MJ
← All projectsmonero-java

monero-java

Java SDK for Monero daemon, wallet RPC, and native client-side wallets.

Cryptographic librariesMoneroSoftware walletsNormal
Repository coverage

122 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

6security candidates58second-pass queue64AI analyses
26commits · 30 days
43commits · 60 days
95commits · 180 days
122commits · 365 days
Backfill bands
Sep 27 → Mar 3127 seen2 candidatesComplete
Mar 31 → Jul 2949 seen3 candidatesComplete
Jul 29 → Aug 2815 seen0 candidatesComplete
Aug 28 → Sep 2719 seen1 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

57/100 average clarity
14Strong · 80–100
41Adequate · 60–79
51Thin · 40–59
16Opaque · 0–39
1security candidate with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
woodser120563058
everoddandeven211051
Analysis record

Published AI watches

Last scanned 11 minutes ago

Informational 24 AI analysisMessage 50 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: send amounts to wallet rpc as json numbers for v0.18.5.3

This commit changes how the Java wallet library sends monetary amounts to the Monero wallet RPC server. Previously, amounts were converted to strings before being sent; now they are sent as JSON numbers. This is a compatibility fix for Mon…

Data type mismatch between client and RPC server could lead to failed or misinterpreted transactionsAmount handling changes in transaction creation and reserve proof generation pathsNo input validation or bounds checks added in the patch
6d0cd696by woodser+3−31 file
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

docs: update api docs

This commit only updates generated Java API documentation (Javadoc HTML files). It adds descriptions explaining how SSL/TLS certificate verification works when connecting to a Monero daemon. No actual program code was changed, so this comm…

f93bae8eby woodser+17−45 files
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

ci: run TLS regression tests

This commit only changes the project's automated build configuration to run a few extra tests during continuous integration. It does not modify any application code, libraries, or user-facing behavior. There is no security fix or vulnerabi…

8c6f97c0by woodser+3−31 file
No security note in commit
Moderate 59 AI analysisMessage 60 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: propagate TLS verification to native and RPC wallets

This commit fixes how Java wallet code passes TLS/SSL certificate verification settings down to the underlying native Monero wallet and to RPC wallets. Previously, the Java layer could request 'verify the certificate' or 'allow any certifi…

TLS/SSL verification preference now propagated across JNI to native walletRPC wallet now translates connection sslVerify into ssl_allow_any_cert and ssl_support parametersConnection equality/hashCode now includes sslVerify, preventing silent mismatches
43c2a9ecby woodser+240−4010 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

docs: update api docs

This commit only updates generated API documentation (Javadoc HTML files). It does not change any actual program code, so it cannot introduce or fix a security vulnerability on its own.

bf0ac8c3by woodser+278−2317 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: isolate key image import test

This commit only changes a test file. It rewrites one wallet test so that it uses a separate offline wallet instead of importing outputs back into the same wallet. There is no change to production code and no security fix or vulnerability …

86567073by woodser+16−151 file
No security note in commit
Informational 15 AI analysisMessage 75 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: sync balances before multi-destination sends

This commit only changes a test file. It makes a wallet test wait for mining to stop and sync balances before checking send results. There is no change to production wallet code, no user-facing behavior change, and no security fix.

e6fd994cby woodser+4−01 file
No security note in commit
Informational 23 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: retain unlock notifications after long polling gaps

This change fixes a bug in a Monero wallet's long-polling notification system. Previously, if there was a long gap between polls, the wallet could use a height bound that was too recent and miss transactions that had since unlocked. The fi…

Functional bug in wallet notification logicPotential missed unlock notifications after polling gapsNo cryptographic, authentication, or input-validation changes
7a1a3af4by woodser+6−21 file
No security note in commit
Informational 14 AI analysisMessage 75 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: synchronize notification balances before sending

This commit only changes a test file. It makes the wallet notification tests more reliable by syncing balances before sending and ensuring mining, listeners, and temporary wallets are cleaned up even if the test fails. There is no change t…

