RB
← All projectsRust Bitcoin

rust-bitcoin

Rust library for Bitcoin data structures, serialization, consensus encoding, and scripts.

BitcoinCryptographic librariesNormal
Repository coverage

2313 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

532security candidates511second-pass queue2206AI analyses
133commits · 30 days
262commits · 60 days
1102commits · 180 days
2018commits · 365 days
Backfill bands
Aug 5 → Feb 6787 seen32 candidatesComplete
Feb 6 → Jun 6878 seen53 candidatesComplete
Jun 6 → Jul 6211 seen15 candidatesComplete
Jul 6 → Aug 5184 seen2 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

66/100 average clarity
510Strong · 80–100
1085Adequate · 60–79
567Thin · 40–59
151Opaque · 0–39
20security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Andrew Poelstra23179157290
Mitchell Bagot649193645068
Tobin C. Harding41566410063
jrakibi944994068
Nick Johnson19121190060
Jamil Lambert, PhD11919116061
satsfy (Renato Britto)381527066
Fmt Bot331431045
Trevor Arjeski111111069
Shing Him Ng31731056
Martin Habovstiak30628068
Ismail Daif22622050
Analysis record

Published AI watches

Last scanned 25 minutes ago

Moderate 62 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6954: units: serialize unsigned amounts as u64

This commit fixes a mismatch in how unsigned Bitcoin amounts were serialized versus deserialized when using certain compact binary formats. Previously, an unsigned amount (like 100 satoshis) was written as a signed number, which caused for…

Data integrity bug: serialized values decode to different numeric values in varint binary formatsRange-check failure: Amount::MAX and large values near the cap fail deserialization after round-tripSerde serialize/deserialize hint mismatch for unsigned amount types
295c9d8aby Andrew Poelstra+66−112 files
No security note in commit
Low 25 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6955: key_expression: preserve master-key invariants in Xpub Arbitrary

This change fixes a bug in test-only code that generates random fake Bitcoin extended public keys (xpubs). Previously, when generating a master xpub (depth 0), the code could pick random values for the parent fingerprint and child number, …

BIP32 master-key invariant violation in generated test dataEncode/decode round-trip failure for generated master xpubsFix aligns Xpub::arbitrary with existing Xpriv::arbitrary behavior
4116ecc6by Andrew Poelstra+35−31 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6947: build(deps): bump cargo-bins/cargo-binstall from 1.21.0 to 1.21.1

This commit updates the version of a helper tool (cargo-binstall) used only inside GitHub Actions automation. It is a routine dependency bump by Dependabot and does not change any code that ships to users. There is no indication of a secur…

c1be49cbby Andrew Poelstra+2−22 files
No security note in commit
High 70 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6919: Sanitize serde size hints before allocating

This commit fixes a denial-of-service weakness in how the library deserializes lists of Bitcoin data (witnesses, amounts, fee rates) from untrusted input. Before the fix, a few bytes of attacker-controlled data could claim a list would con…

Untrusted serde size hint fed directly into Vec::with_capacityPotential memory exhaustion / OOM kill from small malicious inputDenial-of-service vector in deserialization paths
55ddbc0cby Andrew Poelstra+88−105 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

This commit fixes how the Rust Bitcoin library calculates old-style (legacy) transaction signatures when the spending script contains a special opcode called OP_CODESEPARATOR. Previously the library did not handle this opcode at all, which…

Protocol correctness fix for legacy sighash serializationOP_CODESEPARATOR handling added to match Bitcoin Core consensus behaviorPreviously omitted test vectors restored, indicating prior non-compliance
5b815281by Andrew Poelstra+600−3093 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6948: build(deps): bump taiki-e/install-action from 2.83.2 to 2.85.4

This is a routine update by Dependabot to the version of a third-party GitHub Action used in the project's automated testing workflows. The change only affects internal continuous integration (CI) scripts, not the actual Bitcoin library co…

d1431904by Andrew Poelstra+2−22 files
No security note in commit
Low 33 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

This commit fixes a small but real bug in a Rust helper that reads fixed-size chunks from a data slice. The helper was supposed to safely return 'nothing' when asked to read past the end of the data, but it accidentally added two numbers t…

