RB
← All projectsRust Bitcoin

rust-bitcoin

Rust library for Bitcoin data structures, serialization, consensus encoding, and scripts.

BitcoinCryptographic librariesNormal
Repository coverage

2310 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

531security candidates510second-pass queue2204AI analyses
136commits · 30 days
269commits · 60 days
1108commits · 180 days
2034commits · 365 days
Backfill bands
Aug 5 → Feb 6787 seen32 candidatesComplete
Feb 6 → Jun 6878 seen53 candidatesComplete
Jun 6 → Jul 6211 seen15 candidatesComplete
Jul 6 → Aug 5184 seen2 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

66/100 average clarity
507Strong · 80–100
1085Adequate · 60–79
567Thin · 40–59
151Opaque · 0–39
20security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Andrew Poelstra22878155290
Mitchell Bagot649193645068
Tobin C. Harding41566410063
jrakibi944994068
Nick Johnson19121190060
Jamil Lambert, PhD11919116061
satsfy (Renato Britto)381527066
Fmt Bot331431045
Trevor Arjeski111111069
Shing Him Ng31731056
Martin Habovstiak30628068
Ismail Daif22622050
Analysis record

Published AI watches

Last scanned 29 minutes ago

Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6947: build(deps): bump cargo-bins/cargo-binstall from 1.21.0 to 1.21.1

This commit updates the version of a helper tool (cargo-binstall) used only inside GitHub Actions automation. It is a routine dependency bump by Dependabot and does not change any code that ships to users. There is no indication of a secur…

c1be49cbby Andrew Poelstra+2−22 files
No security note in commit
High 70 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6919: Sanitize serde size hints before allocating

This commit fixes a denial-of-service weakness in how the library deserializes lists of Bitcoin data (witnesses, amounts, fee rates) from untrusted input. Before the fix, a few bytes of attacker-controlled data could claim a list would con…

Untrusted serde size hint fed directly into Vec::with_capacityPotential memory exhaustion / OOM kill from small malicious inputDenial-of-service vector in deserialization paths
55ddbc0cby Andrew Poelstra+88−105 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

This commit fixes how the Rust Bitcoin library calculates old-style (legacy) transaction signatures when the spending script contains a special opcode called OP_CODESEPARATOR. Previously the library did not handle this opcode at all, which…

Protocol correctness fix for legacy sighash serializationOP_CODESEPARATOR handling added to match Bitcoin Core consensus behaviorPreviously omitted test vectors restored, indicating prior non-compliance
5b815281by Andrew Poelstra+600−3093 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6948: build(deps): bump taiki-e/install-action from 2.83.2 to 2.85.4

This is a routine update by Dependabot to the version of a third-party GitHub Action used in the project's automated testing workflows. The change only affects internal continuous integration (CI) scripts, not the actual Bitcoin library co…

d1431904by Andrew Poelstra+2−22 files
No security note in commit
Low 33 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

This commit fixes a small but real bug in a Rust helper that reads fixed-size chunks from a data slice. The helper was supposed to safely return 'nothing' when asked to read past the end of the data, but it accidentally added two numbers t…

Integer overflow in bounds-checking helperContract violation: method documented to return None on out-of-bounds access could panic insteadDebug-build panic (denial of service) possible
c6e80843by Andrew Poelstra+2−11 file
Vendor flagged security relevance
Moderate 62 AI analysisMessage 73 · Adequate
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Fix integer overflow in `get_array`

This commit fixes a bug in a Rust helper method called `get_array`, which is meant to safely read a fixed-size chunk from a slice and return nothing if the requested range is out of bounds. The bug was that the code added the caller's offs…

Integer overflow in bounds calculationPotential panic due to violated internal length expectationCaller-controlled arithmetic used for memory access bounds
56fb1287by Martin Habovstiak+2−11 file
Vendor flagged security relevance
High 71 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6915: primitives: Fix `Witness` handling of oversized items

