RB
← All projectsRust Bitcoin

rust-bitcoin

Rust library for Bitcoin data structures, serialization, consensus encoding, and scripts.

BitcoinCryptographic librariesNormal
Repository coverage

2313 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

532security candidates511second-pass queue2206AI analyses
133commits · 30 days
267commits · 60 days
1103commits · 180 days
2024commits · 365 days
Backfill bands
Aug 5 → Feb 6787 seen32 candidatesComplete
Feb 6 → Jun 6878 seen53 candidatesComplete
Jun 6 → Jul 6211 seen15 candidatesComplete
Jul 6 → Aug 5184 seen2 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

66/100 average clarity
510Strong · 80–100
1085Adequate · 60–79
567Thin · 40–59
151Opaque · 0–39
20security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Andrew Poelstra23179157290
Mitchell Bagot649193645068
Tobin C. Harding41566410063
jrakibi944994068
Nick Johnson19121190060
Jamil Lambert, PhD11919116061
satsfy (Renato Britto)381527066
Fmt Bot331431045
Trevor Arjeski111111069
Shing Him Ng31731056
Martin Habovstiak30628068
Ismail Daif22622050
Analysis record

Published AI watches

Last scanned 20 minutes ago

Moderate 62 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6954: units: serialize unsigned amounts as u64

This commit fixes a mismatch in how unsigned Bitcoin amounts were serialized versus deserialized when using certain compact binary formats. Previously, an unsigned amount (like 100 satoshis) was written as a signed number, which caused for…

Data integrity bug: serialized values decode to different numeric values in varint binary formatsRange-check failure: Amount::MAX and large values near the cap fail deserialization after round-tripSerde serialize/deserialize hint mismatch for unsigned amount types
295c9d8aby Andrew Poelstra+66−112 files
No security note in commit
Low 25 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6955: key_expression: preserve master-key invariants in Xpub Arbitrary

This change fixes a bug in test-only code that generates random fake Bitcoin extended public keys (xpubs). Previously, when generating a master xpub (depth 0), the code could pick random values for the parent fingerprint and child number, …

BIP32 master-key invariant violation in generated test dataEncode/decode round-trip failure for generated master xpubsFix aligns Xpub::arbitrary with existing Xpriv::arbitrary behavior
4116ecc6by Andrew Poelstra+35−31 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6947: build(deps): bump cargo-bins/cargo-binstall from 1.21.0 to 1.21.1

This commit updates the version of a helper tool (cargo-binstall) used only inside GitHub Actions automation. It is a routine dependency bump by Dependabot and does not change any code that ships to users. There is no indication of a secur…

c1be49cbby Andrew Poelstra+2−22 files
No security note in commit
High 70 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6919: Sanitize serde size hints before allocating

This commit fixes a denial-of-service weakness in how the library deserializes lists of Bitcoin data (witnesses, amounts, fee rates) from untrusted input. Before the fix, a few bytes of attacker-controlled data could claim a list would con…

Untrusted serde size hint fed directly into Vec::with_capacityPotential memory exhaustion / OOM kill from small malicious inputDenial-of-service vector in deserialization paths
55ddbc0cby Andrew Poelstra+88−105 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

This commit fixes how the Rust Bitcoin library calculates old-style (legacy) transaction signatures when the spending script contains a special opcode called OP_CODESEPARATOR. Previously the library did not handle this opcode at all, which…

Protocol correctness fix for legacy sighash serializationOP_CODESEPARATOR handling added to match Bitcoin Core consensus behaviorPreviously omitted test vectors restored, indicating prior non-compliance
5b815281by Andrew Poelstra+600−3093 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6948: build(deps): bump taiki-e/install-action from 2.83.2 to 2.85.4

This is a routine update by Dependabot to the version of a third-party GitHub Action used in the project's automated testing workflows. The change only affects internal continuous integration (CI) scripts, not the actual Bitcoin library co…

d1431904by Andrew Poelstra+2−22 files
No security note in commit
Low 33 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

This commit fixes a small but real bug in a Rust helper that reads fixed-size chunks from a data slice. The helper was supposed to safely return 'nothing' when asked to read past the end of the data, but it accidentally added two numbers t…

Integer overflow in bounds-checking helperContract violation: method documented to return None on out-of-bounds access could panic insteadDebug-build panic (denial of service) possible
c6e80843by Andrew Poelstra+2−11 file
Vendor flagged security relevance
Moderate 62 AI analysisMessage 73 · Adequate
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Fix integer overflow in `get_array`

