MJ
← All projectsmonero-java

monero-java

Java SDK for Monero daemon, wallet RPC, and native client-side wallets.

Cryptographic librariesMoneroSoftware walletsNormal
Repository coverage

122 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

6security candidates58second-pass queue64AI analyses
26commits · 30 days
43commits · 60 days
95commits · 180 days
122commits · 365 days
Backfill bands
Sep 27 → Mar 3127 seen2 candidatesComplete
Mar 31 → Jul 2949 seen3 candidatesComplete
Jul 29 → Aug 2815 seen0 candidatesComplete
Aug 28 → Sep 2719 seen1 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

57/100 average clarity
14Strong · 80–100
41Adequate · 60–79
51Thin · 40–59
16Opaque · 0–39
1security candidate with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
woodser120563058
everoddandeven211051
Analysis record

Published AI watches

Last scanned 47 minutes ago

Informational 24 AI analysisMessage 50 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: send amounts to wallet rpc as json numbers for v0.18.5.3

This commit changes how the Java wallet library sends monetary amounts to the Monero wallet RPC server. Previously, amounts were converted to strings before being sent; now they are sent as JSON numbers. This is a compatibility fix for Mon…

Data type mismatch between client and RPC server could lead to failed or misinterpreted transactionsAmount handling changes in transaction creation and reserve proof generation pathsNo input validation or bounds checks added in the patch
6d0cd696by woodser+3−31 file
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

docs: update api docs

This commit only updates generated Java API documentation (Javadoc HTML files). It adds descriptions explaining how SSL/TLS certificate verification works when connecting to a Monero daemon. No actual program code was changed, so this comm…

f93bae8eby woodser+17−45 files
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

ci: run TLS regression tests

This commit only changes the project's automated build configuration to run a few extra tests during continuous integration. It does not modify any application code, libraries, or user-facing behavior. There is no security fix or vulnerabi…

8c6f97c0by woodser+3−31 file
No security note in commit
Moderate 59 AI analysisMessage 60 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: propagate TLS verification to native and RPC wallets

This commit fixes how Java wallet code passes TLS/SSL certificate verification settings down to the underlying native Monero wallet and to RPC wallets. Previously, the Java layer could request 'verify the certificate' or 'allow any certifi…

TLS/SSL verification preference now propagated across JNI to native walletRPC wallet now translates connection sslVerify into ssl_allow_any_cert and ssl_support parametersConnection equality/hashCode now includes sslVerify, preventing silent mismatches
43c2a9ecby woodser+240−4010 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

docs: update api docs

This commit only updates generated API documentation (Javadoc HTML files). It does not change any actual program code, so it cannot introduce or fix a security vulnerability on its own.

bf0ac8c3by woodser+278−2317 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: isolate key image import test

This commit only changes a test file. It rewrites one wallet test so that it uses a separate offline wallet instead of importing outputs back into the same wallet. There is no change to production code and no security fix or vulnerability …

86567073by woodser+16−151 file
No security note in commit
Informational 15 AI analysisMessage 75 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: sync balances before multi-destination sends

This commit only changes a test file. It makes a wallet test wait for mining to stop and sync balances before checking send results. There is no change to production wallet code, no user-facing behavior change, and no security fix.

e6fd994cby woodser+4−01 file
No security note in commit
Informational 23 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: retain unlock notifications after long polling gaps

This change fixes a bug in a Monero wallet's long-polling notification system. Previously, if there was a long gap between polls, the wallet could use a height bound that was too recent and miss transactions that had since unlocked. The fi…

Functional bug in wallet notification logicPotential missed unlock notifications after polling gapsNo cryptographic, authentication, or input-validation changes
7a1a3af4by woodser+6−21 file
No security note in commit
Informational 14 AI analysisMessage 75 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: synchronize notification balances before sending

This commit only changes a test file. It makes the wallet notification tests more reliable by syncing balances before sending and ensuring mining, listeners, and temporary wallets are cleaned up even if the test fails. There is no change t…

555c973bby woodser+237−2071 file
No security note in commit
Low 35 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: reset snapshots when switching wallets

This commit fixes a lifecycle bug in the Monero Java wallet library. When a user switches from one wallet to another, background polling and notification threads could keep running with stale data from the previous wallet. The patch adds g…

stale callback invalidation across wallet lifecycle changesgeneration-counter pattern to prevent use of stale snapshotsbackground poller and ZMQ listener reset on wallet clear/switch
2bdc3fc8by woodser+105−322 files
No security note in commit
Low 26 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: restore callbacks when reopening wallets