This commit fixes a bug in how the Rust Bitcoin library counts and compares transaction witness data when a witness contains an oversized item. Previously, several functions relied on an iterator that silently skips oversized items, causin…

Inconsistent serialization/iterator behavior for oversized witness itemswtxid collision risk between transactions differing only in oversized witness bytesIncorrect witness equality for oversized single-item stacks
e1ed5884by Andrew Poelstra+106−273 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6922: Use `try_fold` instead of `fold` in `Sum` impl

This is a code-quality and performance improvement, not a security fix. It changes how the library adds up lists of Bitcoin amounts so that it stops early once an overflow is detected, rather than continuing to process the rest of the list…

No security-relevant signal in commit message or diffRefactor preserves overflow-checking behavior (short-circuits instead of continuing)New API method `NumOpResult::from_result` is a pure inverse of existing `into_result`
86e4d5daby Andrew Poelstra+60−562 files
No security note in commit
Moderate 52 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6893: units: Reject malformed amount strings

This update fixes a bug in how the library reads Bitcoin amount strings like '1.5 BTC'. Previously, certain malformed inputs such as '.', '._', '1_', '1_.0', and '1._0' were incorrectly accepted and treated as valid amounts (often zero), i…

Input validation bypass in amount parserMalformed strings silently parsed as zero or ordinary amountsUnderscore separator placement not enforced
fcb14622by Andrew Poelstra+88−343 files
Vendor flagged security relevance
Low 48 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6921: units: fix div_by_fee_rate_ceil precision

This commit fixes a rounding bug in how the rust-bitcoin library calculates the minimum transaction weight needed to pay a given fee at a given fee rate. The old code rounded the fee rate up too early, which could produce a weight slightly…

Incorrect fee-weight calculation due to premature integer roundingPotential transaction fee shortfall when using div_by_fee_rate_ceilOverflow protection added for Amount::MAX * 4_000_000 intermediate value
b31212e0by Andrew Poelstra+38−82 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6898: Release tracking PR: `consensus-encoding 1.3.0`

This is a routine release-management commit that bumps the version number of the `bitcoin-consensus-encoding` crate from 1.2.0 to 1.3.0 and updates lock files accordingly. It contains no code changes that fix or introduce a security issue.…

0cfc7908by Andrew Poelstra+37−349 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6909: build(deps): bump actions/labeler from 6.2.0 to 7.0.0

This commit updates a GitHub Actions automation tool (actions/labeler) used to automatically tag pull requests with labels. It is a routine dependency version bump from 6.2.0 to 7.0.0, with no indication of a security fix or vulnerability.…

4ed7c068by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6910: build(deps): bump actions/checkout from 7.0.0 to 7.0.1

This commit is a routine update to the GitHub Actions checkout tool used by the project's automated workflows. It only changes version numbers in configuration files and does not alter the actual Bitcoin library code that users run. There …

328c4ae9by Andrew Poelstra+37−3717 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6911: build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0

This commit updates a GitHub Actions helper used to install a Python tool called uv, which runs the zizmor security scanner. The change only bumps the pinned version of the helper from 8.3.2 to 9.0.0. The new version's release notes mentio…

No security-relevant signals in commit or upstream release notesDependency bump in CI only, not in library codeNo CVE or advisory referenced
67600795by Andrew Poelstra+2−22 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6912: build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3

This is a routine Dependabot update that changes the pinned version of GitHub's official CodeQL upload-sarif action from 4.37.0 to 4.37.3 in a single CI workflow. The action only uploads static analysis results to GitHub; it does not touch…

b51cec63by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6913: build(deps): bump dtolnay/rust-toolchain from 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de

This is a routine update to a GitHub Actions helper used to install Rust during automated testing. It only changes the pinned version of the dtolnay/rust-toolchain action in workflow files. There is no change to the actual rust-bitcoin lib…

90330d15by Andrew Poelstra+8−84 files
No security note in commit
Informational 20 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6906: consensus_encoding, primitives: expose exact encoding size for block and transaction