This commit fixes a bug in a Rust helper method called `get_array`, which is meant to safely read a fixed-size chunk from a slice and return nothing if the requested range is out of bounds. The bug was that the code added the caller's offs…

Integer overflow in bounds calculationPotential panic due to violated internal length expectationCaller-controlled arithmetic used for memory access bounds
56fb1287by Martin Habovstiak+2−11 file
Vendor flagged security relevance
High 71 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6915: primitives: Fix `Witness` handling of oversized items

This commit fixes a bug in how the Rust Bitcoin library counts and compares transaction witness data when a witness contains an oversized item. Previously, several functions relied on an iterator that silently skips oversized items, causin…

Inconsistent serialization/iterator behavior for oversized witness itemswtxid collision risk between transactions differing only in oversized witness bytesIncorrect witness equality for oversized single-item stacks
e1ed5884by Andrew Poelstra+106−273 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6922: Use `try_fold` instead of `fold` in `Sum` impl

This is a code-quality and performance improvement, not a security fix. It changes how the library adds up lists of Bitcoin amounts so that it stops early once an overflow is detected, rather than continuing to process the rest of the list…

No security-relevant signal in commit message or diffRefactor preserves overflow-checking behavior (short-circuits instead of continuing)New API method `NumOpResult::from_result` is a pure inverse of existing `into_result`
86e4d5daby Andrew Poelstra+60−562 files
No security note in commit
Moderate 52 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6893: units: Reject malformed amount strings

This update fixes a bug in how the library reads Bitcoin amount strings like '1.5 BTC'. Previously, certain malformed inputs such as '.', '._', '1_', '1_.0', and '1._0' were incorrectly accepted and treated as valid amounts (often zero), i…

Input validation bypass in amount parserMalformed strings silently parsed as zero or ordinary amountsUnderscore separator placement not enforced
fcb14622by Andrew Poelstra+88−343 files
Vendor flagged security relevance
Low 48 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6921: units: fix div_by_fee_rate_ceil precision

This commit fixes a rounding bug in how the rust-bitcoin library calculates the minimum transaction weight needed to pay a given fee at a given fee rate. The old code rounded the fee rate up too early, which could produce a weight slightly…

Incorrect fee-weight calculation due to premature integer roundingPotential transaction fee shortfall when using div_by_fee_rate_ceilOverflow protection added for Amount::MAX * 4_000_000 intermediate value
b31212e0by Andrew Poelstra+38−82 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6898: Release tracking PR: `consensus-encoding 1.3.0`

This is a routine release-management commit that bumps the version number of the `bitcoin-consensus-encoding` crate from 1.2.0 to 1.3.0 and updates lock files accordingly. It contains no code changes that fix or introduce a security issue.…

0cfc7908by Andrew Poelstra+37−349 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6909: build(deps): bump actions/labeler from 6.2.0 to 7.0.0

This commit updates a GitHub Actions automation tool (actions/labeler) used to automatically tag pull requests with labels. It is a routine dependency version bump from 6.2.0 to 7.0.0, with no indication of a security fix or vulnerability.…

4ed7c068by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6910: build(deps): bump actions/checkout from 7.0.0 to 7.0.1

This commit is a routine update to the GitHub Actions checkout tool used by the project's automated workflows. It only changes version numbers in configuration files and does not alter the actual Bitcoin library code that users run. There …

328c4ae9by Andrew Poelstra+37−3717 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6911: build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0

This commit updates a GitHub Actions helper used to install a Python tool called uv, which runs the zizmor security scanner. The change only bumps the pinned version of the helper from 8.3.2 to 9.0.0. The new version's release notes mentio…

No security-relevant signals in commit or upstream release notesDependency bump in CI only, not in library codeNo CVE or advisory referenced
67600795by Andrew Poelstra+2−22 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6912: build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3

This is a routine Dependabot update that changes the pinned version of GitHub's official CodeQL upload-sarif action from 4.37.0 to 4.37.3 in a single CI workflow. The action only uploads static analysis results to GitHub; it does not touch…

b51cec63by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6913: build(deps): bump dtolnay/rust-toolchain from 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de

This is a routine update to a GitHub Actions helper used to install Rust during automated testing. It only changes the pinned version of the dtolnay/rust-toolchain action in workflow files. There is no change to the actual rust-bitcoin lib…

