RB
← All projectsRust Bitcoin

rust-bitcoin

Rust library for Bitcoin data structures, serialization, consensus encoding, and scripts.

BitcoinCryptographic librariesNormal
Repository coverage

2310 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

531security candidates510second-pass queue2204AI analyses
136commits · 30 days
269commits · 60 days
1108commits · 180 days
2036commits · 365 days
Backfill bands
Aug 5 → Feb 6787 seen32 candidatesComplete
Feb 6 → Jun 6878 seen53 candidatesComplete
Jun 6 → Jul 6211 seen15 candidatesComplete
Jul 6 → Aug 5184 seen2 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

66/100 average clarity
507Strong · 80–100
1085Adequate · 60–79
567Thin · 40–59
151Opaque · 0–39
20security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Andrew Poelstra22878155290
Mitchell Bagot649193645068
Tobin C. Harding41566410063
jrakibi944994068
Nick Johnson19121190060
Jamil Lambert, PhD11919116061
satsfy (Renato Britto)381527066
Fmt Bot331431045
Trevor Arjeski111111069
Shing Him Ng31731056
Martin Habovstiak30628068
Ismail Daif22622050
Analysis record

Published AI watches

Last scanned 35 minutes ago

Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6947: build(deps): bump cargo-bins/cargo-binstall from 1.21.0 to 1.21.1

This commit updates the version of a helper tool (cargo-binstall) used only inside GitHub Actions automation. It is a routine dependency bump by Dependabot and does not change any code that ships to users. There is no indication of a secur…

c1be49cbby Andrew Poelstra+2−22 files
No security note in commit
High 70 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6919: Sanitize serde size hints before allocating

This commit fixes a denial-of-service weakness in how the library deserializes lists of Bitcoin data (witnesses, amounts, fee rates) from untrusted input. Before the fix, a few bytes of attacker-controlled data could claim a list would con…

Untrusted serde size hint fed directly into Vec::with_capacityPotential memory exhaustion / OOM kill from small malicious inputDenial-of-service vector in deserialization paths
55ddbc0cby Andrew Poelstra+88−105 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

This commit fixes how the Rust Bitcoin library calculates old-style (legacy) transaction signatures when the spending script contains a special opcode called OP_CODESEPARATOR. Previously the library did not handle this opcode at all, which…

Protocol correctness fix for legacy sighash serializationOP_CODESEPARATOR handling added to match Bitcoin Core consensus behaviorPreviously omitted test vectors restored, indicating prior non-compliance
5b815281by Andrew Poelstra+600−3093 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6948: build(deps): bump taiki-e/install-action from 2.83.2 to 2.85.4

This is a routine update by Dependabot to the version of a third-party GitHub Action used in the project's automated testing workflows. The change only affects internal continuous integration (CI) scripts, not the actual Bitcoin library co…

d1431904by Andrew Poelstra+2−22 files
No security note in commit
Low 33 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

This commit fixes a small but real bug in a Rust helper that reads fixed-size chunks from a data slice. The helper was supposed to safely return 'nothing' when asked to read past the end of the data, but it accidentally added two numbers t…

Integer overflow in bounds-checking helperContract violation: method documented to return None on out-of-bounds access could panic insteadDebug-build panic (denial of service) possible
c6e80843by Andrew Poelstra+2−11 file
Vendor flagged security relevance
Moderate 62 AI analysisMessage 73 · Adequate
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Fix integer overflow in `get_array`

This commit fixes a bug in a Rust helper method called `get_array`, which is meant to safely read a fixed-size chunk from a slice and return nothing if the requested range is out of bounds. The bug was that the code added the caller's offs…

Integer overflow in bounds calculationPotential panic due to violated internal length expectationCaller-controlled arithmetic used for memory access bounds
56fb1287by Martin Habovstiak+2−11 file
Vendor flagged security relevance
High 71 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6915: primitives: Fix `Witness` handling of oversized items

This commit fixes a bug in how the Rust Bitcoin library counts and compares transaction witness data when a witness contains an oversized item. Previously, several functions relied on an iterator that silently skips oversized items, causin…

Inconsistent serialization/iterator behavior for oversized witness itemswtxid collision risk between transactions differing only in oversized witness bytesIncorrect witness equality for oversized single-item stacks
e1ed5884by Andrew Poelstra+106−273 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6922: Use `try_fold` instead of `fold` in `Sum` impl