Integer overflow in bounds-checking helperContract violation: method documented to return None on out-of-bounds access could panic insteadDebug-build panic (denial of service) possible
c6e80843by Andrew Poelstra+2−11 file
Vendor flagged security relevance
Moderate 62 AI analysisMessage 73 · Adequate
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Fix integer overflow in `get_array`

This commit fixes a bug in a Rust helper method called `get_array`, which is meant to safely read a fixed-size chunk from a slice and return nothing if the requested range is out of bounds. The bug was that the code added the caller's offs…

Integer overflow in bounds calculationPotential panic due to violated internal length expectationCaller-controlled arithmetic used for memory access bounds
56fb1287by Martin Habovstiak+2−11 file
Vendor flagged security relevance
High 71 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6915: primitives: Fix `Witness` handling of oversized items

This commit fixes a bug in how the Rust Bitcoin library counts and compares transaction witness data when a witness contains an oversized item. Previously, several functions relied on an iterator that silently skips oversized items, causin…

Inconsistent serialization/iterator behavior for oversized witness itemswtxid collision risk between transactions differing only in oversized witness bytesIncorrect witness equality for oversized single-item stacks
e1ed5884by Andrew Poelstra+106−273 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6922: Use `try_fold` instead of `fold` in `Sum` impl

This is a code-quality and performance improvement, not a security fix. It changes how the library adds up lists of Bitcoin amounts so that it stops early once an overflow is detected, rather than continuing to process the rest of the list…

No security-relevant signal in commit message or diffRefactor preserves overflow-checking behavior (short-circuits instead of continuing)New API method `NumOpResult::from_result` is a pure inverse of existing `into_result`
86e4d5daby Andrew Poelstra+60−562 files
No security note in commit
Moderate 52 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6893: units: Reject malformed amount strings

This update fixes a bug in how the library reads Bitcoin amount strings like '1.5 BTC'. Previously, certain malformed inputs such as '.', '._', '1_', '1_.0', and '1._0' were incorrectly accepted and treated as valid amounts (often zero), i…

Input validation bypass in amount parserMalformed strings silently parsed as zero or ordinary amountsUnderscore separator placement not enforced
fcb14622by Andrew Poelstra+88−343 files
Vendor flagged security relevance
Low 48 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6921: units: fix div_by_fee_rate_ceil precision

This commit fixes a rounding bug in how the rust-bitcoin library calculates the minimum transaction weight needed to pay a given fee at a given fee rate. The old code rounded the fee rate up too early, which could produce a weight slightly…

Incorrect fee-weight calculation due to premature integer roundingPotential transaction fee shortfall when using div_by_fee_rate_ceilOverflow protection added for Amount::MAX * 4_000_000 intermediate value
b31212e0by Andrew Poelstra+38−82 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6898: Release tracking PR: `consensus-encoding 1.3.0`

This is a routine release-management commit that bumps the version number of the `bitcoin-consensus-encoding` crate from 1.2.0 to 1.3.0 and updates lock files accordingly. It contains no code changes that fix or introduce a security issue.…

0cfc7908by Andrew Poelstra+37−349 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6909: build(deps): bump actions/labeler from 6.2.0 to 7.0.0

This commit updates a GitHub Actions automation tool (actions/labeler) used to automatically tag pull requests with labels. It is a routine dependency version bump from 6.2.0 to 7.0.0, with no indication of a security fix or vulnerability.…

4ed7c068by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6910: build(deps): bump actions/checkout from 7.0.0 to 7.0.1

This commit is a routine update to the GitHub Actions checkout tool used by the project's automated workflows. It only changes version numbers in configuration files and does not alter the actual Bitcoin library code that users run. There …

328c4ae9by Andrew Poelstra+37−3717 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6911: build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0

This commit updates a GitHub Actions helper used to install a Python tool called uv, which runs the zizmor security scanner. The change only bumps the pinned version of the helper from 8.3.2 to 9.0.0. The new version's release notes mentio…

