Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit fixes nine separate bugs in the Monero Light Wallet Server (LWS). The most serious ones are: an infinite loop when importing certain address data, a missing size limit that let unauthenticated remote clients request huge amount…
Infinite loop in database import path (DoS)Missing authentication-time message size limit on remote scanner protocol (memory exhaustion / DoS)Untrusted array reads from client in light wallet RPC
This commit fixes a broken GitHub Actions workflow file that builds and publishes Docker images. It corrects a variable name (from 'platform' to 'arch') and adds a missing period at the end of the docker build command. There is no security…
This commit fixes a YAML indentation error in a GitHub Actions workflow file. It changes one line of spacing so the Docker login step is correctly aligned under the job's steps list. There is no security-relevant change to the software its…
This commit fixes a typo in a GitHub Actions workflow file. The Docker build command had an extra word ('build build') that would cause the automated Docker image build to fail. It is a routine CI/CD fix with no security relevance.
This commit fixes a GitHub Actions workflow syntax error. The 'matrix' keyword was missing its required parent 'strategy' wrapper, which would prevent Docker build jobs from running correctly. There is no security relevance in the code cha…
This commit is a routine compatibility update to keep the Monero Light Wallet Server (LWS) project building against recent changes in the upstream Monero codebase. It replaces a custom macro-based type declaration (POD_CLASS) with plain C+…
No security-relevant behavioral changes in the diffChanges are limited to forward-declaration style and missing header includesNo memory safety, cryptographic, input validation, or authorization changes observed
This commit fixes a type-casting mistake in the Monero Light Wallet Server's database code. The program was treating its own custom database context as a different, more generic context. That mismatch could corrupt internal accounting of a…
Wrong context cast in LMDB transaction cleanup (type confusion)Custom context reference counting could be corrupted by mismatched deleterLarge code removal reduces attack surface and eliminates duplicated LMDB wrappers
This commit fixes a simple syntax typo in a GitHub Actions workflow file. The condition that decides whether to add release tags had an extra closing brace, which would cause the workflow to fail parsing rather than run incorrectly. There …
This commit only updates the 'external/monero' git submodule pointer from one commit hash to another. No actual source code changes are shown in this repository's diff. The title and message are generic ('Latest master') and give no indica…
This commit fixes a bug in the Monero Light Wallet Server (LWS) where webhook notifications for mempool transactions could fail or behave incorrectly when scanning subaddresses. The change passes an existing database reader into the output…
Fixes a read-transaction lifecycle issue in webhook lookup during mempool scanningAdds regression test covering mempool publication + webhook deliveryCallback signature change propagates an existing storage_reader to avoid nested/duplicate reads
This commit simply adds a new GPG public key file to the repository. A GPG public key is used to verify that future releases or commits were genuinely signed by the project maintainer. There is no code change, no vulnerability, and no secu…
This commit is a routine build/maintenance change that adjusts which version of the external Monero dependency is pinned. There is no indication of any security fix, vulnerability, or user-facing behavior change. It is essentially a housek…
This commit appears to change which version of an external Monero component the project points to (a so-called 'git submodule pin' or dependency reference). The title says it fixes the pin for 'external/master' back to the 'master' branch.…
This commit fixes a database-handling bug in Monero Light Wallet Server (LWS). The bug caused the server to permanently miss some subaddress outputs because a read transaction was not closed before a new one was opened, triggering an LMDB …
Fixes LMDB transaction-slot error (MDB_BAD_RSLOT)Prevents permanently missed subaddress outputsChanges test expectations to reflect recovered output
This commit fixes a math mistake when checking whether a user requested too many Monero subaddresses. The original code divided two numbers and compared the result to a maximum, which is the wrong way to detect overflow and could allow the…
Integer overflow check corrected from an inverted/incorrect comparison to a canonical safe division pre-checkOccurs in subaddress limit enforcement, which is a security boundary against excessive address derivationSame bug pattern present in two independent locations (storage and REST server)
This commit simply changes a version string from '1.0-alpha' to '1.1-alpha' in a single source file. There is no functional code change, no bug fix, and no security relevance visible in the diff or commit message.
This commit changes one character in the documentation configuration file (mkdocs.yml), adding a trailing slash to the site description. It does not touch any program code, cryptographic logic, network handling, or user data. There is no s…
This commit is a routine documentation-site fix. It changes how the MkDocs documentation builder is invoked in a GitHub Actions workflow (from `python3 mkdocs build` to `python3 -m mkdocs build`) and fixes a typo in the site description. T…
This commit makes a trivial wording change to the project's documentation configuration file, adding a slash to the site description. There is no security relevance.