90330d15by Andrew Poelstra+8−84 files
No security note in commit
Informational 20 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6906: consensus_encoding, primitives: expose exact encoding size for block and transaction

This commit adds a way to ask, in advance, exactly how many bytes a Bitcoin block or transaction will take when serialized. It is a feature addition for the library's encoding system, not a fix for a vulnerability. There is no indication i…

No security-relevant signals in commit message or diffFeature addition: expose exact encoded sizeNo mention of vulnerability, CVE, bug bounty, or security report
1a365d53by Andrew Poelstra+129−1068 files
No security note in commit
Informational 15 AI analysisMessage 88 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump dtolnay/rust-toolchain

This is a routine update by Dependabot that changes which version of a popular GitHub Action (dtolnay/rust-toolchain) is used to install Rust in automated CI workflows. The commit only updates pinned commit hashes in workflow files; it doe…

a31e0b0eby dependabot[bot]+8−84 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateAdd SHA256 midstate conversion to Midstateby Jamil Lambert, PhD · e3ead07c · Mar 25, 2026 · 3 filesMessage 68 · AdequateInformational 19Details
Commit message · Jamil Lambert, PhD

Add SHA256 midstate conversion to Midstate

C-CONV-SPECIFIC states "Conversions should live with the more specific
of the involved types".

Add SHA256 midstate to engine conversion to the more specific
`Midstate`.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 19/100

This commit simply moves an existing SHA256 midstate-to-engine conversion from one place in the code to another. The actual logic is unchanged; it is a code-organization refactor following a Rust API design guideline. There is no security fix or vulnerability here.

Security candidateRun the formatterby Jamil Lambert, PhD · 35e8b9ad · Mar 25, 2026 · 6 filesMessage 55 · ThinInformational 15Details
Commit message · Jamil Lambert, PhD

Run the formatter

Done after the changes so that the previous patch diff more clearly
shows the code move.

55/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Explains rationale or failure mode
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit is purely a code formatting cleanup. It removes blank lines, reorders some import/module declarations, and collapses a few trivial function bodies onto one line. There are no functional changes to how the software behaves, and no security implications.

AI review queuedUpdate api filesby Jamil Lambert, PhD · c3e89fb7 · Mar 25, 2026 · 3 filesMessage 28 · OpaqueInformational 15Details
Commit message · Jamil Lambert, PhD

Update api files

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates generated API snapshot text files to include a newly added public function, `Midstate::to_engine`. It does not change any source code, fix a bug, or alter program behavior. There is no security relevance visible in the commit itself.

AI review queuedprimitives: Update API filesby Mitchell Bagot · 78443e30 · Mar 25, 2026 · 2 filesMessage 35 · OpaqueInformational 15Details
Commit message · Mitchell Bagot

primitives: Update API files

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates generated API snapshot files that list what types and functions are publicly available in the library. It adds entries for a new Signet-related script type that was already introduced elsewhere in the codebase. There is no actual code change, no bug fix, and no security relevance visible in the diff.

Lower-priorityAdd SignetBlockScript/Buf for signet challenge scriptsby Mitchell Bagot · 456425ca · Mar 25, 2026 · 7 filesMessage 73 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Add SignetBlockScript/Buf for signet challenge scripts

Custom signets require a challenge script (or block script). But our
new script types do not provide a tag for that. Currently we are using
WitnessScriptBuf, which has the correct typing, but is sematically
unclear.

Add SignetBlockScript and SignetBlockScriptBuf script types to
represent challenge witness scripts for custom signets.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit is a straightforward code-quality improvement in the rust-bitcoin library. It introduces new type names (SignetBlockScript and SignetBlockScriptBuf) to represent signet challenge scripts more clearly, replacing the previous use of WitnessScript types. There is no security bug being fixed here and no behavior change that would affect users' funds or network safety.

AI review queuedUpdate API text filesby Bortlesboat · 12627ed3 · Mar 25, 2026 · 9 filesMessage 28 · OpaqueInformational 15Details
Commit message · Bortlesboat

Update API text files

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates generated API text files that list the public interface of the Rust Bitcoin crates. The changes reflect newly added standard Rust trait implementations (From<Infallible>) for various error types. These are not code changes and do not alter runtime behavior, so there is no security impact.

