LWS
← All projectsMonero LWS

Monero LWS

Light-wallet server indexing Monero chain data for remote wallet clients.

Indexing infrastructureMoneroPrivacy protocolsNormal
Repository coverage

108 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

10security candidates25second-pass queue35AI analyses
18commits · 30 days
24commits · 60 days
62commits · 180 days
108commits · 365 days
Backfill bands
Sep 27 → Mar 3144 seen3 candidatesComplete
Mar 31 → Jul 2932 seen4 candidatesComplete
Jul 29 → Aug 2812 seen2 candidatesComplete
Aug 28 → Sep 276 seen0 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

50/100 average clarity
1Strong · 80–100
8Adequate · 60–79
83Thin · 40–59
16Opaque · 0–39
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Lee *!* Clagett95934149
Evgeny211062
jpk68300057
everoddandeven300056
Lee Clagett300047
Paul V Puey100076
William Swanson100066
Analysis record

Published AI watches

Last scanned 45 minutes ago

High 71 AI analysisMessage 81 · Strong
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fixes for issues reported by llm (#297)

This commit fixes nine separate bugs in the Monero Light Wallet Server (LWS). The most serious ones are: an infinite loop when importing certain address data, a missing size limit that let unauthenticated remote clients request huge amount…

Infinite loop in database import path (DoS)Missing authentication-time message size limit on remote scanner protocol (memory exhaustion / DoS)Untrusted array reads from client in light wallet RPC
81451fb2by Lee *!* Clagett+62−129 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 28 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix docker build:

This commit fixes a broken GitHub Actions workflow file that builds and publishes Docker images. It corrects a variable name (from 'platform' to 'arch') and adds a missing period at the end of the docker build command. There is no security…

10118fbdby Lee *!* Clagett+3−31 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix docker action file

This commit fixes a YAML indentation error in a GitHub Actions workflow file. It changes one line of spacing so the Docker login step is correctly aligned under the job's steps list. There is no security-relevant change to the software its…

bff4b1b4by Lee *!* Clagett+1−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix docker build command

This commit fixes a typo in a GitHub Actions workflow file. The Docker build command had an extra word ('build build') that would cause the automated Docker image build to fail. It is a routine CI/CD fix with no security relevance.

e5d4b3a7by Lee *!* Clagett+1−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix docker build matrix

This commit fixes a GitHub Actions workflow syntax error. The 'matrix' keyword was missing its required parent 'strategy' wrapper, which would prevent Docker build jobs from running correctly. There is no security relevance in the code cha…

800e026fby Lee *!* Clagett+3−21 file
No security note in commit
Informational 12 AI analysisMessage 70 · Adequate
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Changes required due to upstream monero changes (#290)

This commit is a routine compatibility update to keep the Monero Light Wallet Server (LWS) project building against recent changes in the upstream Monero codebase. It replaces a custom macro-based type declaration (POD_CLASS) with plain C+…

No security-relevant behavioral changes in the diffChanges are limited to forward-declaration style and missing header includesNo memory safety, cryptographic, input validation, or authorization changes observed
fee43d23by Lee *!* Clagett+6−55 files
No security note in commit
Low 32 AI analysisMessage 58 · Thin
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix LMDB (wrong) context cast, and remove now unnecessary LMDB code (#287)

This commit fixes a type-casting mistake in the Monero Light Wallet Server's database code. The program was treating its own custom database context as a different, more generic context. That mismatch could corrupt internal accounting of a…

Wrong context cast in LMDB transaction cleanup (type confusion)Custom context reference counting could be corrupted by mismatched deleterLarge code removal reduces attack surface and eliminates duplicated LMDB wrappers
eef10334by Lee *!* Clagett+155−6839 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix docker conditional

This commit fixes a simple syntax typo in a GitHub Actions workflow file. The condition that decides whether to add release tags had an extra closing brace, which would cause the workflow to fail parsing rather than run incorrectly. There …

cbf6f328by Lee *!* Clagett+1−11 file
No security note in commit
Informational 15 AI analysisMessage 18 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Latest master

This commit only updates the 'external/monero' git submodule pointer from one commit hash to another. No actual source code changes are shown in this repository's diff. The title and message are generic ('Latest master') and give no indica…