No security-relevant signals in commit or upstream release notesDependency bump in CI only, not in library codeNo CVE or advisory referenced
67600795by Andrew Poelstra+2−22 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6912: build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3

This is a routine Dependabot update that changes the pinned version of GitHub's official CodeQL upload-sarif action from 4.37.0 to 4.37.3 in a single CI workflow. The action only uploads static analysis results to GitHub; it does not touch…

b51cec63by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6913: build(deps): bump dtolnay/rust-toolchain from 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de

This is a routine update to a GitHub Actions helper used to install Rust during automated testing. It only changes the pinned version of the dtolnay/rust-toolchain action in workflow files. There is no change to the actual rust-bitcoin lib…

90330d15by Andrew Poelstra+8−84 files
No security note in commit
Informational 20 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6906: consensus_encoding, primitives: expose exact encoding size for block and transaction

This commit adds a way to ask, in advance, exactly how many bytes a Bitcoin block or transaction will take when serialized. It is a feature addition for the library's encoding system, not a fix for a vulnerability. There is no indication i…

No security-relevant signals in commit message or diffFeature addition: expose exact encoded sizeNo mention of vulnerability, CVE, bug bounty, or security report
1a365d53by Andrew Poelstra+129−1068 files
No security note in commit
Informational 15 AI analysisMessage 88 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump dtolnay/rust-toolchain

This is a routine update by Dependabot that changes which version of a popular GitHub Action (dtolnay/rust-toolchain) is used to install Rust in automated CI workflows. The commit only updates pinned commit hashes in workflow files; it doe…

a31e0b0eby dependabot[bot]+8−84 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityUpdate nightly toolchain to nightly-2026-02-21by Tobin C. Harding · f143ffe0 · Feb 26, 2026 · 16 filesMessage 88 · StrongInformational 15Details
Commit message · Tobin C. Harding

Update nightly toolchain to nightly-2026-02-21

Same as done by bot in #5717 but with a manual update to the API text
files because `UnsafeUnpin` impls now show up.

ref: https://doc.rust-lang.org/nightly/core/marker/trait.UnsafeUnpin.html

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100

This commit only updates the pinned Rust nightly compiler version and refreshes the project's automatically-generated public API snapshot files. The new compiler version reports an additional standard Rust trait (`UnsafeUnpin`) in the snapshots, so the snapshots are updated to match. No source code behavior was changed, and there is no security fix or vulnerability introduced.

Lower-priorityconsensus_encoding, primitives, units: follow rust doc title conventionby Nick Johnson · 3fd32e95 · Feb 24, 2026 · 3 filesMessage 65 · AdequateInformational 15Details
Commit message · Nick Johnson

consensus_encoding, primitives, units: follow rust doc title convention

Follow the standard H1 title convention from the rust standard library.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit only rewrites the top-of-file documentation headings in three Rust library crates to follow the Rust standard library's H1 title convention. It changes comments, not executable code, so it cannot affect program behavior or security.

AI review queuedconsensus_encoding: beef up module docsby Nick Johnson · 3e765dba · Feb 24, 2026 · 3 filesMessage 68 · AdequateInformational 15Details
Commit message · Nick Johnson

consensus_encoding: beef up module docs

More conventional C-CRATE-DOC and C-EXAMPLE. The crate doc is essentially
a stripped down version of the original ADR doc. C-EXAMPLE calls for an
example on every public item within reason. It would be very repetative
to apply examples on every item in this crate, a single encoder and
decoder example can probably be used by all items.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds documentation and code examples to a Rust Bitcoin encoding/decoding library. It does not change any actual program logic, fix bugs, or alter behavior. There is no security issue here.

Lower-priorityunits: Introduce coverage for Display on error typesby Mitchell Bagot · 1af0abd1 · Feb 24, 2026 · 8 filesMessage 95 · StrongInformational 15Details
Commit message · Mitchell Bagot

units: Introduce coverage for Display on error types

The error types in units are largely untested by existing tests.
Since it's important to ensure that error display some content, we
should include assertions that error display messages are non-empty.