This commit adds a way to ask, in advance, exactly how many bytes a Bitcoin block or transaction will take when serialized. It is a feature addition for the library's encoding system, not a fix for a vulnerability. There is no indication i…

No security-relevant signals in commit message or diffFeature addition: expose exact encoded sizeNo mention of vulnerability, CVE, bug bounty, or security report
1a365d53by Andrew Poelstra+129−1068 files
No security note in commit
Informational 15 AI analysisMessage 88 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump dtolnay/rust-toolchain

This is a routine update by Dependabot that changes which version of a popular GitHub Action (dtolnay/rust-toolchain) is used to install Rust in automated CI workflows. The commit only updates pinned commit hashes in workflow files; it doe…

a31e0b0eby dependabot[bot]+8−84 files
No security note in commit
Informational 15 AI analysisMessage 93 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump github/codeql-action/upload-sarif

This is a routine patch-version update of a GitHub-maintained action used only to upload static-analysis results (SARIF files) from a scheduled CI job. The change does not touch any project source code, cryptographic logic, or user-facing …

2cac6e38by dependabot[bot]+1−11 file
No security note in commit
Informational 15 AI analysisMessage 93 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0

This is a routine automated update by Dependabot that changes the pinned version of a GitHub Action used to install a Python tool called 'uv' in two workflow files. The new version is a major release of the setup-uv action itself, but the …

7d7e7269by dependabot[bot]+2−22 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedImprove hex codec test coverageby Jamil Lambert, PhD · c51ee8db · Apr 21, 2026 · 3 filesMessage 55 · ThinInformational 15Details
Commit message · Jamil Lambert, PhD

Improve hex codec test coverage

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds new unit tests for the existing hexadecimal encoding/decoding code. It does not change any production logic, so it cannot introduce or fix a security vulnerability on its own.

Security candidatecrypto: Move SerializedLegacyPublicKey to cryptoby Mitchell Bagot · 8f809ccd · Apr 21, 2026 · 2 filesMessage 78 · AdequateInformational 15Details
Commit message · Mitchell Bagot

crypto: Move SerializedLegacyPublicKey to crypto

Now that the SerializedLegacyPublicKey has been re-arranged to remove
the strict dependence on PushBytes, it can be trivially moved to the
crypto crate.

Move SerializedLegacyPublicKey to crypto crate and re-export from
bitcoin.
Move associated test to crypto key module.

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit is a simple internal code reorganization. It moves the SerializedLegacyPublicKey type from the main bitcoin crate into the lower-level crypto crate and re-exports it so existing code keeps working. No behavior changes, no bug fixes, and no security implications are visible in the diff.

Security candidateRemove dependence on PushBytes for SerializedLegacyPublicKeyby Mitchell Bagot · 1f3051c9 · Apr 21, 2026 · 1 fileMessage 73 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Remove dependence on PushBytes for SerializedLegacyPublicKey

The SerializedLegacyPublicKey type currently relies on
Borrow<PushBytes> to implement the Borrow and AsRef for [u8]. Since
PushBytes is only in bitcoin, this prevents the simple move. Instead,
the main reference conversion should be Deref for [u8].

Move Deref impl into encapsulating module and redefine
Borrow<PushBytes> in terms of it. Adjust order of Borrow and AsRef
impls.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This is a small internal code cleanup in the rust-bitcoin library. It changes how one public-key wrapper type exposes its underlying byte slice, removing a dependency on another type (PushBytes) so the code can be moved between crates more easily. There is no user-visible behavior change and no security fix.

Lower-priorityCI: update GitHub Actions versions to ensure GA runtime compatibilityby Ismail Daif · ce746b03 · Apr 20, 2026 · 6 filesMessage 74 · AdequateInformational 15Details
Commit message · Ismail Daif

CI: update GitHub Actions versions to ensure GA runtime compatibility

74/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Explains rationale or failure mode! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only updates version numbers and pinned commit hashes for GitHub Actions used in the project's automated CI (continuous integration) workflows. It does not change any of the actual Bitcoin library code that users or applications interact with. There is no indication of a security vulnerability being fixed or introduced.