This commit fixes a state-tracking bug in a Monero wallet library. When a wallet client object was reused to open or create another wallet, an internal 'closed' flag was not reset. This could leave event/callback listeners disabled on the …

State-management bug in wallet lifecycleMissing reset of closed flag on reused RPC clientPotential loss of transaction/sync callbacks after wallet reopen
e6a5b8d5by woodser+2−01 file
No security note in commit
Informational 15 AI analysisMessage 83 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: wait for wallet pending state before equality

This commit only changes test code. It makes wallet equality tests wait for pending transactions to fully clear from the wallets' own state before comparing balances and rescanning spent outputs. There is no change to production wallet log…

eb72c61cby woodser+5−52 files
No security note in commit
Informational 14 AI analysisMessage 60 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: mine to height before checking sync notifications

This commit only changes test code. It refactors how a Monero wallet test waits for a new block by introducing a helper that mines until a specific blockchain height is reached, instead of starting mining and waiting for the next block in …

4f38f454by woodser+33−272 files
No security note in commit
Low 43 AI analysisMessage 68 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet full: cancel native calls before closing

This commit hardens how the Java Monero wallet shuts down. It makes sure background native (C++) calls are cancelled and finish before the wallet is freed, and it protects listener cleanup from running at the same time as notifications. Th…

Use-after-free / double-free risk in close pathRace condition between native listener callbacks and wallet destructionCross-thread JNIEnv handling in JNI listener destructor
e949b9e1by woodser+123−576 files
No security note in commit
Informational 22 AI analysisMessage 73 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: announce missed confirm transition when tx unlocks between polls

This commit fixes a notification bug in a Monero wallet library. Previously, if a transaction both confirmed and became unlocked between two polling checks (which can happen during fast block times), the wallet would only announce the 'unl…

No security-relevant signals present in commit message or diffChange is a state-transition notification ordering fixNo input validation, cryptographic, authorization, or memory-safety changes
37bfe4a5by woodser+6−01 file
No security note in commit
Informational 17 AI analysisMessage 95 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test: update offline wallet expectations for ungated daemon calls

This commit only changes test code. It updates the expected behavior of an offline Monero wallet so that certain daemon-related calls no longer throw a 'not connected' error. The underlying wallet behavior was already changed elsewhere; th…

Test-only changeError message masking from untrusted daemons mentioned in commentBehavior alignment with monero-wallet-rpc auto_refresh
5eb65343by woodser+4−51 file
No security note in commit
Informational 15 AI analysisMessage 95 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test: update sync progress tests for throttled progress with hash-skip reporting

This commit only updates test code to match a new wallet behavior where sync progress notifications are throttled and may report a temporary 'hash-skip' phase. There are no product code changes, no bug fixes, and no security-relevant behav…

9872555aby woodser+20−151 file
No security note in commit
Moderate 59 AI analysisMessage 73 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: prevent close from freeing wallet during in-flight calls

This commit fixes a race condition in a Monero wallet Java library. Previously, calling close() on a wallet could free the underlying native wallet memory while other operations were still running, which could cause crashes or unpredictabl…

Race condition between wallet close() and in-flight native callsPotential use-after-free of C++ wallet handle (jniWalletHandle)New read/write locking around all JNI wallet operations
5c01e76cby woodser+883−4682 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 55 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test correct restore heights after closing wallet

This commit only updates test expectations in a Java test file. It changes three comments/assertions so that the test now expects a wallet's restore height to be remembered after closing, rather than expecting it to be lost. There is no pr…

246ab28dby woodser+3−31 file
No security note in commit
Informational 23 AI analysisMessage 50 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: bound getTxs re-fetch on inconsistency

This change fixes a potential infinite recursion bug in the Monero wallet RPC client. Previously, when the software detected inconsistent transaction data from multiple RPC calls, it would repeatedly re-fetch the data forever. Now it limit…

Unbounded recursion / retry loop replaced with bounded retry limitPotential denial of service via stack overflow or unresponsive wallet RPC clientError handling added for unresolvable data inconsistency
8c7dcc35by woodser+7−21 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queueddocs: update javadocsby woodser · f7a4ce09 · Jul 27, 2026 · 21 filesMessage 40 · ThinInformational 15Details
Commit message · woodser

docs: update javadocs

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathdocumentation-only discountsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only updates generated Javadoc HTML documentation files. It does not change any source code, runtime behavior, or security logic. The visible differences are documentation additions for existing wallet API methods (such as trusted-daemon flags and key-image import/export) and regenerated index files. There is no security-relevant code change to assess.