AI review queuedImplement From<Infallible> for all public error typesby Andrew Barnes · c425a0cf · Mar 25, 2026 · 10 filesMessage 81 · StrongInformational 19Details
Commit message · Andrew Barnes

Implement From<Infallible> for all public error types

Add From<Infallible> implementations for 31 public error types
across the consensus_encoding, primitives, and units crates. Each
impl is placed directly below its type declaration. For hidden
error types, the impl is placed below the inner type declaration.

Closes: #5767

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathparser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit adds standard Rust trait implementations that let the library's error types be automatically converted from an 'impossible' error type (Infallible). It is a routine API-ergonomics improvement with no security relevance: Infallible can never actually be produced at runtime, so these conversions can never be triggered by an attacker.

Security candidateChange sign_message::sign to take &PrivateKeyby Mitchell Bagot · d9efc06e · Mar 25, 2026 · 2 filesMessage 90 · StrongInformational 18Details
Commit message · Mitchell Bagot

Change sign_message::sign to take &PrivateKey

The sign_message::sign function in bitcoin currently takes a
secp256k1::SecretKey. In order to move away from using secp types in
the api, this should instead be a PrivateKey. Further, since we hope to
remove Copy from PrivateKey, APIs should be designed to take references
where possible.

Introduce raw_ecdsa_sign_recoverable to PrivateKey.
Change sign_message::sign to take &PrivateKey instead of SecretKey.
Adjust test cases accordingly.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 18/100

This commit is a routine API refactor in the rust-bitcoin library. It changes the message-signing function so it accepts a higher-level PrivateKey reference instead of a low-level secp256k1 secret key, and moves the underlying signing logic into a new PrivateKey method. There is no indication this fixes a security bug; it is a design cleanup to hide internal cryptographic types from users and prepare for future API changes.

AI review queuedRun the formatterby Mitchell Bagot · bf983044 · Mar 25, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · Mitchell Bagot

Run the formatter

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is purely a code-formatting cleanup. It removes blank lines, collapses a struct literal onto one line, reorders re-exports and module declarations, and adds a blank line between imports. There is no functional change and no security relevance.

Lower-priorityCI: Add formatting jobby Tobin C. Harding · cf39b401 · Mar 25, 2026 · 2 filesMessage 63 · AdequateInformational 15Details
Commit message · Tobin C. Harding

CI: Add formatting job

Add a `fmt --check` job. As discussed in PR 5866 lets have a job and
a policy that PRs with red fmt jobs can merge if they get past
Andrew's CI. This will encourage most devs to format their PRs without
forcing everyone to install the nightly toolchain.

63/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only adds a code-formatting check to the project's continuous integration (CI) pipeline and updates the contributor guide to explain the formatting policy. It does not change any production code, cryptographic logic, network handling, or data parsing. There is no security issue here.

Lower-priorityFix code comment so formatter doesn't munge itby Tobin C. Harding · 20a65b49 · Mar 25, 2026 · 1 fileMessage 60 · AdequateInformational 15Details
Commit message · Tobin C. Harding

Fix code comment so formatter doesn't munge it

Make the code comment more ugly than it is but less than the formatter
will make it.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit only rearranges code comments in a test file to prevent an automated code formatter from reformatting them awkwardly. No program logic, behavior, or security-sensitive code was changed.

AI review queuedRun the formatterby Tobin C. Harding · 88fdfcef · Mar 25, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · Tobin C. Harding

Run the formatter

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only runs an automated code formatter. It reorders imports, removes blank lines, and collapses some struct literals onto single lines. There are no functional code changes and no security relevance.

Security candidateci: upgrade cargo-rbmtby Nick Johnson · 78348b4a · Mar 24, 2026 · 33 filesMessage 78 · AdequateInformational 15Details
Commit message · Nick Johnson

ci: upgrade cargo-rbmt

This version of cargo-rbmt dropped the "with" and "without" feature set
generating keys for the test matrix. Replicating the important sets with
the exact_features key and depending on the random sets for the rest. I
didn't bother to add the "arbitrary" feature to the exact_feature sets
since it doesn't seem critical.

78/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
cryptography-sensitive pathboot or update path
AI analysis · Informational 15/100

This commit is a routine maintenance update to the project's automated testing setup. It upgrades an internal tool called cargo-rbmt and moves its configuration from separate files into each crate's Cargo.toml package metadata. It also changes how nightly and stable Rust compiler versions are tracked, storing them in the workspace Cargo.toml instead of separate version files. There are no changes to the actual Bitcoin library code that users depend on, and no security-relevant behavior is modified.

