Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit fixes nine separate bugs in the Monero Light Wallet Server (LWS). The most serious ones are: an infinite loop when importing certain address data, a missing size limit that let unauthenticated remote clients request huge amount…
Infinite loop in database import path (DoS)Missing authentication-time message size limit on remote scanner protocol (memory exhaustion / DoS)Untrusted array reads from client in light wallet RPC
This commit fixes a broken GitHub Actions workflow file that builds and publishes Docker images. It corrects a variable name (from 'platform' to 'arch') and adds a missing period at the end of the docker build command. There is no security…
This commit fixes a YAML indentation error in a GitHub Actions workflow file. It changes one line of spacing so the Docker login step is correctly aligned under the job's steps list. There is no security-relevant change to the software its…
This commit fixes a typo in a GitHub Actions workflow file. The Docker build command had an extra word ('build build') that would cause the automated Docker image build to fail. It is a routine CI/CD fix with no security relevance.
This commit fixes a GitHub Actions workflow syntax error. The 'matrix' keyword was missing its required parent 'strategy' wrapper, which would prevent Docker build jobs from running correctly. There is no security relevance in the code cha…
This commit is a routine compatibility update to keep the Monero Light Wallet Server (LWS) project building against recent changes in the upstream Monero codebase. It replaces a custom macro-based type declaration (POD_CLASS) with plain C+…
No security-relevant behavioral changes in the diffChanges are limited to forward-declaration style and missing header includesNo memory safety, cryptographic, input validation, or authorization changes observed
This commit fixes a type-casting mistake in the Monero Light Wallet Server's database code. The program was treating its own custom database context as a different, more generic context. That mismatch could corrupt internal accounting of a…
Wrong context cast in LMDB transaction cleanup (type confusion)Custom context reference counting could be corrupted by mismatched deleterLarge code removal reduces attack surface and eliminates duplicated LMDB wrappers
This commit fixes a simple syntax typo in a GitHub Actions workflow file. The condition that decides whether to add release tags had an extra closing brace, which would cause the workflow to fail parsing rather than run incorrectly. There …
This commit only updates the 'external/monero' git submodule pointer from one commit hash to another. No actual source code changes are shown in this repository's diff. The title and message are generic ('Latest master') and give no indica…
This commit fixes a bug in the Monero Light Wallet Server (LWS) where webhook notifications for mempool transactions could fail or behave incorrectly when scanning subaddresses. The change passes an existing database reader into the output…
Fixes a read-transaction lifecycle issue in webhook lookup during mempool scanningAdds regression test covering mempool publication + webhook deliveryCallback signature change propagates an existing storage_reader to avoid nested/duplicate reads
This commit simply adds a new GPG public key file to the repository. A GPG public key is used to verify that future releases or commits were genuinely signed by the project maintainer. There is no code change, no vulnerability, and no secu…
This commit is a routine build/maintenance change that adjusts which version of the external Monero dependency is pinned. There is no indication of any security fix, vulnerability, or user-facing behavior change. It is essentially a housek…
This commit appears to change which version of an external Monero component the project points to (a so-called 'git submodule pin' or dependency reference). The title says it fixes the pin for 'external/master' back to the 'master' branch.…
This commit fixes a database-handling bug in Monero Light Wallet Server (LWS). The bug caused the server to permanently miss some subaddress outputs because a read transaction was not closed before a new one was opened, triggering an LMDB …
Fixes LMDB transaction-slot error (MDB_BAD_RSLOT)Prevents permanently missed subaddress outputsChanges test expectations to reflect recovered output
This commit fixes a math mistake when checking whether a user requested too many Monero subaddresses. The original code divided two numbers and compared the result to a maximum, which is the wrong way to detect overflow and could allow the…
Integer overflow check corrected from an inverted/incorrect comparison to a canonical safe division pre-checkOccurs in subaddress limit enforcement, which is a security boundary against excessive address derivationSame bug pattern present in two independent locations (storage and REST server)
This commit simply changes a version string from '1.0-alpha' to '1.1-alpha' in a single source file. There is no functional code change, no bug fix, and no security relevance visible in the diff or commit message.
This commit changes one character in the documentation configuration file (mkdocs.yml), adding a trailing slash to the site description. It does not touch any program code, cryptographic logic, network handling, or user data. There is no s…
This commit is a routine documentation-site fix. It changes how the MkDocs documentation builder is invoked in a GitHub Actions workflow (from `python3 mkdocs build` to `python3 -m mkdocs build`) and fixes a typo in the site description. T…
This commit makes a trivial wording change to the project's documentation configuration file, adding a slash to the site description. There is no security relevance.