This is a code-quality and performance improvement, not a security fix. It changes how the library adds up lists of Bitcoin amounts so that it stops early once an overflow is detected, rather than continuing to process the rest of the list…

No security-relevant signal in commit message or diffRefactor preserves overflow-checking behavior (short-circuits instead of continuing)New API method `NumOpResult::from_result` is a pure inverse of existing `into_result`
86e4d5daby Andrew Poelstra+60−562 files
No security note in commit
Moderate 52 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6893: units: Reject malformed amount strings

This update fixes a bug in how the library reads Bitcoin amount strings like '1.5 BTC'. Previously, certain malformed inputs such as '.', '._', '1_', '1_.0', and '1._0' were incorrectly accepted and treated as valid amounts (often zero), i…

Input validation bypass in amount parserMalformed strings silently parsed as zero or ordinary amountsUnderscore separator placement not enforced
fcb14622by Andrew Poelstra+88−343 files
Vendor flagged security relevance
Low 48 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6921: units: fix div_by_fee_rate_ceil precision

This commit fixes a rounding bug in how the rust-bitcoin library calculates the minimum transaction weight needed to pay a given fee at a given fee rate. The old code rounded the fee rate up too early, which could produce a weight slightly…

Incorrect fee-weight calculation due to premature integer roundingPotential transaction fee shortfall when using div_by_fee_rate_ceilOverflow protection added for Amount::MAX * 4_000_000 intermediate value
b31212e0by Andrew Poelstra+38−82 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6898: Release tracking PR: `consensus-encoding 1.3.0`

This is a routine release-management commit that bumps the version number of the `bitcoin-consensus-encoding` crate from 1.2.0 to 1.3.0 and updates lock files accordingly. It contains no code changes that fix or introduce a security issue.…

0cfc7908by Andrew Poelstra+37−349 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6909: build(deps): bump actions/labeler from 6.2.0 to 7.0.0

This commit updates a GitHub Actions automation tool (actions/labeler) used to automatically tag pull requests with labels. It is a routine dependency version bump from 6.2.0 to 7.0.0, with no indication of a security fix or vulnerability.…

4ed7c068by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6910: build(deps): bump actions/checkout from 7.0.0 to 7.0.1

This commit is a routine update to the GitHub Actions checkout tool used by the project's automated workflows. It only changes version numbers in configuration files and does not alter the actual Bitcoin library code that users run. There …

328c4ae9by Andrew Poelstra+37−3717 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6911: build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0

This commit updates a GitHub Actions helper used to install a Python tool called uv, which runs the zizmor security scanner. The change only bumps the pinned version of the helper from 8.3.2 to 9.0.0. The new version's release notes mentio…

No security-relevant signals in commit or upstream release notesDependency bump in CI only, not in library codeNo CVE or advisory referenced
67600795by Andrew Poelstra+2−22 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6912: build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3

This is a routine Dependabot update that changes the pinned version of GitHub's official CodeQL upload-sarif action from 4.37.0 to 4.37.3 in a single CI workflow. The action only uploads static analysis results to GitHub; it does not touch…

b51cec63by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6913: build(deps): bump dtolnay/rust-toolchain from 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de

This is a routine update to a GitHub Actions helper used to install Rust during automated testing. It only changes the pinned version of the dtolnay/rust-toolchain action in workflow files. There is no change to the actual rust-bitcoin lib…

90330d15by Andrew Poelstra+8−84 files
No security note in commit
Informational 20 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6906: consensus_encoding, primitives: expose exact encoding size for block and transaction

This commit adds a way to ask, in advance, exactly how many bytes a Bitcoin block or transaction will take when serialized. It is a feature addition for the library's encoding system, not a fix for a vulnerability. There is no indication i…

No security-relevant signals in commit message or diffFeature addition: expose exact encoded sizeNo mention of vulnerability, CVE, bug bounty, or security report
1a365d53by Andrew Poelstra+129−1068 files
No security note in commit
Informational 15 AI analysisMessage 88 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump dtolnay/rust-toolchain

This is a routine update by Dependabot that changes which version of a popular GitHub Action (dtolnay/rust-toolchain) is used to install Rust in automated CI workflows. The commit only updates pinned commit hashes in workflow files; it doe…

a31e0b0eby dependabot[bot]+8−84 files
No security note in commit
Informational 15 AI analysisMessage 93 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump github/codeql-action/upload-sarif