Lower-priorityRemove rustdocs from pub extern crate re-exportsby Jamil Lambert, PhD · 95b1cd21 · Mar 24, 2026 · 4 filesMessage 68 · AdequateInformational 15Details
Commit message · Jamil Lambert, PhD

Remove rustdocs from pub extern crate re-exports

The docs are not rendered and are inconsistently applied across the
repo.

Remove all docs from pub extern crate re-exports.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit only removes documentation comments from public crate re-exports. It does not change any executable code, APIs, or behavior. There is no security relevance.

AI review queuedUpdate API filesby busayo-OD · 5976a31e · Mar 24, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · busayo-OD

Update API files

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates generated API snapshot text files. It removes lines that list certain error-conversion functions from the public API surface, but it does not change any actual Rust source code, logic, or behavior. There is no security-relevant change visible in the diff.

AI review queuedRemove From<SubError> for Error implsby busayo-OD · 39c6e225 · Mar 24, 2026 · 7 filesMessage 45 · ThinInformational 17Details
Commit message · busayo-OD

Remove From<SubError> for Error impls

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit removes automatic conversion traits (From implementations) that let sub-errors be silently turned into parent errors. It replaces them with explicit error wrapping at each call site. This is a code-quality and API-clarity change, not a security fix. There is no evidence in the commit message or diff that it addresses a vulnerability, exploit, or bug that could affect users.

AI review queuedRun the formatterby Mitchell Bagot · 1b962b50 · Mar 24, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · Mitchell Bagot

Run the formatter

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is purely a code-formatting cleanup. It removes blank lines, reorders imports, and lets an automated formatter rewrap a few lines. There are no functional changes to how the software behaves, and nothing in the diff suggests a security fix or vulnerability.

Lower-priorityp2p: Fix ExactSizeEncoder impl on CommandStringEncoderby Mitchell Bagot · 1ab6fe25 · Mar 24, 2026 · 1 fileMessage 73 · AdequateLow 26Details
Commit message · Mitchell Bagot

p2p: Fix ExactSizeEncoder impl on CommandStringEncoder

The ExactSizeEncoder trait is supposed to return the size of the
remaining data in the encoder. That is, as chunks are encoded and
returned to the caller, .len() should decrease, eventually reaching 0.
The ExactSizeEncoder impl for CommandStringEncoder uses a hard-coded
length, preventing this behaviour.

Change ExactSizeEncoder impl on CommandStringEncoder to call through
to the inner ArrayEncoder impl.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Low 26/100

This commit fixes a small but real bug in a Bitcoin peer-to-peer networking library written in Rust. A helper object that encodes message command names (like "version") was incorrectly reporting that it always had 12 bytes left to send, even after some bytes had already been consumed. The fix makes it report the actual remaining length. The bug could mislead callers that rely on the remaining-length promise, but the commit does not show a direct path to stealing funds or remote code execution.

Security candidateIntroduce serialisation functions for PublicKeyby Mitchell Bagot · de942b87 · Mar 24, 2026 · 2 filesMessage 80 · StrongInformational 19Details
Commit message · Mitchell Bagot

Introduce serialisation functions for PublicKey

Currently, the bitcoin::PublicKey type cannot be serialised in a
controlled manner without first converting to an underlying secp256k1
type. Since we want to avoid users needing secp types, serialisation
should be possible with just the bitcoin wrapper type.

Introduce serialize_compressed and serialize_uncompressed functions
on PublicKey that pass through to the corresponding secp functions.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
cryptography-sensitive path
AI analysis · Informational 19/100

This commit adds two new helper methods, serialize_compressed and serialize_uncompressed, to the bitcoin::PublicKey type. Previously, users had to reach into the underlying secp256k1 library to serialize a public key. The change simply wraps that existing behavior in a more convenient API and updates internal callers to use the new methods. There is no indication of a security bug being fixed.

Security candidateIntroduce roundtrip tests for all key typesby Mitchell Bagot · 65258cd1 · Mar 24, 2026 · 1 fileMessage 90 · StrongInformational 15Details
Commit message · Mitchell Bagot

Introduce roundtrip tests for all key types

In order to make sure that the key types can be converted to/from their
corresponding secp types, add tests that roundtrip from bitcoin ->
secp -> bitcoin for all main key types.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit only adds new automated tests that check whether Bitcoin-style cryptographic keys can be converted to and from the underlying secp256k1 library's key types. It does not change any production code, fix a bug, or alter behavior. There is no security issue here.