This commit adds mempool (pending transaction) support to Monero Light Wallet Server. It lets users see unconfirmed transactions through the /get_address_txs REST endpoint and the live /feed websocket. The change also refactors how the ser…
Large feature commit (+1906/-634) touching REST, WebSocket feed, scanner, and new mempool componentRefactored transaction ownership scanning into shared ownership_test helper; reduces duplicated crypto/derivation logicMempool transactions are parsed and validated before being added to the local cache in /submit_raw_tx
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
Lower-priorityFix ARCH flag in upstream monero to default for safest compilation (#299)by Lee *!* Clagett · 50992465 · Oct 1, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Fix ARCH flag in upstream monero to default for safest compilation (#299)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
Lower-priorityAdd arm64 to CI AND do 'real' beginning build with submoduled monero (#298)by Lee *!* Clagett · eb74eb08 · Sep 30, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Add arm64 to CI AND do 'real' beginning build with submoduled monero (#298)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
Security candidateFixes for issues reported by llm (#297)by Lee *!* Clagett · 81451fb2 · Sep 30, 2026 · 9 filesMessage 81 · StrongHigh 71Details
Commit message · Lee *!* Clagett
Fixes for issues reported by llm (#297)
* Fix infinite loop when importing lookahead address with {0,0} output * Fix zero threads on client * Restrict remote scanner client message sizes until authentication * Fix untrusted array (users, blocks) reads from client * Fix overflow check * Harden gamma picker * Add check for relayed flag before adding to mempool list * Fix double response on tx parse error * Fix erase call in remote scanning round-robin algo * Fix mempool metadata in pessimistic state
81/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
access controlmemory safetydefensive validationsigning or wallet path
AI analysis · High 71/100
This commit fixes nine separate bugs in the Monero Light Wallet Server (LWS). The most serious ones are: an infinite loop when importing certain address data, a missing size limit that let unauthenticated remote clients request huge amounts of memory, reading untrusted array data from clients before proper validation, an incorrect overflow check when calculating subaddress counts, and a double HTTP response that could confuse clients. Several other fixes correct thread handling, mempool behavior, and a round-robin scheduling erase bug. The commit title says these issues were 'reported by llm'—likely an automated or large-language-model-assisted review—so the security relevance is acknowledged by the project author but not via a formal vendor security advisory.
Lower-priorityDisable provenance in Docker GH action (needed for custom manifest)by Lee *!* Clagett · 0111c696 · Sep 30, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Disable provenance in Docker GH action (needed for custom manifest)
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
This commit fixes a broken GitHub Actions workflow file that builds and publishes Docker images. It corrects a variable name (from 'platform' to 'arch') and adds a missing period at the end of the docker build command. There is no security issue here—just a routine build script repair.
This commit fixes a YAML indentation error in a GitHub Actions workflow file. It changes one line of spacing so the Docker login step is correctly aligned under the job's steps list. There is no security-relevant change to the software itself.
Lower-priorityAdding manifest to group buildsby Lee *!* Clagett · afbb8fc6 · Sep 30, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Adding manifest to group builds
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
This commit fixes a typo in a GitHub Actions workflow file. The Docker build command had an extra word ('build build') that would cause the automated Docker image build to fail. It is a routine CI/CD fix with no security relevance.
This commit fixes a GitHub Actions workflow syntax error. The 'matrix' keyword was missing its required parent 'strategy' wrapper, which would prevent Docker build jobs from running correctly. There is no security relevance in the code change itself.
Lower-prioritySpeedup arm64 docker build by using built-in arm64 runnerby Lee *!* Clagett · 022e814c · Sep 30, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Speedup arm64 docker build by using built-in arm64 runner
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Bypass checkpoint gate for regtest chain reorgs (#286)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityAdd Ubuntu 26.04 to CI (#291)by Lee *!* Clagett · 6d05ca3b · Sep 18, 2026 · 4 filesMessage 78 · AdequateTriage 0Details
Commit message · Lee *!* Clagett
Add Ubuntu 26.04 to CI (#291)
* Add Ubuntu 26.04 to CI
* Add waiting/synchronization to test threads
78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
AI review queuedChanges required due to upstream monero changes (#290)by Lee *!* Clagett · fee43d23 · Sep 18, 2026 · 5 filesMessage 70 · AdequateInformational 12Details
Commit message · Lee *!* Clagett
Changes required due to upstream monero changes (#290)
70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100
This commit is a routine compatibility update to keep the Monero Light Wallet Server (LWS) project building against recent changes in the upstream Monero codebase. It replaces a custom macro-based type declaration (POD_CLASS) with plain C++ struct forward declarations and adds a few missing standard library header includes. There is no indication in the commit that any security vulnerability is being fixed.
Lower-priorityUpdate unbound and expat (in Dockerfile) to newest releasesby Lee Clagett · cb41b245 · Sep 16, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Lee Clagett
Update unbound and expat (in Dockerfile) to newest releases
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedFix LMDB (wrong) context cast, and remove now unnecessary LMDB code (#287)by Lee *!* Clagett · eef10334 · Aug 26, 2026 · 9 filesMessage 58 · ThinLow 32Details
Commit message · Lee *!* Clagett
Fix LMDB (wrong) context cast, and remove now unnecessary LMDB code (#287)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 32/100
This commit fixes a type-casting mistake in the Monero Light Wallet Server's database code. The program was treating its own custom database context as a different, more generic context. That mismatch could corrupt internal accounting of active readers/writers or cause the wrong cleanup code to run when a database transaction ends. The patch also removes a lot of now-redundant LMDB wrapper code and switches the project to use its own dedicated transaction and cursor types so the mistake cannot recur in the same way.
Lower-priorityUpdate Dockerfile to download+use unbound 25.5.2by Lee Clagett · 1ffb2526 · Aug 17, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Lee Clagett
Update Dockerfile to download+use unbound 25.5.2
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityUpdate libexpat and boost in Docker builds (#284)by Lee *!* Clagett · 894cc92d · Aug 13, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Update libexpat and boost in Docker builds (#284)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityUpdating CI dependencies for upstream Monero rust/cargo inclusion (#285)by Lee *!* Clagett · 0d92551b · Aug 13, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Updating CI dependencies for upstream Monero rust/cargo inclusion (#285)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedFix docker conditionalby Lee *!* Clagett · cbf6f328 · Aug 8, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett
Fix docker conditional
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit fixes a simple syntax typo in a GitHub Actions workflow file. The condition that decides whether to add release tags had an extra closing brace, which would cause the workflow to fail parsing rather than run incorrectly. There is no security issue here.