This is a routine patch-version update of a GitHub-maintained action used only to upload static-analysis results (SARIF files) from a scheduled CI job. The change does not touch any project source code, cryptographic logic, or user-facing …

2cac6e38by dependabot[bot]+1−11 file
No security note in commit
Informational 15 AI analysisMessage 93 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0

This is a routine automated update by Dependabot that changes the pinned version of a GitHub Action used to install a Python tool called 'uv' in two workflow files. The new version is a major release of the setup-uv action itself, but the …

7d7e7269by dependabot[bot]+2−22 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateImplement Serde traits for ArrayVecby Abeeujah · dadbbaf3 · May 1, 2026 · 1 fileMessage 83 · StrongInformational 18Details
Commit message · Abeeujah

Implement Serde traits for ArrayVec

This implementation is a prerequisite for the serde traits
impl for `WitnessVersion` and `WitnessProgram`.

Add tests covering round-trip serialization, capacity overflow errors,
and wire-format compatibilitywith slices using both JSON and Bincode.

83/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
memory safety
AI analysis · Informational 18/100

This commit adds the ability to serialize and deserialize a small fixed-capacity vector type (ArrayVec) used inside the rust-bitcoin library. It is a routine feature addition with explicit guards against overflowing the capacity during deserialization. There is no indication this fixes a security bug or introduces a vulnerability.

AI review queuedUpdate API filesby Abeeujah · 62895cdb · May 1, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Abeeujah

Update API files

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates a generated text file listing the public API surface of the crate. It records that an internal ArrayVec type now implements standard serde serialization/deserialization traits. The diff itself contains no source code changes, no bug fixes, and no behavior changes.

Security candidatefuzz: remove psbt fuzz targets and document explicit local bitcoin dependencyby Ismail Daif · e64a89af · May 1, 2026 · 3 filesMessage 60 · AdequateInformational 15Details
Commit message · Ismail Daif

fuzz: remove psbt fuzz targets and document explicit local bitcoin dependency

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing boundaryfuzzing or regression evidence
AI analysis · Informational 15/100

This commit removes two PSBT (Partially Signed Bitcoin Transaction) fuzz testing targets from the project's automated fuzzing setup and adds a clarifying comment about why an explicit version number is needed for a local dependency. There is no change to the actual Bitcoin library code that users rely on, and nothing in the commit suggests a security vulnerability was fixed or introduced.

AI review queuedp2p: add V1MessageHeader constructorby yancy · 5bb9e5db · May 1, 2026 · 1 fileMessage 58 · ThinInformational 12Details
Commit message · yancy

p2p: add V1MessageHeader constructor

Adds a constructor to `V1MessageHeader` which also computes the 4 byte
checksum as defined by protocol docs. This constructor is used to
compose a network header that can be transmitted over the network stream.

Any network message (payload) must be directly preceded in the network
stream by a header. In that way, the receiving client knows how many
bytes to read, and what message to interpret.

A working code example might be a Pong response:
```
let message = bitcoin_p2p_messages::message::Pong(nonce);
let msg_header = V1MessageHeader::new(magic, &message, "pong");

// write the header to stream
encoding::encode_to_writer(&msg_header, &stream);

// write message to stream
encoding::encode_to_writer(&message, &stream);
```

Note that Currently, CommandString wraps a Cow<'static, str>, so the
lifetime of `cmd` must match the static lifetime. However, the protocol
documents define this as a 12 byte field, so this can and should be
changed at some point.

The fields defined in `V1MessageHeader` is the first four fields of a
message structure. An example given in the docs of message header is
given as:

```
Message Header:
F9 BE B4 D9 - Main network magic bytes
76 65 72 73 69 6F 6E 00 00 00 00 00 - "version" command
64 00 00 00 - Payload is 100 bytes long
35 8d 49 32 - payload checksum (byte order)
```

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 12/100

This commit adds a new helper function (constructor) to build a Bitcoin P2P network message header. It simply packages existing fields and computes the message checksum automatically. There is no indication it fixes a security bug or introduces a vulnerability; it appears to be a routine API improvement.