248e9148by Lee *!* Clagett+1−11 file
No security note in commit
Low 35 AI analysisMessage 58 · Thin
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix mempool webhook read during subaddress scanning (#283)

This commit fixes a bug in the Monero Light Wallet Server (LWS) where webhook notifications for mempool transactions could fail or behave incorrectly when scanning subaddresses. The change passes an existing database reader into the output…

Fixes a read-transaction lifecycle issue in webhook lookup during mempool scanningAdds regression test covering mempool publication + webhook deliveryCallback signature change propagates an existing storage_reader to avoid nested/duplicate reads
89e90f58by Lee *!* Clagett+354−136 files
No security note in commit
Informational 15 AI analysisMessage 53 · Thin
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Add/update newest GPG signing key (#282)

This commit simply adds a new GPG public key file to the repository. A GPG public key is used to verify that future releases or commits were genuinely signed by the project maintainer. There is no code change, no vulnerability, and no secu…

5b64b31eby Lee *!* Clagett+22−01 file
No security note in commit
Informational 11 AI analysisMessage 45 · Thin
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Another attempt at fixing external/monero pin

This commit is a routine build/maintenance change that adjusts which version of the external Monero dependency is pinned. There is no indication of any security fix, vulnerability, or user-facing behavior change. It is essentially a housek…

1e48ef2bby Lee *!* Clagett+1−11 file
No security note in commit
Informational 4 AI analysisMessage 45 · Thin
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix external/master pin back to master

This commit appears to change which version of an external Monero component the project points to (a so-called 'git submodule pin' or dependency reference). The title says it fixes the pin for 'external/master' back to the 'master' branch.…

d7f8ef46by Lee *!* Clagett+1−11 file
No security note in commit
Moderate 56 AI analysisMessage 58 · Thin
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix `MDB_BAD_RSLOT` in `subaddress_reader::update_reader()` causing permanently missed subaddress outputs (#278)

This commit fixes a database-handling bug in Monero Light Wallet Server (LWS). The bug caused the server to permanently miss some subaddress outputs because a read transaction was not closed before a new one was opened, triggering an LMDB …

Fixes LMDB transaction-slot error (MDB_BAD_RSLOT)Prevents permanently missed subaddress outputsChanges test expectations to reflect recovered output
38b336e2by Evgeny+8−33 files
No security note in commit
Moderate 59 AI analysisMessage 63 · Adequate
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fix integer overflow check in subaddress handling (#264)

This commit fixes a math mistake when checking whether a user requested too many Monero subaddresses. The original code divided two numbers and compared the result to a maximum, which is the wrong way to detect overflow and could allow the…

Integer overflow check corrected from an inverted/incorrect comparison to a canonical safe division pre-checkOccurs in subaddress limit enforcement, which is a security boundary against excessive address derivationSame bug pattern present in two independent locations (storage and REST server)
33c56770by Lee *!* Clagett+2−22 files
No security note in commit
Informational 15 AI analysisMessage 38 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Bump branch to 1.1-alpha

This commit simply changes a version string from '1.0-alpha' to '1.1-alpha' in a single source file. There is no functional code change, no bug fix, and no security relevance visible in the diff or commit message.

fb599e8aby Lee *!* Clagett+1−11 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Bump mkdocs to regenerate

This commit changes one character in the documentation configuration file (mkdocs.yml), adding a trailing slash to the site description. It does not touch any program code, cryptographic logic, network handling, or user data. There is no s…

322f5827by Lee *!* Clagett+1−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Another publish attempt

This commit is a routine documentation-site fix. It changes how the MkDocs documentation builder is invoked in a GitHub Actions workflow (from `python3 mkdocs build` to `python3 -m mkdocs build`) and fixes a typo in the site description. T…

d86d25a7by Lee *!* Clagett+2−22 files
No security note in commit
Informational 15 AI analysisMessage 18 · Opaque
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

tweaking docs

This commit makes a trivial wording change to the project's documentation configuration file, adding a slash to the site description. There is no security relevance.