555c973bby woodser+237−2071 file
No security note in commit
Low 35 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: reset snapshots when switching wallets

This commit fixes a lifecycle bug in the Monero Java wallet library. When a user switches from one wallet to another, background polling and notification threads could keep running with stale data from the previous wallet. The patch adds g…

stale callback invalidation across wallet lifecycle changesgeneration-counter pattern to prevent use of stale snapshotsbackground poller and ZMQ listener reset on wallet clear/switch
2bdc3fc8by woodser+105−322 files
No security note in commit
Low 26 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: restore callbacks when reopening wallets

This commit fixes a state-tracking bug in a Monero wallet library. When a wallet client object was reused to open or create another wallet, an internal 'closed' flag was not reset. This could leave event/callback listeners disabled on the …

State-management bug in wallet lifecycleMissing reset of closed flag on reused RPC clientPotential loss of transaction/sync callbacks after wallet reopen
e6a5b8d5by woodser+2−01 file
No security note in commit
Informational 15 AI analysisMessage 83 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: wait for wallet pending state before equality

This commit only changes test code. It makes wallet equality tests wait for pending transactions to fully clear from the wallets' own state before comparing balances and rescanning spent outputs. There is no change to production wallet log…

eb72c61cby woodser+5−52 files
No security note in commit
Informational 14 AI analysisMessage 60 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: mine to height before checking sync notifications

This commit only changes test code. It refactors how a Monero wallet test waits for a new block by introducing a helper that mines until a specific blockchain height is reached, instead of starting mining and waiting for the next block in …

4f38f454by woodser+33−272 files
No security note in commit
Low 43 AI analysisMessage 68 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet full: cancel native calls before closing

This commit hardens how the Java Monero wallet shuts down. It makes sure background native (C++) calls are cancelled and finish before the wallet is freed, and it protects listener cleanup from running at the same time as notifications. Th…

Use-after-free / double-free risk in close pathRace condition between native listener callbacks and wallet destructionCross-thread JNIEnv handling in JNI listener destructor
e949b9e1by woodser+123−576 files
No security note in commit
Informational 22 AI analysisMessage 73 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: announce missed confirm transition when tx unlocks between polls

This commit fixes a notification bug in a Monero wallet library. Previously, if a transaction both confirmed and became unlocked between two polling checks (which can happen during fast block times), the wallet would only announce the 'unl…

No security-relevant signals present in commit message or diffChange is a state-transition notification ordering fixNo input validation, cryptographic, authorization, or memory-safety changes
37bfe4a5by woodser+6−01 file
No security note in commit
Informational 17 AI analysisMessage 95 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test: update offline wallet expectations for ungated daemon calls

This commit only changes test code. It updates the expected behavior of an offline Monero wallet so that certain daemon-related calls no longer throw a 'not connected' error. The underlying wallet behavior was already changed elsewhere; th…

Test-only changeError message masking from untrusted daemons mentioned in commentBehavior alignment with monero-wallet-rpc auto_refresh
5eb65343by woodser+4−51 file
No security note in commit
Informational 15 AI analysisMessage 95 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test: update sync progress tests for throttled progress with hash-skip reporting

This commit only updates test code to match a new wallet behavior where sync progress notifications are throttled and may report a temporary 'hash-skip' phase. There are no product code changes, no bug fixes, and no security-relevant behav…

9872555aby woodser+20−151 file
No security note in commit
Moderate 59 AI analysisMessage 73 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: prevent close from freeing wallet during in-flight calls

This commit fixes a race condition in a Monero wallet Java library. Previously, calling close() on a wallet could free the underlying native wallet memory while other operations were still running, which could cause crashes or unpredictabl…

Race condition between wallet close() and in-flight native callsPotential use-after-free of C++ wallet handle (jniWalletHandle)New read/write locking around all JNI wallet operations
5c01e76cby woodser+883−4682 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 55 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test correct restore heights after closing wallet