AI review queuedUpdate API filesby Mitchell Bagot · 8d1dd754 · Apr 20, 2026 · 3 filesMessage 28 · OpaqueInformational 15Details
Commit message · Mitchell Bagot

Update API files

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates automatically-generated API snapshot files. It shows a public type being renamed from EncodableByteIter to EncoderByteIter and changing from borrowing an encodable value to owning an encoder. There is no source code change in the diff, no bug fix, and no security-relevant behavior shown.

Lower-priorityconsensus_encoding: Change EncodableByteIter to EncoderByteIterby Mitchell Bagot · 680fe952 · Apr 20, 2026 · 7 filesMessage 73 · AdequateInformational 18Details
Commit message · Mitchell Bagot

consensus_encoding: Change EncodableByteIter to EncoderByteIter

The EncodableByteIter is currently trait bounded on Encodable. It would
be better if it were instead simplified to be bounded on Encoder, and
renamed to EncoderByteIter, since it is ultimately only a wrapper
around an Encoder, not a special type interacting with Encodable.

Change EncodableByteIter to take an Encoder type directly.
Add Clone derive now that trait bounds allow for it.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 18/100

This is a routine internal refactoring of a Rust Bitcoin library type. It renames EncodableByteIter to EncoderByteIter and changes it to wrap an encoder directly rather than an encodable value. There is no security fix or vulnerability indicated in the commit.

Lower-priorityFix lint errors in taproot-primitivesby Mitchell Bagot · cd2448a3 · Apr 20, 2026 · 1 fileMessage 90 · StrongInformational 15Details
Commit message · Mitchell Bagot

Fix lint errors in taproot-primitives

The taproot-primitives crate has stricter lint requirements than
bitcoin where most of the logic initially came from. In order to ensure
clean CI tests, these should be fixed.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
AI analysis · Informational 15/100

This is a routine code cleanup commit that fixes two Rust lint warnings in the taproot-primitives crate. It adds a Clippy suppression annotation and replaces an integer cast with a safer conversion. There is no security-relevant behavior change.

Lower-priorityMove hash types and LeafVersion to taproot-primitivesby Mitchell Bagot · 918fc424 · Apr 20, 2026 · 7 filesMessage 85 · StrongInformational 19Details
Commit message · Mitchell Bagot

Move hash types and LeafVersion to taproot-primitives

The hash types and LeafVersion enums are required by functionality in
the crypto crate. In order to facilitate the further separation of
logic into the crypto crate, these types need to be split from the
bitcoin crate.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 19/100

This commit is a routine code reorganization: it moves Taproot hash types (like TapLeafHash, TapNodeHash, TapTweakHash) and the LeafVersion enum from the main bitcoin crate into a new taproot-primitives crate. The bitcoin crate then re-exports these types so existing users see no change. There is no security fix or behavior change visible in the diff.

Lower-prioritySplit TapNodeHash and TapLeafHash logic into extension traitsby Mitchell Bagot · c512ab7e · Apr 20, 2026 · 2 filesMessage 73 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Split TapNodeHash and TapLeafHash logic into extension traits

The impl blocks for TapNodeHash and TapLeafHash use types and functions
that can't be easily moved to a new crate. Since the functionality is
not required on the types in primitives, it can be split into extension
traits to be left in bitcoin.

Introduce TapNodeHashExt and TapLeafHashExt extension traits. Move
functionality from TapNodeHash and TapLeafHash to the traits.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit is a routine internal code reorganization. It moves some Taproot hash helper methods from direct implementations on two types into Rust 'extension traits' so the underlying types can live in a more basic crate while the extra logic stays in the main bitcoin crate. There is no change to what the code computes or any security behavior.

Lower-priorityCreate an empty taproot-primitives crateby Mitchell Bagot · 1c53e49a · Apr 20, 2026 · 6 filesMessage 45 · ThinInformational 15Details
Commit message · Mitchell Bagot

Create an empty taproot-primitives crate

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit creates a brand-new, empty Rust crate named 'bitcoin-taproot-primitives'. It contains no executable code, no new logic, and no changes to existing behavior. It is purely a project structure change preparing for future development.