AI review queuedwallet: export raw tx hex and tx keys from signTxs()by woodser · 3e3bd586 · Jul 27, 2026 · 2 filesMessage 73 · AdequateInformational 12Details
Commit message · woodser

wallet: export raw tx hex and tx keys from signTxs()

Signed txs always include raw full hex and tx keys, with the RPC wallet
requesting both for parity with jni.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit changes how a Monero wallet library requests data when signing transactions via RPC. It now explicitly asks the remote wallet to also return the raw transaction hex data and the transaction keys, matching behavior already present in the JNI wallet implementation. There is no direct evidence in the commit that this introduces a security vulnerability; it appears to be a parity/feature completeness change.

AI review queuedwallet: support explicit trusted daemon for full walletsby woodser · 95c69cad · Jul 25, 2026 · 7 filesMessage 73 · AdequateInformational 21Details
Commit message · woodser

wallet: support explicit trusted daemon for full wallets

Adds setDaemonConnection(connection, isTrusted) to MoneroWallet, wallet
config support, and isDaemonTrusted() for full wallets.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit adds a new option for users to explicitly tell a Monero wallet whether its connected daemon should be treated as 'trusted.' A trusted daemon can receive more sensitive data or perform more powerful operations than an untrusted one. The change is a feature addition that exposes an existing underlying wallet capability; it does not by itself create a vulnerability, but it makes it easier for users to accidentally or intentionally mark a remote daemon as trusted. That could increase the impact of other attacks if a user is tricked into trusting a malicious daemon.

AI review queuedtest: fix flaky reserve proof over-request (#6595)by woodser · 5bbcb829 · Jul 24, 2026 · 1 fileMessage 100 · StrongInformational 12Details
Commit message · woodser

test: fix flaky reserve proof over-request (#6595)

get_reserve_proof validates against the account's strict balance
(counts pending-spent outputs), so request the whole-wallet balance to
reliably exceed it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit only changes a test file to fix a flaky test. The test was requesting a reserve proof for an amount slightly above a single account's balance, but the underlying Monero wallet validates against a stricter 'whole-wallet' balance that includes pending-spent outputs. Because unconfirmed transactions can make the strict balance higher than the reported account balance, the old test sometimes failed to trigger the expected error. The fix requests an amount above the whole-wallet balance instead. There is no change to production code, no security vulnerability, and no user-facing behavior change.

AI review queuedtest: remove fixed segfault todosby woodser · e51a7e20 · Jul 23, 2026 · 1 fileMessage 67 · AdequateInformational 12Details
Commit message · woodser

test: remove fixed segfault todos

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit simply removes two comment lines in test code that said certain tests occasionally crashed on Apple Silicon Macs. No actual code behavior was changed, so it does not introduce or fix a security issue on its own. It only updates internal notes about previously observed test failures.

AI review queuedtest: aggregate send destinations by address instead of orderby woodser · 73ce5a15 · Jul 23, 2026 · 1 fileMessage 95 · StrongInformational 15Details
Commit message · woodser

test: aggregate send destinations by address instead of order

monero-project does not preserve destination order or splitting, so
testTxsWallet compares per-address totals rather than positionally.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes a test file. It updates how a Monero wallet test checks transaction destinations: instead of comparing each destination in the exact order it was sent, it now adds up the amounts sent to each address and compares the totals. This is a test-only adjustment to match how the upstream Monero software actually behaves, not a fix for a security problem in production code.

Security candidatetest: fix sending from subaddresses in single transactionby woodser · 3d8e696d · Jul 23, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · woodser

test: fix sending from subaddresses in single transaction

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · Informational 15/100

This commit changes one line in a test file. It fixes a test that checks sending Monero from multiple subaddresses in a single, unsplit transaction. Previously the test passed null (likely allowing default split behavior); now it explicitly disables transaction splitting. There is no change to production wallet code, no security fix, and no indication of a vulnerability.

AI review queuedfix: validate same proxy uri without scheme in wallet rpc (#151)by woodser · e46f579e · Jul 4, 2026 · 3 filesMessage 70 · AdequateInformational 22Details
Commit message · woodser

fix: validate same proxy uri without scheme in wallet rpc (#151)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Informational 22/100

This commit fixes a bug where the wallet RPC component treated the same proxy address as different if one version included a scheme prefix like 'socks5://' and the other did not. Previously, this caused an unnecessary error when setting a daemon connection. The fix normalizes proxy URIs before comparing them, so equivalent addresses are recognized as the same. It is a usability and correctness fix rather than a clear-cut security vulnerability.