This commit only updates test expectations in a Java test file. It changes three comments/assertions so that the test now expects a wallet's restore height to be remembered after closing, rather than expecting it to be lost. There is no pr…

246ab28dby woodser+3−31 file
No security note in commit
Informational 23 AI analysisMessage 50 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: bound getTxs re-fetch on inconsistency

This change fixes a potential infinite recursion bug in the Monero wallet RPC client. Previously, when the software detected inconsistent transaction data from multiple RPC calls, it would repeatedly re-fetch the data forever. Now it limit…

Unbounded recursion / retry loop replaced with bounded retry limitPotential denial of service via stack overflow or unresponsive wallet RPC clientError handling added for unresolvable data inconsistency
8c7dcc35by woodser+7−21 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedbump version to v0.8.40by woodser · 2b6e83e5 · Dec 4, 2025 · 3 filesMessage 38 · OpaqueInformational 15Details
Commit message · woodser

bump version to v0.8.40

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine version bump from 0.8.39 to 0.8.40. It updates the version number in the README, Maven project file, and a Java source file. There are no code changes that affect security or functionality.

AI review queuedupdate donation messageby woodser · 3a07fb72 · Dec 4, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · woodser

update donation message

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes the wording of a donation request in the README file. It is a routine documentation edit with no security relevance.

AI review queuedupdate donation messageby woodser · 2c0a6e24 · Dec 4, 2025 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · woodser

update donation message

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only rewords a donation message in the README. It is a non-functional documentation change with no security relevance.

AI review queuedupdate libsby woodser · 1b3b8bc8 · Oct 14, 2025 · 13 filesMessage 0 · OpaqueInformational 0Details
Commit message · woodser

update libs

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 0/100

This commit only replaces precompiled binary library files (such as .so, .dylib, and .dll files) across multiple operating systems and architectures. The commit message simply says 'update libs' and provides no explanation of why the libraries were updated. Because these are binary files, the actual code changes inside them cannot be seen in the diff. There is no direct evidence in the commit or supplied references that this update fixes or introduces a security issue.

AI review queuedupdate javadocsby woodser · c146d234 · Oct 14, 2025 · 12 filesMessage 18 · OpaqueInformational 15Details
Commit message · woodser

update javadocs

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathdocumentation-only discountsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only regenerates the project's Java API documentation (Javadocs). It does not change any actual program code, so it cannot introduce or fix a security vulnerability on its own.

AI review queuedbump version to v0.8.39by woodser · 43a3c35b · Oct 14, 2025 · 3 filesMessage 38 · OpaqueInformational 15Details
Commit message · woodser

bump version to v0.8.39

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine version bump from 0.8.38 to 0.8.39. It updates the library version number in three files: the project build file (pom.xml), the README documentation, and a Java source file that reports the library version. There is one minor typo in the README where a version is written as 0.8.9 instead of 0.8.39, but that is just a documentation mistake and not a security issue. No code behavior changes are present.

AI review queuedset daemon proxy by setting daemon connectionby woodser · 48712254 · Oct 14, 2025 · 11 filesMessage 45 · ThinInformational 12Details
Commit message · woodser

set daemon proxy by setting daemon connection

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit is a routine feature refactor, not a security fix. It changes how Tor proxy settings are configured in the monero-java library so that the proxy URI is bundled together with the daemon connection object instead of being set separately. There is no indication of a vulnerability being patched.

AI review queuedupdate spec pdfby woodser · a297d0f1 · Oct 14, 2025 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · woodser

update spec pdf

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates documentation files: a diagram source file and its exported PDF. It changes the 'last updated' date, the referenced Monero version number, and removes one method ('setProxyUri') from a wallet interface diagram. No executable code, build scripts, or configuration files were modified, so it cannot directly affect software security or be exploited.