1647bdb2by Lee *!* Clagett+1−11 file
No security note in commit
Low 34 AI analysisMessage 73 · Adequate
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Add mempool support to /get_address_txs and /feed (#251)

This commit adds mempool (pending transaction) support to Monero Light Wallet Server. It lets users see unconfirmed transactions through the /get_address_txs REST endpoint and the live /feed websocket. The change also refactors how the ser…

Large feature commit (+1906/-634) touching REST, WebSocket feed, scanner, and new mempool componentRefactored transaction ownership scanning into shared ownership_test helper; reduces duplicated crypto/derivation logicMempool transactions are parsed and validated before being added to the local cache in /submit_raw_tx
a7aea46eby Lee *!* Clagett+1906−63432 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedFix docker build:by Lee *!* Clagett · 10118fbd · Sep 30, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fix docker build:

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a broken GitHub Actions workflow file that builds and publishes Docker images. It corrects a variable name (from 'platform' to 'arch') and adds a missing period at the end of the docker build command. There is no security issue here—just a routine build script repair.

AI review queuedFix docker action fileby Lee *!* Clagett · bff4b1b4 · Sep 30, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fix docker action file

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a YAML indentation error in a GitHub Actions workflow file. It changes one line of spacing so the Docker login step is correctly aligned under the job's steps list. There is no security-relevant change to the software itself.

AI review queuedFix docker build commandby Lee *!* Clagett · e5d4b3a7 · Sep 30, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fix docker build command

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a typo in a GitHub Actions workflow file. The Docker build command had an extra word ('build build') that would cause the automated Docker image build to fail. It is a routine CI/CD fix with no security relevance.

AI review queuedFix docker build matrixby Lee *!* Clagett · 800e026f · Sep 30, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fix docker build matrix

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a GitHub Actions workflow syntax error. The 'matrix' keyword was missing its required parent 'strategy' wrapper, which would prevent Docker build jobs from running correctly. There is no security relevance in the code change itself.

AI review queuedChanges required due to upstream monero changes (#290)by Lee *!* Clagett · fee43d23 · Sep 18, 2026 · 5 filesMessage 70 · AdequateInformational 12Details
Commit message · Lee *!* Clagett

Changes required due to upstream monero changes (#290)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit is a routine compatibility update to keep the Monero Light Wallet Server (LWS) project building against recent changes in the upstream Monero codebase. It replaces a custom macro-based type declaration (POD_CLASS) with plain C++ struct forward declarations and adds a few missing standard library header includes. There is no indication in the commit that any security vulnerability is being fixed.

AI review queuedFix LMDB (wrong) context cast, and remove now unnecessary LMDB code (#287)by Lee *!* Clagett · eef10334 · Aug 26, 2026 · 9 filesMessage 58 · ThinLow 32Details
Commit message · Lee *!* Clagett

Fix LMDB (wrong) context cast, and remove now unnecessary LMDB code (#287)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 32/100

This commit fixes a type-casting mistake in the Monero Light Wallet Server's database code. The program was treating its own custom database context as a different, more generic context. That mismatch could corrupt internal accounting of active readers/writers or cause the wrong cleanup code to run when a database transaction ends. The patch also removes a lot of now-redundant LMDB wrapper code and switches the project to use its own dedicated transaction and cursor types so the mistake cannot recur in the same way.

AI review queuedFix docker conditionalby Lee *!* Clagett · cbf6f328 · Aug 8, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fix docker conditional

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a simple syntax typo in a GitHub Actions workflow file. The condition that decides whether to add release tags had an extra closing brace, which would cause the workflow to fail parsing rather than run incorrectly. There is no security issue here.

AI review queuedLatest masterby Lee *!* Clagett · 248e9148 · Aug 8, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Latest master

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates the 'external/monero' git submodule pointer from one commit hash to another. No actual source code changes are shown in this repository's diff. The title and message are generic ('Latest master') and give no indication of what changed in the submodule. Without inspecting the submodule's own commits, we cannot determine any security relevance from the materials provided.

AI review queuedBump branch to 1.1-alphaby Lee *!* Clagett · fb599e8a · May 23, 2026 · 1 fileMessage 38 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Bump branch to 1.1-alpha

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply changes a version string from '1.0-alpha' to '1.1-alpha' in a single source file. There is no functional code change, no bug fix, and no security relevance visible in the diff or commit message.