Introduce tests to cover Display impls for all error types in units

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit only adds new tests that check error messages are non-empty. It does not change any production code, so it cannot introduce a security vulnerability or fix one. It is a routine improvement to test coverage.

Lower-priorityFix Error source for ParseDenominationErrorby Mitchell Bagot · 676907c6 · Feb 24, 2026 · 1 fileMessage 68 · AdequateInformational 17Details
Commit message · Mitchell Bagot

Fix Error source for ParseDenominationError

The ParseDenominationError return None for the error source in the
std::error::Error trait implementation. Since the type is a wrapper
enum for other errors, it should return the inner error in source().

Return the inner error types for ParseDenominationError in source().

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 17/100

This is a tiny Rust bug fix in how one error type reports its underlying cause. It does not create a security vulnerability and cannot be exploited; it only affects how detailed error messages are produced when parsing Bitcoin amount denominations fails.

Lower-priorityRearrange types in hex_codecby Mitchell Bagot · 7aba40d7 · Feb 24, 2026 · 1 fileMessage 58 · ThinInformational 15Details
Commit message · Mitchell Bagot

Rearrange types in hex_codec

The hex_codec module was created over various patches and thus doesn't
follow best practice for ordering. Errors should be near the bottom,
with important types near the top.

Rearrange hex_codec to put HexPrimitive at the top, and
ParsePrimitiveError at the bottom.

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit simply moves two code blocks around within a single file. It is a cosmetic reorganization with no functional changes, no bug fixes, and no security implications.

Lower-priorityprimitives: Move hex_codec to independent moduleby Mitchell Bagot · 58cf5011 · Feb 24, 2026 · 2 filesMessage 68 · AdequateInformational 15Details
Commit message · Mitchell Bagot

primitives: Move hex_codec to independent module

The hex_codec module in lib.rs of primitives now makes up 2/3rds of
the file. At this scale, it is better suited to be moved into its
own file.

Move the hex_codec module in lib.rs to a new module file, and import
it as a pub(crate) mod.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit simply moves an existing block of hex-encoding code from one file to another within the project. It does not change what the code does, fix a bug, or alter any public behavior. There is no security relevance.

Lower-priorityClean up function comments and visibility in hex_codecby Mitchell Bagot · 118791e4 · Feb 24, 2026 · 1 fileMessage 73 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Clean up function comments and visibility in hex_codec

The hex_codec module should be entirely hidden to outside the crate.
While all types are pub(crate), the inner field of HexPrimitive was
pub.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This is a minor code cleanup change in a Rust Bitcoin library. It changes one internal field from being publicly visible to being visible only within the crate, and updates some documentation comments. There is no security issue here.

AI review queuedRemove alloc requirement for HexPrimitiveby Mitchell Bagot · 032c5db4 · Feb 24, 2026 · 3 filesMessage 80 · StrongInformational 18Details
Commit message · Mitchell Bagot

Remove alloc requirement for HexPrimitive

The Display/Debug/UpperHex/LowerHex implementations on HexPrimitive
all relied on alloc due to the implementation of hex_write_with_case.
This locks LowerHex and UpperHex on Header behind alloc, and led to
an unnecessary custom implementation of Display.

Change hex_write_with_case to remove alloc requirement, and remove
corresponding feature gates. Move hex_write_with_case to inherent
function on HexPrimitive, and rename to fmt_hex. Replace Display impl
on Header with call through to HexPrimitive. Remove feature gates on
Header Upper/LowerHex.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This is a routine code cleanup in the rust-bitcoin library. It removes the need for the 'alloc' feature when formatting certain Bitcoin data types as hex, making the hex formatting work in more constrained environments. There is no indication this fixes a security vulnerability.

AI review queuedAdjust from_str in HexPrimitive to be no-allocby Mitchell Bagot · 8b4b80b3 · Feb 24, 2026 · 4 filesMessage 80 · StrongInformational 17Details
Commit message · Mitchell Bagot

Adjust from_str in HexPrimitive to be no-alloc

The from_str implementation for parsing types from hex strings currently
relies on alloc due to the use of hex::decode_to_vec. This locks Header
FromStr decoding behind alloc.