Lower-priorityRemove confusing byte literals in testsby Abeeujah · fd25c0a3 · Apr 30, 2026 · 1 fileMessage 78 · AdequateInformational 15Details
Commit message · Abeeujah

Remove confusing byte literals in tests

Use hex instead of bytes to maintain consistency across all other
tests which uses hex.

The hex string upholds the properties of the byte string (length,
validity) and is parsed via the `hex!` macro.

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit only changes test code. It replaces byte-string literals with hex-string literals to make the test data easier to read and keep it consistent with other tests. The actual production code being tested is not modified, and the test behavior remains the same.

Lower-priorityp2p: Remove legacy encoding from `lib`by rustaceanrob · efa4f343 · Apr 30, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from `lib`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit removes old-style encoding implementations from three simple data types (ProtocolVersion, ServiceFlags, and Magic) in the rust-bitcoin peer-to-peer library. It is a routine code cleanup that switches these types to use a newer, dedicated encoding macro. There is no indication of a security bug being fixed.

Lower-priorityp2p: Remove legacy encoding from `merkle_tree`by rustaceanrob · a20da27d · Apr 30, 2026 · 1 fileMessage 45 · ThinInformational 12Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from `merkle_tree`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 12/100

This commit removes old-style encoding and decoding code for two Bitcoin peer-to-peer message types (MerkleBlock and PartialMerkleTree) and replaces it with a newer encoding system already present in the file. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a routine cleanup or migration to a newer serialization API.

Lower-priorityp2p: Remove legacy encoding from `address`by rustaceanrob · d5e8f0c7 · Apr 30, 2026 · 3 filesMessage 45 · ThinInformational 12Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from `address`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 12/100

This commit removes old, unused code that encoded and decoded Bitcoin peer network addresses using a legacy 'consensus' encoding system. It is a cleanup change: the deleted code appears to have been superseded by newer encoding machinery elsewhere in the crate. There is no indication in the commit that this fixes a security bug or that the removed code was reachable by attackers.

Lower-priorityp2p: Remove legacy encoding from `message_filter`by rustaceanrob · 8e70dda4 · Apr 30, 2026 · 1 fileMessage 45 · ThinInformational 11Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from `message_filter`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 11/100

This commit removes old-style Bitcoin consensus encoding code from the peer-to-peer message filter module. It replaces hand-written encoding implementations with newer macro-generated ones that were already added elsewhere in the file. There is no indication in the commit that this fixes a security bug; it appears to be a routine cleanup/refactoring change.

Lower-priorityp2p: Remove legacy encoding from `message_blockdata`by rustaceanrob · 5f687c60 · Apr 30, 2026 · 1 fileMessage 50 · ThinInformational 12Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from `message_blockdata`

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 12/100

This commit removes old-style encoding and decoding code for several Bitcoin peer-to-peer message types and replaces it with a newer, generated encoding system. There is no direct evidence in the commit or supplied references that this fixes a security vulnerability; it appears to be a routine refactoring or cleanup of legacy code.

Lower-priorityp2p: Remove legacy encoding from `message_network`by rustaceanrob · f41f1135 · Apr 30, 2026 · 2 filesMessage 50 · ThinInformational 16Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from `message_network`

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 16/100

This commit removes old, unused Bitcoin network message encoding code from the rust-bitcoin p2p library. It deletes fallback implementations that were kept alongside newer encoding logic. There is no direct evidence this fixes an active security bug, but removing redundant legacy code reduces the attack surface and the chance that outdated, potentially unsafe code paths could be accidentally used in the future.

Lower-priorityp2p: Remove legacy encoding from `message_bloom`by rustaceanrob · cb8a2385 · Apr 30, 2026 · 1 fileMessage 45 · ThinInformational 12Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from `message_bloom`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 12/100

This commit removes old, unused encoding code for Bitcoin peer-to-peer bloom filter messages. It is a cleanup change that deletes legacy implementations after newer replacement code was already in place. There is no indication this fixes a security bug or introduces a vulnerability.

Lower-priorityp2p: Remove legacy encoding from BIP-152by rustaceanrob · 3a8505d5 · Apr 30, 2026 · 2 filesMessage 45 · ThinLow 27Details
Commit message · rustaceanrob

p2p: Remove legacy encoding from BIP-152

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Low 27/100

This commit removes old-style serialization code for compact-block P2P messages and replaces it with a newer internal encoding system. It is a cleanup/refactoring change in the rust-bitcoin library. There is no direct evidence in the commit that it fixes a security vulnerability, but any encoding change can in principle affect how malformed network data is parsed.