Security candidatecrypto: Remove error conversion From implsby Mitchell Bagot · e986053a · Apr 20, 2026 · 2 filesMessage 68 · AdequateInformational 19Details
Commit message · Mitchell Bagot

crypto: Remove error conversion From impls

From impls for conversions between error types represent a public api
commitment. Since we can't know how the error types may need to change
as the crate progresses, it's best to remove these now and reintroduce
them later if we find them necessary and/or useful for users.

Remove all From<BarError> for FooError in crypto, replacing uses with
map_err where appropriate.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 19/100

This commit removes automatic error-conversion shortcuts in the crypto module of the rust-bitcoin library. It does not fix a bug or vulnerability; it is a deliberate API cleanup to avoid promising too much to future users. Existing code that relied on the removed conversions will need minor updates, but runtime behavior is unchanged.

Security candidatecrypto: Re-export key types at crate rootby Mitchell Bagot · adf52bbc · Apr 20, 2026 · 1 fileMessage 60 · AdequateInformational 15Details
Commit message · Mitchell Bagot

crypto: Re-export key types at crate root

Re-export the key types at the crate root, similar to the re-exports in
bitcoin.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit simply makes several existing key types easier to import by re-exporting them at the top level of the crypto crate. It does not change any behavior, logic, or security properties of the code.

Security candidatecrypto: Add pub extern crate for crates with public api typesby Mitchell Bagot · fd25de60 · Apr 20, 2026 · 1 fileMessage 85 · StrongInformational 16Details
Commit message · Mitchell Bagot

crypto: Add pub extern crate for crates with public api types

In crypto, various types from child crates are present in the public
api, including base58::Error, network::NetworkKind, secp256k1 keys and
io traits. In order to simplify dependency handling, these crates
should be exposed through pub extern crate exports in the root of the
crypto crate.

Add pub extern crate statements for base58, network, io and secp256k1.
Remove comment on hex_stable re-export to match new policy.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
cryptography-sensitive path
AI analysis · Informational 16/100

This change simply re-exports a few internal Rust crates through the public API of the `crypto` sub-crate so users don't have to add those dependencies manually. It is a routine dependency-management and API-ergonomics patch with no apparent security relevance.

AI review queuedMove transaction encoding tests to primitives/tests/encoding.rsby busayo-OD · 3951134d · Apr 19, 2026 · 2 filesMessage 95 · StrongInformational 15Details
Commit message · busayo-OD

Move transaction encoding tests to primitives/tests/encoding.rs

This change moves transaction consensus encoding and decoding tests,
along with shared helpers and constants, into a dedicated test file.
Removes the FIXME comment that requested this change.

The assert_eq! on the no-witnesses error is replaced with matches!
on the outer error type due to visibility constraints.

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply moves existing transaction encoding and decoding tests from one file to another. It does not change any production code, only reorganizes test code. The only functional tweak is replacing one detailed error comparison with a broader pattern match, because the moved test can no longer see a private inner error type. There is no security issue here.

Security candidateMove most key types to crypto crateby Mitchell Bagot · c96fc0fd · Apr 19, 2026 · 8 filesMessage 68 · AdequateInformational 18Details
Commit message · Mitchell Bagot

Move most key types to crypto crate

The key types in bitcoin are largely disconnected from bitcoin outside
of interdependencies within the crypto module. With the other
submodules moved, the keys can now be trivially moved to the crypto
crate.

Move and re-export all crypto key types and relevant errors from crypto
crate.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 18/100

This commit is a large but straightforward internal code reorganization. It moves Bitcoin key types (public keys, private keys, keypairs, and related errors) from the main `bitcoin` crate into a new `crypto` sub-crate, then re-exports them so existing users of the `bitcoin` crate see the same public API. There is no indication of a security bug being fixed or introduced; it is a refactoring to improve the project's modular structure.