Implement from_str without alloc, and adjust feature gates on
HeaderDecoder to match new relaxed requirements.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit is a routine refactoring of how hex strings are parsed into Bitcoin data structures in the rust-bitcoin library. It replaces an allocation-based hex decoder with a streaming, no-allocation decoder so the code can run in environments without a heap allocator. There is no direct security bug being fixed; it is a feature-gate and performance/capability cleanup.

Security candidateFix to_secret_key docs on Keypairby Mitchell Bagot · 1e84a774 · Feb 24, 2026 · 1 fileMessage 68 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Fix to_secret_key docs on Keypair

The to_secret_key function docs state that it returns a PrivateKey
type, but the function actually returns a secp256k1::SecretKey.

Fix to_secret_key docs on Keypair to correctly reference
secp256k1::SecretKey return type.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit fixes a documentation comment for a Rust function. The comment previously said the function returned one type of private key object, but it actually returns a different, lower-level secret key type. There is no code behavior change and no security risk.

Security candidateReplace old encoding logic with new encoders in sighashby Mitchell Bagot · 9aceea29 · Feb 24, 2026 · 1 fileMessage 73 · AdequateInformational 16Details
Commit message · Mitchell Bagot

Replace old encoding logic with new encoders in sighash

The sighash module contains a lot of encoding logic for types that make
use of the old consensus::Encodable trait's consensus_encode function.
With the introduction of the new consensus_encoding crate and
associated encoders, this logic can all be replaced with call-throughs
to the new encoders.

Replace all uses of consensus::Encodable logic with equivalent encoding
logic from consensus_encoding::Encodable/Encoder impls.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 16/100

This is a code cleanup commit in the rust-bitcoin library. It replaces old transaction-encoding helper functions with newer equivalent ones inside the signature-hash (sighash) code. There is no direct evidence in the commit message or diff that this fixes a security vulnerability; it reads as a refactoring to use a newer internal API. However, because the change touches the exact code that computes Bitcoin transaction signatures, any accidental change to the bytes produced could break compatibility with the Bitcoin protocol or wallets, so it is in a security-sensitive area.

Lower-priorityconsensus_encoding: expose vis fragment on exposed macrosby Nick Johnson · f0180702 · Feb 24, 2026 · 1 fileMessage 73 · AdequateInformational 15Details
Commit message · Nick Johnson

consensus_encoding: expose vis fragment on exposed macros

Following the C-MACRO-VIS API convention, expose a vis fragment to allow
the caller to choose the output's visibility. This change is backwards
compatible.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit is a routine API ergonomics improvement. It changes two Rust macros so that the caller can specify the visibility of the generated struct and its constructor (e.g., public, private, or crate-visible), instead of always forcing public visibility. The change is explicitly described as backwards compatible and follows a documented Rust API convention.

Lower-priorityio: Add flush_to_writer functionby Mitchell Bagot · e44744ce · Feb 24, 2026 · 1 fileMessage 70 · AdequateInformational 15Details
Commit message · Mitchell Bagot

io: Add flush_to_writer function

In some cases, we may have an Encoder instance, without a corresponding
Encodable. In these cases, having a way to flush the encoder to an io
writer is extremely useful to avoid having to replicate the logic of
encode_to_writer inline.

Add flush_to_writer function to match flush_to_writer from
consensus_encoding.

70/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This commit adds a new helper function that lets developers flush an existing data encoder directly to an output writer. It is a straightforward code refactor that splits an existing function into two pieces; there is no indication of a security bug or fix.

Security candidatebitcoin: reject 65 bytes signature with sighash 0x00by jrakibi · 371b17e3 · Feb 24, 2026 · 1 fileMessage 98 · StrongModerate 60Details
Commit message · jrakibi

bitcoin: reject 65 bytes signature with sighash 0x00

According to BIP341, if taproot signature is 65 bytes long, the last byte (sighash)
must be different from 0x00, otherwise, it is invalid.
currently, we are accepting it as a valid signature.
this might also break the roundtrip of from_slice -> serialize

ref: https://github.com/bitcoin/bips/blob/master/bip-0341.mediawiki#taproot-key-path-spending-signature-validation

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
signing boundarycryptography-sensitive path
AI analysis · Moderate 60/100

This commit fixes a bug where the Rust Bitcoin library incorrectly accepted 65-byte Taproot signatures whose final byte was 0x00. Under Bitcoin's BIP-341 rules, such signatures are invalid. Accepting them could let invalid transactions or signatures slip through, and it could break the library's own round-trip serialization (reading a signature in and writing it back out).