Lower-priorityp2p: Remove legacy encoding in `message`by rustaceanrob · af2d0132 · Apr 30, 2026 · 2 filesMessage 45 · ThinInformational 18Details
Commit message · rustaceanrob

p2p: Remove legacy encoding in `message`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 18/100

This commit removes old-style Bitcoin P2P message encoding and decoding code from the rust-bitcoin library and replaces it with a newer encoding system. It is a cleanup/refactoring change, not a fix for an active security bug. The deleted code included checksum verification and message-length limits that now live in the new encoder, so the security of the library depends on whether the new code provides equivalent protections. The commit itself does not describe any security issue.

Security candidatecrypto: Change to_public_key to return FullPublicKeyby Mitchell Bagot · ccf5b5c8 · Apr 30, 2026 · 4 filesMessage 85 · StrongInformational 19Details
Commit message · Mitchell Bagot

crypto: Change to_public_key to return FullPublicKey

In general, modern bitcoin code should be using either the compressed
FullPublicKey or the XOnlyPublicKey. Users should try to avoid the
legacy optionally-compressed public key. To this end, the types were
renamed. To further consolidate this, the to_public_key methods
throughout the key module should also return FullPublicKey, with the
existing behaviour relegated to new to_legacy_public_key.

Change all to_public_key functions to return FullPublicKey and
introduce corresponding to_legacy_public_key functions to return
LegacyPublicKey where necessary.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 19/100

This commit is a routine API cleanup in the rust-bitcoin library. It changes several methods named to_public_key so they return a modern compressed public key type (FullPublicKey) instead of an older type that could be either compressed or uncompressed (LegacyPublicKey). The old behavior is preserved under new to_legacy_public_key methods. The change is about encouraging safer modern key handling, not about fixing an active security bug.

Lower-priorityUpdate the API text filesby Tobin C. Harding · 1d5bcfed · Apr 30, 2026 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · Tobin C. Harding

Update the API text files

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates generated API text files to include a newly added public function, `drain_to_engine`, in the documented interface list. It does not change any source code, behavior, or security properties of the library. There is no security issue here.

Lower-priorityhashes: Add drain_to_engine functionby Tobin C. Harding · e35c7db3 · Apr 30, 2026 · 1 fileMessage 58 · ThinInformational 15Details
Commit message · Tobin C. Harding

hashes: Add drain_to_engine function

Add a function that pairs with `encode_to_engine`. This is similar to
the APIs `encode_to_writer`/`drain_to_writer` in other crates.

Note, use one level of path on the `Encoder` to be uniform with the
code in `encode_to_engine`.

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit adds a new public helper function called drain_to_engine in the rust-bitcoin hashes crate. It simply refactors existing code so that the logic for feeding an encoder's output into a hash engine can be called independently. There is no indication of a bug fix or security issue in the commit message or diff.

Lower-priorityci: Change encodable coverage to check for Encode traitby Mitchell Bagot · 2c7421ef · Apr 29, 2026 · 2 filesMessage 100 · StrongInformational 15Details
Commit message · Mitchell Bagot

ci: Change encodable coverage to check for Encode trait

The Encodable trait was recently renamed to Encode, but this script
was not similarly updated. As such, the CI now fails due to an
incorrect docs file path.

Change Encodable to Encode in encodable coverage check to track new
trait name.

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
AI analysis · Informational 15/100

This is a routine CI maintenance patch. A trait named Encodable was renamed to Encode elsewhere in the project, and this change updates a GitHub Actions workflow and a shell script so they reference the new name. It fixes a broken documentation-file path that was causing CI to fail. There is no security issue here.

Lower-priorityci: clean up github disk bloatby Nick Johnson · 66a2b59b · Apr 28, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · Nick Johnson

ci: clean up github disk bloat

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only adds a GitHub Actions step that frees disk space before running CI tests. It is a routine infrastructure/maintenance change with no user-facing or security-relevant code change.