AI review queuedBump mkdocs to regenerateby Lee *!* Clagett · 322f5827 · May 23, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Bump mkdocs to regenerate

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit changes one character in the documentation configuration file (mkdocs.yml), adding a trailing slash to the site description. It does not touch any program code, cryptographic logic, network handling, or user data. There is no security relevance.

AI review queuedAnother publish attemptby Lee *!* Clagett · d86d25a7 · May 23, 2026 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Another publish attempt

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine documentation-site fix. It changes how the MkDocs documentation builder is invoked in a GitHub Actions workflow (from `python3 mkdocs build` to `python3 -m mkdocs build`) and fixes a typo in the site description. There is no security relevance.

AI review queuedtweaking docsby Lee *!* Clagett · 1647bdb2 · May 23, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

tweaking docs

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit makes a trivial wording change to the project's documentation configuration file, adding a slash to the site description. There is no security relevance.

AI review queuedAdd mempool support to /get_address_txs and /feed (#251)by Lee *!* Clagett · a7aea46e · May 23, 2026 · 32 filesMessage 73 · AdequateLow 34Details
Commit message · Lee *!* Clagett

Add mempool support to /get_address_txs and /feed (#251)

Co-authored-by: William Swanson <swansontec@gmail.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit adds mempool (pending transaction) support to Monero Light Wallet Server. It lets users see unconfirmed transactions through the /get_address_txs REST endpoint and the live /feed websocket. The change also refactors how the server checks whether transaction outputs belong to a user's address, moving that logic into a shared helper called ownership_test. There is no direct evidence in the commit message or diff that this fixes a security vulnerability; it reads as a feature addition with associated code cleanup.

AI review queuedImplemented websocket "/feed" (i.e "push" updates) on HTTP (REST) API (#237)by Lee *!* Clagett · d2d03b5c · May 23, 2026 · 40 filesMessage 58 · ThinLow 39Details
Commit message · Lee *!* Clagett

Implemented websocket "/feed" (i.e "push" updates) on HTTP (REST) API (#237)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 39/100

This commit adds a new real-time WebSocket '/feed' endpoint to the Monero Light Wallet Server. It lets wallet clients receive live transaction and block updates instead of polling. The change is large (+3,300 lines) and touches networking, authentication, serialization, and database access. It also refactors existing account-opening code so it can be shared between the old REST API and the new feed. There is no indication in the commit that this is a security fix; it appears to be a feature implementation. Because it is brand-new network-facing code, it increases the attack surface, but the diff itself does not contain an obvious, directly exploitable vulnerability.

AI review queuedFix rct::h2d call (upstream change) (#252)by Lee *!* Clagett · a3abb637 · May 13, 2026 · 1 fileMessage 53 · ThinLow 42Details
Commit message · Lee *!* Clagett

Fix rct::h2d call (upstream change) (#252)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 42/100

This commit updates a single function that decodes hidden Monero transaction amounts to match a recent upstream Monero library change. The old code called rct::h2d(copy.amount) directly and assumed it always succeeded. The new code creates a local output variable, calls rct::h2d(out, copy.amount), and only returns the decoded amount if the function reports success. This is a defensive fix that prevents the wallet server from returning potentially invalid or garbage decoded amounts if the conversion fails. It is unlikely to be a critical remote-exploitable vulnerability on its own, but it removes a correctness bug that could affect balance or transaction reporting.

AI review queuedImprove Github Pages deploymentby Lee *!* Clagett · a2302eb8 · Apr 9, 2026 · 1 fileMessage 35 · OpaqueInformational 18Details
Commit message · Lee *!* Clagett

Improve Github Pages deployment

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 18/100

This commit updates the GitHub Actions workflow that publishes documentation to GitHub Pages. It replaces a third-party deployment action with GitHub's official actions and adds explicit permissions so the workflow only gets the access it needs. The change is a routine hardening/improvement of the documentation publishing pipeline, not a fix for an active security flaw in the Monero Light Wallet Server software itself.