AI review queuedconsensus_encoding: add track_caller to panic-able sitesby Nick Johnson · 0276325e · Feb 23, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · Nick Johnson

consensus_encoding: add track_caller to panic-able sites

Defensively added to the Decoder trait itself since the performance
impact is negligible.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
parser or protocol pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds Rust's #[track_caller] attribute to two methods in a decoding trait. This is a diagnostic improvement: if the code ever panics, the error message will point to the caller's location instead of deep inside the library. It does not change what the code does, what data it accepts, or whether it panics. There is no security fix here.

AI review queuedRe-release without rc suffixby Tobin C. Harding · 418685a9 · Feb 23, 2026 · 20 filesMessage 90 · StrongInformational 20Details
Commit message · Tobin C. Harding

Re-release without rc suffix

Turns out that the `-rc.0` suffix causes way more problems than it
solves because of how `cargo` resolves the version numbers and what we
intended on using the RC releases for.

In brief

- We wanted to be able to do breaking changes if required
- We wanted to signal that these releases were almost there (TM)
- We wanted to be able to do downstream testing including releasing
downstream crates with the RC releases as part of their public API.

In hindsite we messed up and should have just kept iterating as normal
until we were ready.

Re-release the whole stack without any rc suffix's. However keep
`bitcoin 0.33.0-beta` because we want 0.32.0 to be the latest stable
release and its important that it shows as such on docs.rs

Also, for pre-1.0 crates that had an rc release just jump to the next
version i.e., `io 0.4.0-rc.0` goes to `io 0.5.0`. Just for good
measure.


crate | latest stable | latest RC | with this applied
-----------------------------------------------------------
consensus_encoding 0.0.0 1.0.0-rc.3 0.1.0
units 0.2.0 1.0.0-rc.4 0.3.0
primitives 0.101.0 1.0.0-rc.2 0.102.0
hashes 0.19.0 - 0.20.0
io 0.3.0 0.4.0-rc.0 0.5.0
base58ck 0.3.0 - 0.4.0


bitcoin - 0.33.0-beta.0 to be yanked. Release as 0.33.0-beta

p2p - updated deps, unrelased so no other changes.
internals - not touched (currently 0.5.0)
chacha20_poly1305 - not touched

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 20/100

This commit is a routine release-management change for the rust-bitcoin project. It re-releases several crates without the '-rc' (release candidate) suffix in their version numbers and updates internal dependency version requirements accordingly. There are no code logic changes, bug fixes, or security patches in the diff—only version numbers, lock files, changelogs, and README text.

Security candidatebitcoin: preserve parity for XOnlyPublicKeyby jrakibi · f4e9fcae · Feb 22, 2026 · 1 fileMessage 80 · StrongLow 49Details
Commit message · jrakibi

bitcoin: preserve parity for XOnlyPublicKey

both From impls for XOnlyPublicKey lose parity because they call `from_secp(`,
which defaults to Parity::Even. we now preserve parity by extracting it from
x_only_public_key() instead

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
cryptography-sensitive path
AI analysis · Low 49/100

This commit fixes a bug in how X-only public keys were created from full public keys. An X-only key is just the X coordinate of a point, but a point can have an even or odd Y coordinate (parity). The old code always assumed even parity, which could silently produce the wrong key for odd-parity inputs. The fix preserves the actual parity from the source key.

Lower-priorityconsensus_encoding: add conventinal manifest metadataby Nick Johnson · e001c89d · Feb 21, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · Nick Johnson

consensus_encoding: add conventinal manifest metadata

Follows C-METADATA from the API guidelines.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit only adds two standard metadata fields (homepage and documentation URLs) to a Rust package manifest file. It does not change any executable code, cryptographic logic, or network behavior. There is no security relevance.