AI review queuedignore sources field from wallet rpc transfer (#148)by woodser · d3a62760 · Jul 4, 2026 · 1 fileMessage 58 · ThinInformational 18Details
Commit message · woodser

ignore sources field from wallet rpc transfer (#148)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This is a tiny one-line change in a Java library that talks to the Monero cryptocurrency wallet. The library now explicitly ignores a new 'sources' field returned by the Monero wallet RPC when parsing transfer data. It prevents the parser from falling through to an 'unknown field' error or warning, but does not by itself fix a security vulnerability. It is best characterized as a compatibility/robustness update.

AI review queuedutils: add NetworkUtils.isLoopbackUrlby woodser · 2e27c087 · Jun 17, 2026 · 2 filesMessage 35 · OpaqueInformational 12Details
Commit message · woodser

utils: add NetworkUtils.isLoopbackUrl

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 12/100

This commit adds a new helper method to check whether a web address points to the same computer (a 'loopback' address like 127.0.0.1 or localhost). It is purely a utility addition with tests and does not change any existing behavior or fix a known bug on its own.

AI review queuedupdate javadocsby woodser · 79a31b13 · Jun 17, 2026 · 3 filesMessage 18 · OpaqueInformational 15Details
Commit message · woodser

update javadocs

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates generated Java API documentation files (javadocs). It adds an index entry and search index entry for a new utility method, isLoopbackUrl(), in the NetworkUtils class. There are no source code changes, no functional changes, and no security fixes or security-relevant behavior changes in this commit.

Security candidatedocs: update javadocsby woodser · 661cd5a7 · Jun 17, 2026 · 226 filesMessage 40 · ThinInformational 15Details
Commit message · woodser

docs: update javadocs

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathboot or update pathparser or protocol pathdocumentation-only discount
AI analysis · Informational 15/100

This commit only regenerates the project's Javadoc HTML documentation. It does not change any source code, build scripts, or runtime behavior. The documentation now reflects a new NetworkUtils helper class and marks an older MoneroUtils.parseUri method as deprecated, but these are already-existing code facts being documented, not new code changes.

AI review queuedcore: allow disabling TLS certificate verification on RPC connectionby woodser · aaf0dffd · Jun 17, 2026 · 1 fileMessage 60 · AdequateModerate 52Details
Commit message · woodser

core: allow disabling TLS certificate verification on RPC connection

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
defensive validationsecond-pass: broader security terminology
AI analysis · Moderate 52/100

This commit adds an optional switch that lets users turn off HTTPS/TLS certificate verification when the Java library connects to a Monero daemon or wallet RPC server. By default verification stays ON, so ordinary users are not affected. However, if a developer or user explicitly disables it, an attacker on the same network could intercept the connection with a fake certificate and steal passwords, transaction data, or manipulate RPC commands. The change also fixes IPv6 address handling when connecting through a SOCKS proxy.

AI review queueddocs: update javadocsby woodser · cdd1e143 · Jun 5, 2026 · 13 filesMessage 40 · ThinInformational 15Details
Commit message · woodser

docs: update javadocs

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathdocumentation-only discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only updates generated Javadoc HTML documentation files. It does not change any source code, runtime behavior, or fix any security issue. The visible additions are documentation entries for new method overloads and a new regtest configuration option that already exist in the codebase.

AI review queuedsupport regtest wallet config for jni wallet (#139)by woodser · 9b429dfe · May 30, 2026 · 6 filesMessage 58 · ThinInformational 20Details
Commit message · woodser

support regtest wallet config for jni wallet (#139)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit adds support for a 'regtest' (regression test) mode flag when opening or creating full wallets through the Java JNI bridge. Regtest is a private, sandboxed Monero network used for testing, similar to a practice environment. The change also explicitly blocks the regtest option for RPC wallets, where it is not supported. There is no direct security vulnerability in the diff itself; it is a feature addition for testing configuration. The main security consideration is that if a user mistakenly enables regtest on a mainnet wallet, it could cause confusion or incorrect behavior, but the code enforces that regtest can only be used with mainnet network type.

AI review queuedremove loop from change password test (#138)by woodser · 9c879cd6 · May 30, 2026 · 1 fileMessage 63 · AdequateInformational 13Details
Commit message · woodser

remove loop from change password test (#138)

63/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Informational 13/100

This commit removes a loop in a test that repeatedly changed a wallet password. The change is purely a test-code simplification and does not alter any production wallet logic. It is not a security fix.

