…

Parsing of URI-encoded secret key material from QR codesManual URI/query-string parsing instead of using a hardened parserUse of decodeURIComponent on untrusted QR code data
a33f2421by selsta+52−13 files
No security note in commit
Informational 23 AI analysisMessage 68 · Adequate
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: fix restore from QR code

This commit fixes a broken feature in the Monero wallet's setup wizard that restores a wallet by scanning a QR code. The feature had been completely non-functional since a prior redesign because the code that processes the scanned QR code …

No security-relevant signals in the diff or commit messageFixes a broken user-facing feature (restore from QR code)Adds null-safety for extra_parameters to prevent crashes on bare-address QR codes
fbe4c084by Thomas+18−252 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

tests: add QML wallet wizard coverage

This commit adds automated user-interface tests for the Monero wallet setup wizard. It does not change how real users create or open wallets; it only adds test code and exposes a few internal UI control names so the tests can interact with…

0eef8dacby selsta+686−217 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityworkflows: update checkout and upload-artifact to v7by selsta · a88f8070 · Jul 19, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · selsta

workflows: update checkout and upload-artifact to v7

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
Lower-priorityoshelper: wait for hidden window before taking screenshot on macOSby selsta · 62d0a59c · Jul 19, 2026 · 1 fileMessage 65 · AdequateTriage 0Details
Commit message · selsta

oshelper: wait for hidden window before taking screenshot on macOS

Also improve error message and add a missing include.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Lower-prioritymain: init logs on startupby selsta · 03996459 · Jul 19, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · selsta

main: init logs on startup

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedwizard: fix restore from QR codeby Thomas · fbe4c084 · Jul 19, 2026 · 2 filesMessage 68 · AdequateInformational 23Details
Commit message · Thomas

wizard: fix restore from QR code

updateFromQrCode lived in Wizard.js, a .pragma library script with no
access to QML scope, so every scan aborted on its first statement and
filled nothing. Broken since the wizard redesign (f329a710); the function
also still referenced pre-redesign items that no longer exist.

Move it into WizardRestoreWallet1.qml next to the fields it fills, switch
to the keys form so the scanned values are visible, and handle the null
extra_parameters emitted for bare-address QR codes.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit fixes a broken feature in the Monero wallet's setup wizard that restores a wallet by scanning a QR code. The feature had been completely non-functional since a prior redesign because the code that processes the scanned QR code was placed in a JavaScript library that cannot access the wizard's user-interface elements. The patch moves that code into the correct wizard page, updates it to use the current user-interface elements, and safely handles QR codes that contain only an address with no extra key data. This is a straightforward bug fix with no clear security relevance.

Lower-prioritybuild: prepare v0.18.5.2by selsta · 4403cf56 · Jul 16, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · selsta

build: prepare v0.18.5.2

50/100 · ThinMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedtests: add QML wallet wizard coverageby selsta · 0eef8dac · Jul 16, 2026 · 17 filesMessage 55 · ThinInformational 15Details
Commit message · selsta

tests: add QML wallet wizard coverage

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds automated user-interface tests for the Monero wallet setup wizard. It does not change how real users create or open wallets; it only adds test code and exposes a few internal UI control names so the tests can interact with wizard pages. There is no security fix or vulnerability here.

AI review queuedwizard: only validate custom wallet locationsby selsta · 3e800edd · Jul 16, 2026 · 2 filesMessage 60 · AdequateInformational 24Details
Commit message · selsta

wizard: only validate custom wallet locations

Also show the wallet location selector in all wallet modes and
use the selected path when creating a wallet.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit changes the Monero GUI wallet creation wizard so that users always see and can edit the wallet save location, regardless of which wallet mode they chose. Previously, the location field was hidden in simpler modes and the wallet was saved to a default folder. The change also stops validating whether the default folder is writable, only checking custom locations. This is a user-experience and correctness fix rather than a clear security patch, though it removes a minor validation inconsistency.

Security candidateReceive: fix stale subaddress selection after switching accountsby Cole Munz · 6cbdb9f3 · Jul 15, 2026 · 1 fileMessage 73 · AdequateLow 25Details
Commit message · Cole Munz

Receive: fix stale subaddress selection after switching accounts

subaddressListView.currentIndex was only reset when it equaled -1
(the initial sentinel), so switching to an account with fewer
addresses left the Receive page showing the old index and its label
while the QR/address itself already reflected the new account's
primary address. onPageCompleted also hardcoded index 0 when setting
current_address instead of using the selected index, so the shown
address could disagree with the selected row's label even within the
same account after revisiting the page.