This commit adds mempool (pending transaction) support to Monero Light Wallet Server. It lets users see unconfirmed transactions through the /get_address_txs REST endpoint and the live /feed websocket. The change also refactors how the ser…
Large feature commit (+1906/-634) touching REST, WebSocket feed, scanner, and new mempool componentRefactored transaction ownership scanning into shared ownership_test helper; reduces duplicated crypto/derivation logicMempool transactions are parsed and validated before being added to the local cache in /submit_raw_tx
This commit adds a single configuration file named 'cname' to the docs folder. The file contains the custom domain name 'docs.monerolws.com' for GitHub Pages documentation hosting. It makes no code changes and has no security relevance.
AI review queuedFixing mkdocs build commandby Lee *!* Clagett · bcbf8999 · Mar 17, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett
Fixing mkdocs build command
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
This commit fixes a typo in an automated documentation publishing script. The previous command incorrectly tried to run mkdocs as a Python module (python3 mkdocs build), which would fail. The corrected command simply runs mkdocs build. There is no security issue here.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedPushing initial attempt at a docs siteby Lee *!* Clagett · b3ac4770 · Mar 17, 2026 · 19 filesMessage 45 · ThinInformational 15Details
Commit message · Lee *!* Clagett
Pushing initial attempt at a docs site
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a documentation-only change. It adds a new docs website for the monero-lws project, including Markdown guides, OpenAPI YAML specs, a GitHub Actions workflow to deploy the site, and a MkDocs configuration. No source code, build scripts, or runtime behavior of the application were modified. There is no security-relevant change in the software itself.
Lower-priorityFix minor spelling errors (#232)by jpk68 · fe3f4099 · Feb 2, 2026 · 2 filesMessage 53 · ThinTriage 0Details
Commit message · jpk68
Fix minor spelling errors (#232)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
Lower-priorityIncrease submit_raw_tx limits to 512 KiB (#227)by Lee *!* Clagett · e2bc477b · Jan 17, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Increase submit_raw_tx limits to 512 KiB (#227)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityVarious address assignment optimizations (#223)by Paul V Puey · 7465b2db · Jan 17, 2026 · 13 filesMessage 76 · AdequateTriage 0Details
Commit message · Paul V Puey
Various address assignment optimizations (#223)
* Add context to error logs * Implement block depth threading * Log thread work status * gitignore cache files * Add --min-block-depth flag * Allows user to set the minimum block depth of an address as used to calculate the work when distributing addresses to threads. * Alternate over/under allocating work to threads This ensures the last thread is closer to being evenly allocated compared to all the prior threads. * Add --split-sync-threads option * This options splits up threads into synced and unsynced classes * Improve logging of thread assignments * Add support for balance-new-addresses * Option will more intelligently distribute new addresses to threads with a scan height that closely matches that of the incoming address * fixup! Add support for balance-new-addresses * Fix scanner_options and program objects sort order
---------
Co-authored-by: William Swanson <swansontec@gmail.com>
76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Lower-priorityFix build with Boost 1.90by Lee *!* Clagett · dc84a173 · Jan 7, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Fix build with Boost 1.90
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityUpdate Dockerfile to boost 1.90by Lee *!* Clagett · 5caac960 · Jan 7, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Update Dockerfile to boost 1.90
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedAdd EXCLUDE_FROM_ALL for monero dependency (#221)by Lee *!* Clagett · f2b35340 · Dec 19, 2025 · 1 fileMessage 53 · ThinInformational 15Details
Commit message · Lee *!* Clagett
Add EXCLUDE_FROM_ALL for monero dependency (#221)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
This is a one-line build-system change that tells CMake not to automatically build every target from the bundled Monero dependency when building monero-lws. It only affects which build targets are included by default and does not change any executable code, network behavior, or cryptographic logic.
Security candidatelookahead optimization for users that disabled subaddresses (#220)by Lee *!* Clagett · 6c0b957e · Dec 19, 2025 · 1 fileMessage 58 · ThinInformational 12Details
Commit message · Lee *!* Clagett
lookahead optimization for users that disabled subaddresses (#220)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocol
AI analysis · Informational 12/100
This is a small performance optimization. When a user has disabled subaddresses, the scanner now skips a step that pre-generates future subaddress keys. This makes servers with subaddresses disabled run faster. There is no security problem visible in the change.