Lower-priorityfuzz: add max_total_time option to fuzz.shby Ismail Daif · 8cc9bf59 · Apr 28, 2026 · 2 filesMessage 55 · ThinInformational 15Details
Commit message · Ismail Daif

fuzz: add max_total_time option to fuzz.sh

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100

This commit only changes the project's internal fuzzing test script. It adds a command-line option to control how long fuzzing runs, replacing a fixed 100,000-run limit with a default 100-second time limit. There is no change to the actual Bitcoin library code that users rely on, and no security issue is present.

Lower-priorityci: revert to local action for setup-rbmtby Nick Johnson · 22153300 · Apr 28, 2026 · 3 filesMessage 80 · StrongInformational 15Details
Commit message · Nick Johnson

ci: revert to local action for setup-rbmt

Github Actions doesn't allow the uses key to be set by a runtime value,
which means a separate rbmt version needs to be managed just for the
shared action. Given how little this action does, easier to just copy
paste it and avoid the confusion.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit is a routine GitHub Actions maintenance change. It copies a small reusable workflow step (called 'setup-rbmt') from a separate repository into this one, so the project no longer has to reference an external repository version. There is no change to the actual Bitcoin library code, no user-facing behavior change, and no security fix or vulnerability introduced.

AI review queuedbitcoin: cut down on exact_features test matrixesby Nick Johnson · 0435a98d · Apr 28, 2026 · 1 fileMessage 83 · StrongInformational 15Details
Commit message · Nick Johnson

bitcoin: cut down on exact_features test matrixes

The Github CI runner is timing out when running all the feature sets
on the older MSRV compiler. The current list of exact_features in the
bitcoin crate was a conserative "include everything" when we switched
over to cargo-rbmt. This cuts it down ~50% and focuses on core
interactions we want to always cover. This puts more responsibilites on
cargo-rbmt's random feature subsets it runs on every commit.

83/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 15/100

This commit only changes the list of feature combinations that are tested automatically in CI. It removes most of a large, exhaustive test matrix and keeps just two core combinations to avoid timeouts on older Rust compilers. There is no change to the actual library code, dependencies, or user-facing behavior.

Lower-priorityci: do not run tests on the nightly toolchainby Nick Johnson · 6f990ed2 · Apr 28, 2026 · 1 fileMessage 90 · StrongInformational 15Details
Commit message · Nick Johnson

ci: do not run tests on the nightly toolchain

Discussed elsewhere, but these are relatively expensive, requiring a bunch
of artifacts to be built for the specific nightly toolchain, and don't
provide much more signal than the lint run.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit simply removes the nightly Rust toolchain from the project's automated test matrix. It is a routine CI cost-saving change and has no security relevance.

Lower-priorityIntroduce CI action to enforce encodable fuzzingby Mitchell Bagot · fcaab9c4 · Apr 28, 2026 · 2 filesMessage 90 · StrongInformational 15Details
Commit message · Mitchell Bagot

Introduce CI action to enforce encodable fuzzing

With the introduction of the Encodable differential fuzz target, it's
important to ensure that all new implementations of Encodable types
are compared against existing implementations from bitcoin 0.32.

Add Encodable-coverage action to check compare_consensus_encoding
target for inclusion of all Encodable types on branch and bitcoin 0.32.

Assisted-by: Claude Opus 4.5

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100

This commit adds a new continuous integration (CI) check and a helper script that make sure every type that can be encoded in the current version of the library is also tested by an existing differential fuzz test against an older version of the library. It does not change any library code, user-facing behavior, or fix a bug; it only strengthens automated testing.

Lower-priorityAdd fuzz target comparing consensus encoding to bitcoin 0.32by Mitchell Bagot · 32304c26 · Apr 28, 2026 · 6 filesMessage 95 · StrongInformational 15Details
Commit message · Mitchell Bagot

Add fuzz target comparing consensus encoding to bitcoin 0.32

Since bitcoin 0.32, consensus encoding has been rebuilt from the ground
up with the consensus_encoding crate. In order to confirm that it
functions identically to the original encoding implementations, the
two should be differentially fuzzed.

Introduce a fuzz target that compares encodings using serialize from
bitcoin 0.32 against encode_to_vec from consensus_encoding.

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100

This commit adds a new automated test (a fuzz target) that compares how the current development version of the rust-bitcoin library encodes Bitcoin data against the previous stable release (0.32). It does not change any production code, fix a bug, or introduce a vulnerability. It only adds testing infrastructure and dependency lockfile updates needed to run that test.