Lower-priorityconsensus_encoding: fix up doc linkby Nick Johnson · 2098b582 · Feb 21, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Nick Johnson

consensus_encoding: fix up doc link

Confrom to C-LINK API conventions.

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This is a one-word documentation fix. A comment that referenced another type was changed from plain text to a proper Rust doc link so that documentation tools can create a clickable link. There is no code behavior change and no security relevance.

AI review queuedUpdate apiby Nick Johnson · c9cdde0b · Feb 21, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Nick Johnson

Update api

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit updates a generated API snapshot file to reflect a minor relaxation of trait bounds on an error type. It is a documentation/tracking file change, not a code change, and has no security relevance.

AI review queuedconsensus_encoding: remove redundant trait boundsby Nick Johnson · 3ea57579 · Feb 20, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Nick Johnson

consensus_encoding: remove redundant trait bounds

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a minor code cleanup in a Rust Bitcoin library. It removes unnecessary requirements (trait bounds) from an error-handling implementation. The change does not affect security, runtime behavior, or how the library processes Bitcoin data.

Lower-priorityFix Unknown NetworkMessage encodingby Mitchell Bagot · cf1a9fee · Feb 20, 2026 · 1 fileMessage 58 · ThinLow 37Details
Commit message · Mitchell Bagot

Fix Unknown NetworkMessage encoding

The NetworkMessageEncoder and old Encodable implementation for
NetworkMessage make use of the Vec<u8> encoding for the raw payload
data. This introduces a vector length prefix to the start of the
encoding which causes the roundtrip for Unknown NetworkMessage types to
fail. In practice, NetworkMessage will only ever be decoded through the
RawNetworkMessage, where a payload length will be known. As such, this
length prefix is not necessary in the encoding and can be trivially
removed.

Change Unknown NetworkMessage encoding to directly write the vector of
bytes instead of using Vec<u8> encoding logic.

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
AI analysis · Low 37/100

This commit fixes a bug in how custom or unknown Bitcoin peer-to-peer messages were being serialized. Previously, the code accidentally added an extra length number to the front of the raw payload bytes, so if you decoded an unknown message and re-encoded it, the bytes would not match. The fix writes the raw payload bytes directly without the extra length prefix, and adds a test to confirm round-trip encoding works.

Security candidateEncapsulate PublicKey and PrivateKeyby Mitchell Bagot · 118b8987 · Feb 20, 2026 · 1 fileMessage 58 · ThinInformational 17Details
Commit message · Mitchell Bagot

Encapsulate PublicKey and PrivateKey

With the previous changes to the PublicKey and PrivateKey types, both
can now be encapsulated to control the scope of access to the inner
fields.

Move PublicKey and PrivateKey to encapsulated module and add them to
the pub use.

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive path
AI analysis · Informational 17/100

This commit is a routine internal code reorganization. It moves the PublicKey and PrivateKey type definitions into a private 'encapsulate' module and re-exports them publicly. The fields were already private before this change, so no new access restrictions are introduced. There is no indication this fixes a security bug or changes behavior visible to users of the library.

Security candidateRemove public access to all fields of PublicKey and PrivateKeyby Mitchell Bagot · 41d946ff · Feb 20, 2026 · 3 filesMessage 73 · AdequateInformational 18Details
Commit message · Mitchell Bagot

Remove public access to all fields of PublicKey and PrivateKey

As with the inner fields, the compressed and network fields of PublicKey
and PrivateKey allows public access for read/write. To allow for
encapsulation, read access should be limited to an accessor function.

Introduce compressed() accessor function for PublicKey and compressed()
and network() accessor functions for PrivateKey. Replace all direct
access to inner fields with use of the accessor functions.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 18/100

This commit hides the internal fields of two key types (PublicKey and PrivateKey) so outside code can no longer read or change them directly. Instead, it provides read-only accessor methods. This is a normal defensive-coding change that improves encapsulation and makes future misuse less likely, but the commit itself does not fix a known active bug or vulnerability.