Security candidateMake with_serialized a public function on PublicKeyby Mitchell Bagot · 2c08753a · Mar 24, 2026 · 1 fileMessage 73 · AdequateInformational 16Details
Commit message · Mitchell Bagot

Make with_serialized a public function on PublicKey

The with_serialized function on PublicKey allows for a callback
function to be called with the key serialised in a form based on the
compressedness flag. At present, this is only used internally in the
key module.

Make with_serialized pub and add docs.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 16/100

This commit simply changes an existing internal helper function to be publicly usable and adds documentation and examples. It does not fix a bug, change behavior, or introduce any new security-sensitive logic. The function already existed and behaved the same way; only its visibility changed from private to public.

Security candidateAdd to_secret_bytes to PrivateKeyby Mitchell Bagot · 9feba0df · Mar 24, 2026 · 1 fileMessage 58 · ThinInformational 16Details
Commit message · Mitchell Bagot

Add to_secret_bytes to PrivateKey

Private keys have statically-known length of 32 bytes, unlike public
keys. To simplify roundtrips with from_byte_array and secp equivalents,
a function to return the fixed length array should be present.

Introduce to_secret_bytes function to PrivateKey. Replace to_vec range
implementation with to_secret_bytes().to_vec().

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
Why it was queued
secret or key materialcryptography-sensitive path
AI analysis · Informational 16/100

This commit adds a new helper method, to_secret_bytes, to the PrivateKey type in the rust-bitcoin library. It returns a private key as a fixed 32-byte array instead of a variable-length vector. The existing to_secret_vec method is rewritten to use the new helper. There is no visible security fix or behavior change; it is a routine API convenience addition.

Lower-priorityCI: Delete the readmeby Tobin C. Harding · 20f2e382 · Mar 23, 2026 · 1 fileMessage 63 · AdequateInformational 15Details
Commit message · Tobin C. Harding

CI: Delete the readme

The readme is stale now. Furthermore, when I originally wrote it I
thought the 20 job limit was per user as in the user pushing PRs but
its per user/org as in the thing holding each repo. So for us its per
`rust-bitcoin` org - all the repos and all the devs pushing to those
repos. Feels like we are too poor to have proper CI which is horeshit
right there.

Anyways, we are leaving GitHub soon so it doesn't matter now but lets
delete the stale readme before we go.

63/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit simply deletes a stale README file inside the GitHub workflows folder. It contains only documentation about CI job names and GitHub Actions usage limits. No code, configuration, or security controls were changed.

Security candidatehashes: Add SHA256d dispatch and public APIby jrakibi · 629cfcb7 · Mar 23, 2026 · 2 filesMessage 68 · AdequateInformational 16Details
Commit message · jrakibi

hashes: Add SHA256d dispatch and public API

Add sha256d dispatcher that currently handles 2-way ARM,
with the idea to extend to 4-way, 8-way, and 2-way x86.
we also expose a public API that will be used in merkle
root computation (in a follow up PR)

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 16/100

This commit adds a new performance-oriented function for computing many double-SHA256 hashes at once, with a special two-at-a-time path for ARM CPUs that support SHA2 hardware instructions. It also exposes that function as a new public API. There is nothing in the diff that fixes a bug, checks bounds incorrectly, or introduces an obvious security flaw; it appears to be a routine optimization and API addition.

Security candidatehashes: interleave two independent hashes for 2-way SHA256dby jrakibi · 0fbfbd14 · Mar 23, 2026 · 1 fileMessage 81 · StrongInformational 18Details
Commit message · jrakibi

hashes: interleave two independent hashes for 2-way SHA256d

ARM SHA256H/H2 instructions take 4 cycles to produce a
result. the next `SHA256H` needs the result of the current
one as input, so the CPU has to wait until it is ready.
(in Transform 2 for eg, 3 out of every 4 cycles are wasted
doing nothing)

we fill those wasted cycles by computing a second independent
hash alongside the first.

See https://developer.arm.com/documentation/PJDOC-466751330-7215/r4p1/
(Section 3.20) for Cortex-A76 instruction timings. The exact
latency may differ on other ARM chips but the concept is the
same

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive path
AI analysis · Informational 18/100

This commit is a performance optimization for SHA256 double hashing on 64-bit ARM processors. It rewrites a single-hash ARM hardware-accelerated routine to compute two independent hashes at the same time, filling otherwise wasted CPU cycles. There is no security bug being fixed and no new attack surface introduced; it is purely a speed improvement.