Validate currentIndex against the current account's address count on
page load, and share the address/label sync logic between the
selection handler and onPageCompleted so both stay consistent.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
defensive validationprivacy or spend-authorization protocol
AI analysis · Low 25/100

This is a user-interface bug fix in the Monero wallet's Receive page. When a user switched between accounts, the page could show a label and QR code from one account while the displayed address belonged to another account, because the selected list row was not updated to match the new account. The fix makes sure the selected row and displayed address/label stay in sync. It is a consistency bug, not a cryptographic or network vulnerability.

AI review queuedwizard: create wallets in memoryby selsta · daec1dbf · Jul 15, 2026 · 5 filesMessage 45 · ThinModerate 59Details
Commit message · selsta

wizard: create wallets in memory

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This change alters the Monero GUI wallet setup wizard so that newly created or recovered wallets are kept only in memory, rather than being written to a temporary file on disk during the setup process. The old approach created temporary wallet files on the computer's storage and then deleted them after the user finished the wizard. The patch removes the code that created and cleaned up those temporary files. This is a defensive improvement: it reduces the chance that an unfinished or temporary wallet file containing sensitive data is left behind on disk, exposed to other users, recovered by forensic tools, or leaked through backups, swap files, or file indexing. The change also adds a small UI guard so the wizard cannot be interacted with while a hardware-device wallet is being created asynchronously.

AI review queuedworkflows: drop requests dependency from p2pool hash verificationby Thomas · 0575b7d6 · Jul 15, 2026 · 1 fileMessage 83 · StrongInformational 21Details
Commit message · Thomas

workflows: drop requests dependency from p2pool hash verification

857f0bc6 moved the p2pool-hashes job to the ubuntu-slim runner, which
does not ship the requests module, so the check fails with
ModuleNotFoundError for every pull request touching P2PoolManager.cpp.
Use urllib from the standard library for the single API call instead.

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
defensive validationdocumentation-only discountsecond-pass: broader security terminology
AI analysis · Informational 21/100

This commit fixes a broken GitHub workflow script that verifies P2Pool software hashes. The script previously used the third-party 'requests' library, which is not installed on the slim Ubuntu runner used by the project. The change switches to Python's built-in 'urllib' library so the automated check can run again. It is a reliability/maintenance fix, not a security vulnerability patch.

AI review queuedmakefile: remove unused variableby jpk68 · 7d384cd2 · Jul 14, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · jpk68

makefile: remove unused variable

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply removes an unused Makefile variable called 'deldirs'. There is no change to compiled code, no security fix, and no user-facing behavior change.

AI review queuedlibwalletqt: fix potential out-of-bounds readby jpk68 · 68a83e2a · Jul 14, 2026 · 1 fileMessage 45 · ThinLow 38Details
Commit message · jpk68

libwalletqt: fix potential out-of-bounds read

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 38/100

This commit fixes a bug in the Monero GUI wallet where three functions that read transaction details could access memory beyond the bounds of an internal list when the list is empty. The old check used 'index > size - 1', which underflows when the list is empty (size 0), so the guard failed and the code could read from an invalid position. The new check 'index >= size' is safe even when the list is empty. This is a defensive fix that prevents a potential crash or reading of unintended data when the wallet processes an unsigned transaction with no outputs or fees recorded.

AI review queuedFix precision loss when passing amounts from QMLby selsta · f9c378f0 · Jul 14, 2026 · 7 filesMessage 45 · ThinLow 34Details
Commit message · selsta

Fix precision loss when passing amounts from QML

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit fixes a precision-loss bug when the Monero GUI wallet passes payment amounts from the user interface (QML) to the underlying wallet code. Previously, amounts were converted too early from human-readable XMR strings into 64-bit integers, which could silently drop very small fractions of a Monero amount. The patch moves the conversion into the C++ backend where the wallet's own parsing function is used, preserving precision. This mainly affects QR-code/payment URIs and reserve proofs, not a remote exploit.