Lower-priorityFix divide by zero in db code (#219)by Lee *!* Clagett · 332c969c · Dec 18, 2025 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Fix divide by zero in db code (#219)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityA few odds and ends after lookahead patch (#215)by Lee *!* Clagett · 770e3b0c · Dec 18, 2025 · 6 filesMessage 53 · ThinTriage 0Details
Commit message · Lee *!* Clagett
A few odds and ends after lookahead patch (#215)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Security candidateAdd support for subaddress lookahead (#195)by Lee *!* Clagett · 16111cae · Dec 18, 2025 · 20 filesMessage 53 · ThinLow 39Details
Commit message · Lee *!* Clagett
Add support for subaddress lookahead (#195)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · Low 39/100
This commit adds subaddress lookahead support to the Monero Light Wallet Server (LWS). It lets wallets tell the server how many future subaddresses to precompute and watch, replacing a simple on/off subaddress flag with a configurable limit. The change touches the database format, admin and REST APIs, and the block scanner. It also adds automatic approval options for account creation and import requests. There is no explicit security bug visible in the diff, but the large schema migration and new resource-limit logic introduce ordinary operational risks: a misconfigured or maliciously large lookahead could make the server precompute huge numbers of subaddresses, consuming CPU and database space. The code does add a max_subaddresses cap and clamping helpers to mitigate this.
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityUpdate Dockerfile unbound to 1.24.2by Lee *!* Clagett · b621d088 · Dec 4, 2025 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Update Dockerfile unbound to 1.24.2
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityPrint version on monero-lws-daemon startup (#213)by Lee *!* Clagett · 506c3a87 · Dec 3, 2025 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Print version on monero-lws-daemon startup (#213)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityFix usage of mdb_cursor_put with invalid memory references (#210)by Lee *!* Clagett · 24bdbb43 · Dec 1, 2025 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Fix usage of mdb_cursor_put with invalid memory references (#210)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedAdd /get_version, based on openmonero with a few extra additions (#209)by Lee *!* Clagett · 8cf09765 · Nov 27, 2025 · 7 filesMessage 58 · ThinLow 28Details
Commit message · Lee *!* Clagett
Add /get_version, based on openmonero with a few extra additions (#209)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 28/100
This commit adds a new public /get_version endpoint to the Monero Light Wallet Server. It also changes the server to accept GET requests for some endpoints and records the HTTP method used. The new endpoint exposes detailed version and build information, including the exact git commit hash, branch, build date, Monero version, blockchain height, and server configuration. This information could help an attacker identify outdated or vulnerable server versions, but the commit itself does not appear to introduce a direct exploit.
Security candidateDon't log MDB_NOTFOUND with subaddress lookup (#208)by Lee *!* Clagett · c65a1f48 · Nov 23, 2025 · 1 fileMessage 58 · ThinInformational 17Details
Commit message · Lee *!* Clagett
Don't log MDB_NOTFOUND with subaddress lookup (#208)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocol
AI analysis · Informational 17/100
This change stops the program from writing a scary but harmless 'not found' log message when a subaddress lookup returns no result. It is a minor cleanup that reduces log noise; it does not fix a vulnerability that an attacker could exploit.
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityAdd rabbitmq to default Dockerfile build (#206)by Lee *!* Clagett · f7af8d3b · Nov 19, 2025 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Add rabbitmq to default Dockerfile build (#206)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityLogging Improvements (#198)by William Swanson · e08480cb · Nov 14, 2025 · 4 filesMessage 66 · AdequateTriage 0Details
Commit message · William Swanson
Logging Improvements (#198)
* Log ZMQ SUB address at startup * Log current thread number and block height * fixup! Log current thread number and block height
66/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Lower-priorityFix locked_funds computation (#200)by Lee *!* Clagett · 0caec18f · Nov 14, 2025 · 2 filesMessage 43 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Fix locked_funds computation (#200)
43/100 · ThinMessage clarity
✓ Descriptive subject✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityHopefully fix issue with db corruption (bad data size) (#199)by Lee *!* Clagett · 26a88296 · Nov 13, 2025 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · Lee *!* Clagett
Hopefully fix issue with db corruption (bad data size) (#199)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body