Security candidateBump crypto crate versionby Mitchell Bagot · 345ad946 · Apr 19, 2026 · 5 filesMessage 58 · ThinInformational 15Details
Commit message · Mitchell Bagot

Bump crypto crate version

With the move of types complete, the crypto crate is in a suitable
state for release and integration with bitcoin.

Bump crypto version number to 0.1.0.
Update crypto changelog.
Adjust bitcoin cargo TOML to match new version number.
Update lock files.

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit is a routine version bump for an internal Rust crate. It changes the package version from 0.0.0 to 0.1.0, updates dependency references and lock files, and records the migration of code into the crate in the changelog. There are no code logic changes and no security-relevant behavior changes visible in the diff.

Security candidateFix lint errors in crypto crateby Mitchell Bagot · c65f4c9f · Apr 19, 2026 · 1 fileMessage 80 · StrongInformational 15Details
Commit message · Mitchell Bagot

Fix lint errors in crypto crate

The prior code move introduces a variety of lint errors due to the lax
lint requirements from bitcoin compared to the other crates.

Fix all lint errors in crypto crate's sighash module.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit only cleans up style warnings in a Rust source file. It replaces wildcard imports with explicit Self:: references, adds a documentation comment, and fixes a minor formatting issue in a doc comment. There is no change to program behavior or security.

Security candidateMove minimal sighash types to crypto crateby Mitchell Bagot · d4a3f75a · Apr 19, 2026 · 7 filesMessage 68 · AdequateInformational 18Details
Commit message · Mitchell Bagot

Move minimal sighash types to crypto crate

While many of the sighash types are intertwined with taproot and
bitcoin dependencies, some can be moved and re-exported trivially.

Move and re-export EcdsaSighashType, TapSighashType,
InvalidSighashTypeError, NonStandardSighashTypeError and
SighashTypeParseError to crypto crate.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 18/100

This commit is a routine code reorganization: it moves some Bitcoin signature-hash type definitions (EcdsaSighashType, TapSighashType, and related error types) from the main bitcoin crate into a new bitcoin-crypto sub-crate, then re-exports them so existing users see no change. There is no functional change to how signatures or transactions are validated.

Security candidateBreak split_anyonecanpay_flag functions to SplitAnyoneCanPay traitby Mitchell Bagot · 652a0039 · Apr 19, 2026 · 1 fileMessage 73 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Break split_anyonecanpay_flag functions to SplitAnyoneCanPay trait

The split_anyonecanpay_flag functions are pub(crate). Since we don't
want them to be in the public API, and they're exclusively used by
logic that will remain in bitcoin, we can split them into a pub(crate)
trait to be left behind.

Introduce SplitAnyoneCanPay trait and implement for TapSigHashType and
EcdsaSighashType by moving the corresponding split_anyonecanpay_flag
functions to them.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit is a simple internal code cleanup in the rust-bitcoin library. It moves two nearly identical helper functions into a shared internal trait, without changing what the code does or how it behaves. There is no security issue here.

Security candidateReturn TapSighashType parse error in PsbtSighashType FromStrby Mitchell Bagot · 910ad0d4 · Apr 19, 2026 · 1 fileMessage 73 · AdequateInformational 19Details
Commit message · Mitchell Bagot

Return TapSighashType parse error in PsbtSighashType FromStr

The FromStr trait for PsbtSighashType uses the TapSighashType FromStr
to parse from a string. On failure, this generates the same
SighashTypeParseError that is currently returned. Rather than manually
constructing the error, we can just return the error result from
attempting to parse s as a TapSighashType.

Return the error result of the TapSighashType FromStr impl rather than
manually constructing a new error in PsbtSighashType FromStr impl.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing boundarysigning or wallet path
AI analysis · Informational 19/100

This is a small code-quality change in how a Bitcoin-related Rust library reports parsing errors for a special sighash type. It makes the error message come directly from the underlying Taproot parser instead of being manually rebuilt. There is no direct security vulnerability here, but it slightly improves error-message accuracy and removes a tiny bit of duplicated logic.