Security candidateMerge pull request #4192by tobtoht · 7b286f48 · Jul 14, 2026 · 503 filesMessage 51 · ThinInformational 15Details
Commit message · tobtoht

Merge pull request #4192

53b5fa1 fix overlap in certain languages (SNeedlewoods)

ACKs: jpk68, selsta

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
seed or entropy pathsigning or wallet pathboot or update pathauthentication pathparser or protocol pathmerge-commit duplicate discount
AI analysis · Informational 15/100

This commit is a large merge of pull request #4192 into the Monero GUI repository. The actual code change within that PR is a single, minor user-interface fix by contributor SNeedlewoods to prevent text overlap in certain languages. The rest of the diff is the initial population of the repository with the full Monero GUI source tree, build files, translations, images, and CI workflows. There is no security-relevant code change here.

AI review queuedWizardController: abort saving the wallet if setPassword failsby plowsof · dabf4178 · Jul 11, 2026 · 3 filesMessage 65 · AdequateModerate 59Details
Commit message · plowsof

WizardController: abort saving the wallet if setPassword fails

WizardController: set password for restored temp wallet

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This commit fixes a flaw in the Monero GUI wallet creation and restore wizard. Previously, when restoring or creating a wallet from keys, the temporary wallet was created with a blank password. If setting the user's chosen password later failed, the wizard would still save the wallet—leaving it protected by the blank password instead of the intended one. The change ensures the temporary wallet gets a random password and that the wizard aborts saving if the real password cannot be set.

AI review queuedsrc: fix boolean QJSValueList constructionby selsta · 7884edfb · Jul 10, 2026 · 2 filesMessage 60 · AdequateInformational 23Details
Commit message · selsta

src: fix boolean QJSValueList construction

Qt 6 interprets boolean values as QList sizes, causing
callbacks to receive undefined. Construct QJSValue explicitly.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit fixes a Qt 6 compatibility bug in the Monero GUI wallet. In Qt 6, passing a plain true/false value into a JavaScript callback argument list was being misread as a list size, so the callback received 'undefined' instead of the actual result. The fix explicitly wraps each value as a QJSValue. This is a reliability/functional bug, not a security vulnerability: there is no evidence it can be exploited to steal funds, run code, or bypass protections.

Lower-prioritywizard: warn when adjusting kdf roundsby jpk68 · c5de80fe · Jul 10, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · jpk68

wizard: warn when adjusting kdf rounds

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-prioritypages/transfer: fix spacing in warning messageby jpk68 · cb4374a3 · Jul 9, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · jpk68

pages/transfer: fix spacing in warning message

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-prioritybuild: switch to Ninjaby selsta · 75363863 · Jul 6, 2026 · 7 filesMessage 40 · ThinTriage 0Details
Commit message · selsta

build: switch to Ninja

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
AI review queuedREADME: remove miniupnpby selsta · cfefbd3b · Jul 6, 2026 · 3 filesMessage 28 · OpaqueInformational 15Details
Commit message · selsta

README: remove miniupnp

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates documentation and build scripts to remove the miniupnpc library from the list of dependencies. It does not change any actual program code, so it cannot directly introduce or fix a security vulnerability in the software itself. It is a housekeeping change reflecting that the project no longer needs miniupnpc.

Lower-priorityTitleBar: fix signal calls with extra argumentsby selsta · 4ec2ecae · Jul 5, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · selsta

TitleBar: fix signal calls with extra arguments

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityworkflows: use ubuntu-slim for simple tasksby selsta · 857f0bc6 · Jul 5, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · selsta

workflows: use ubuntu-slim for simple tasks

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedREADME: remove libunwindby selsta · 4e01d389 · Jul 5, 2026 · 3 filesMessage 28 · OpaqueInformational 15Details
Commit message · selsta

README: remove libunwind

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply removes mentions of the libunwind library from build instructions and CI dependency lists. It is a documentation and build-configuration cleanup, not a code change. There is no indication of a security vulnerability being fixed.

Lower-priorityqml: fix maximize button icon stateby selsta · a693ebfe · Jul 5, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · selsta

qml: fix maximize button icon state

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-prioritymain: only create native menu bar on macOSby selsta · d68e63a3 · Jul 5, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · selsta

main: only create native menu bar on macOS

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body