AI review queuedFix archlinux ci (#231)by Lee *!* Clagett · 817db6c9 · Mar 18, 2026 · 1 fileMessage 36 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fix archlinux ci (#231)

36/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes an Arch Linux CI build script by adding the --noconfirm flag to a pacman system update command. It is purely a build/CI maintenance change and has no security relevance to the actual Monero LWS software or its users.

AI review queuedAttempt to CNAME correctlyby Lee *!* Clagett · 6b3ec7c1 · Mar 18, 2026 · 2 filesMessage 35 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Attempt to CNAME correctly

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine GitHub Pages configuration fix. It moves the custom domain setting from the deployment workflow file into a dedicated CNAME file in the docs folder, and removes a duplicate lowercase 'cname' file. There is no security issue here—just housekeeping to make the documentation website's custom domain work correctly.

AI review queuedFix docker workflowby Lee *!* Clagett · 589eff85 · Mar 17, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fix docker workflow

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a YAML syntax error in a GitHub Actions workflow file. A missing closing quote in the paths-ignore list caused the workflow configuration to be invalid. The change adds the missing quote so the workflow can parse correctly. There is no security-relevant code change.

AI review queuedAdd cname to docs folderby Lee *!* Clagett · a3468f97 · Mar 17, 2026 · 1 fileMessage 38 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Add cname to docs folder

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit adds a single configuration file named 'cname' to the docs folder. The file contains the custom domain name 'docs.monerolws.com' for GitHub Pages documentation hosting. It makes no code changes and has no security relevance.

AI review queuedFixing mkdocs build commandby Lee *!* Clagett · bcbf8999 · Mar 17, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Lee *!* Clagett

Fixing mkdocs build command

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a typo in an automated documentation publishing script. The previous command incorrectly tried to run mkdocs as a Python module (python3 mkdocs build), which would fail. The corrected command simply runs mkdocs build. There is no security issue here.

AI review queuedPushing initial attempt at a docs siteby Lee *!* Clagett · b3ac4770 · Mar 17, 2026 · 19 filesMessage 45 · ThinInformational 15Details
Commit message · Lee *!* Clagett

Pushing initial attempt at a docs site

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a documentation-only change. It adds a new docs website for the monero-lws project, including Markdown guides, OpenAPI YAML specs, a GitHub Actions workflow to deploy the site, and a MkDocs configuration. No source code, build scripts, or runtime behavior of the application were modified. There is no security-relevant change in the software itself.

AI review queuedAdd EXCLUDE_FROM_ALL for monero dependency (#221)by Lee *!* Clagett · f2b35340 · Dec 19, 2025 · 1 fileMessage 53 · ThinInformational 15Details
Commit message · Lee *!* Clagett

Add EXCLUDE_FROM_ALL for monero dependency (#221)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: broader security terminology
AI analysis · Informational 15/100

This is a one-line build-system change that tells CMake not to automatically build every target from the bundled Monero dependency when building monero-lws. It only affects which build targets are included by default and does not change any executable code, network behavior, or cryptographic logic.

AI review queuedAdd /get_version, based on openmonero with a few extra additions (#209)by Lee *!* Clagett · 8cf09765 · Nov 27, 2025 · 7 filesMessage 58 · ThinLow 28Details
Commit message · Lee *!* Clagett

Add /get_version, based on openmonero with a few extra additions (#209)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 28/100

This commit adds a new public /get_version endpoint to the Monero Light Wallet Server. It also changes the server to accept GET requests for some endpoints and records the HTTP method used. The new endpoint exposes detailed version and build information, including the exact git commit hash, branch, build date, Monero version, blockchain height, and server configuration. This information could help an attacker identify outdated or vulnerable server versions, but the commit itself does not appear to introduce a direct exploit.

AI review queuedAdd from_height to /import_wallet_request (#194)by Lee *!* Clagett · 151d3092 · Nov 5, 2025 · 4 filesMessage 53 · ThinLow 28Details
Commit message · Lee *!* Clagett

Add from_height to /import_wallet_request (#194)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 28/100

This commit adds a new optional 'from_height' field to the /import_wallet_request endpoint in the Monero Light Wallet Server. Previously, import requests always started scanning from block 0. Now users can request a later starting block height. The change appears to be a feature addition rather than a security fix, though it touches authentication-related code paths.