AI review queuedsupport flag to skip refresh after multisig importby woodser · c97e9db4 · May 30, 2026 · 6 filesMessage 50 · ThinInformational 17Details
Commit message · woodser

support flag to skip refresh after multisig import

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit adds a new optional flag to the Monero wallet's multisig import function, letting callers choose whether the wallet automatically refreshes after importing multisig data. It is a straightforward API enhancement that preserves the previous default behavior (refresh enabled). There is no indication in the commit that this fixes a security bug or vulnerability.

AI review queuedcore: fix npe setting proxy with daemon connectionby woodser · 1921dbc6 · May 30, 2026 · 1 fileMessage 50 · ThinInformational 22Details
Commit message · woodser

core: fix npe setting proxy with daemon connection

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 22/100

This is a one-line bug fix for a NullPointerException (NPE) in the Java Monero wallet library. Before the fix, the code tried to read a proxy setting from a connection object without first checking whether the connection object existed. If no daemon connection was provided, the program would crash. The fix adds a simple null check. It is a defensive coding fix, not an obvious security vulnerability, though unhandled crashes can sometimes be abused to deny service or mask other behavior.

AI review queuedadd todos for jni tests which occasionally segfaultby woodser · 138b60b7 · May 30, 2026 · 1 fileMessage 60 · AdequateInformational 10Details
Commit message · woodser

add todos for jni tests which occasionally segfault

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 10/100

This commit only adds comments (TODOs) to two test methods and changes one test to repeat 15 times instead of once. It documents that two tests sometimes crash on Apple Silicon Macs but work on Intel, possibly due to JNI binaries. There is no code fix or security change.

AI review queuedbump version to v0.8.43by woodser · 3070c706 · Feb 17, 2026 · 3 filesMessage 38 · OpaqueInformational 15Details
Commit message · woodser

bump version to v0.8.43

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates the package version number from 0.8.42 to 0.8.43 in three files: the README, the Maven build file, and a Java source file that reports the library version. There are no code behavior changes, no bug fixes, and no security-related modifications.

AI review queuedset missing pool attribute to fix filtered databy woodser · 068352a6 · Feb 17, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · woodser

set missing pool attribute to fix filtered data

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a one-line bug fix in a Java library that talks to the Monero cryptocurrency wallet. The developer added a missing setting that marks confirmed transactions as no longer being in the memory pool (the waiting area for unconfirmed transactions). Without this setting, filters that ask 'show me only transactions still in the pool' could include already-confirmed transactions by mistake, leading to confusing or incorrect wallet data. There is no direct security attack shown in the commit itself.

AI review queuedfix tests to relay after creating txby woodser · c32ceade · Feb 16, 2026 · 1 fileMessage 55 · ThinInformational 15Details
Commit message · woodser

fix tests to relay after creating tx

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a small test-only change. The developer fixed three test methods so they correctly configure whether a transaction should be relayed immediately or created first and relayed separately. No production wallet code was changed, and there is no security issue here.

AI review queuedvalidate wallet proxy with startup proxyby woodser · 62458e08 · Feb 16, 2026 · 1 fileMessage 45 · ThinLow 45Details
Commit message · woodser

validate wallet proxy with startup proxy

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Low 45/100

This commit adds a check that prevents the wallet from later changing the proxy settings it was started with. If the wallet was launched with a proxy, any later attempt to set a different proxy (or no proxy) now throws an error instead of silently switching. This is a defensive hardening change that reduces the chance of traffic accidentally bypassing the intended proxy.

AI review queuedbump version to 0.8.42by woodser · 828be5a6 · Feb 16, 2026 · 3 filesMessage 38 · OpaqueInformational 15Details
Commit message · woodser

bump version to 0.8.42

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates the library's version number from 0.8.41 to 0.8.42 in three places: the README, the Maven build file, and a Java source file that returns the version string. There are no code behavior changes, no bug fixes, and no security-related modifications.

AI review queuedbump version to 0.8.41by woodser · a16c9cd1 · Jan 11, 2026 · 3 filesMessage 38 · OpaqueInformational 15Details
Commit message · woodser

bump version to 0.8.41

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine version bump from 0.8.40 to 0.8.41. It only updates version strings in the README, Maven project file, and a Java source file. There are no code logic changes, bug fixes, or security-related modifications.