Security candidateFix lint errors in crypto crateby Mitchell Bagot · ff655ac5 · Apr 19, 2026 · 1 fileMessage 80 · StrongInformational 15Details
Commit message · Mitchell Bagot

Fix lint errors in crypto crate

The prior code move introduces a variety of lint errors due to the lax
lint requirements from bitcoin compared to the other crates.

Fix all lint errors in crypto crate's ecdsa module.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit is a routine code cleanup in the rust-bitcoin crypto crate. It fixes compiler lint warnings by adding documentation comments, adjusting number formatting, and making minor style changes. There is no functional change to how signatures are created, validated, or parsed, and no security issue is present.

Security candidateSplit raw_ecdsa_sign_recoverable function to PrivateKeyExtby Mitchell Bagot · bb8fed10 · Apr 19, 2026 · 2 filesMessage 73 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Split raw_ecdsa_sign_recoverable function to PrivateKeyExt

The raw_ecdsa_sign_recoverable function on PrivateKey exists purely to
provide the low level functionality used in the sign_message module of
bitcoin. Since this is not necessary at this early stage in the crypto
crate, it should be moved to a new extension trait prior to the move.

Introduce PrivateKeyExt and move raw_ecdsa_sign_recoverable to the new
extension trait.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine internal code reorganization. It moves a low-level ECDSA signing helper method from the main PrivateKey implementation into a new extension trait called PrivateKeyExt, and updates the one place that uses it to import the trait. There is no change to what the code does or any security fix.

Security candidateMove ecdsa module to crypto crateby Mitchell Bagot · 31168f7f · Apr 19, 2026 · 7 filesMessage 68 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Move ecdsa module to crypto crate

The ecdsa module has no dependencies in bitcoin outside of some in the
sighash module of crypto. Following the previous sighash move, this
entire module can now be trivially moved to the crypto crate.

Move the ecdsa module to the crypto crate.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine internal code reorganization. It moves the ECDSA signature module from the main 'bitcoin' crate into a smaller 'crypto' sub-crate, then re-exports it so existing users see no change. There is no security fix or vulnerability here.

Security candidateSplit methods to extension traits on public keysby Mitchell Bagot · fffcd586 · Apr 19, 2026 · 2 filesMessage 68 · AdequateInformational 18Details
Commit message · Mitchell Bagot

Split methods to extension traits on public keys

The p2wpkh_script_code functions on FullPublicKey and LegacyPublicKey
rely on functionality only present in the bitcoin crate. Since this
will not be easy to move out, these functions should be moved to
extension traits prior to the move.

Further, the to_bytes method on LegacyPublicKey relies on
SerializedLegacyPublicKey, a type which itself relies on conversions
to and from PushBytes, a type only available in bitcoin. Since the
serialised type cannot be moved at present, the to_bytes must be left
behind in the extension trait for now.

Introduce FullPublicKeyExt and LegacyPublicKeyExt and move the
corresponding p2wpkh_script_code functions to them from the public
key types. Move to_bytes on LegacyPublicKey to LegacyPublicKeyExt.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 18/100

This commit is a routine internal code reorganization. It moves a few public-key helper methods into Rust 'extension traits' so the underlying key types can be relocated to a different crate later. The actual behavior of the moved functions is unchanged, and there is no indication of a bug fix or security patch.

Lower-priorityfuzz: Install cargo-fuzz for verify-execution jobby Ismail Daif · 14e8024e · Apr 18, 2026 · 2 filesMessage 55 · ThinInformational 15Details
Commit message · Ismail Daif

fuzz: Install cargo-fuzz for verify-execution job

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100

This commit is a routine fix to the project's automated fuzz-testing pipeline. It adds an installation step for the 'cargo-fuzz' tool in one CI job and updates a script that generates the workflow file. There is no change to the actual Bitcoin library code that users depend on, and nothing in the commit suggests a security vulnerability or fix.