RB
← All projectsRust Bitcoin

rust-bitcoin

Rust library for Bitcoin data structures, serialization, consensus encoding, and scripts.

BitcoinCryptographic librariesNormal
Repository coverage

2313 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

532security candidates511second-pass queue2206AI analyses
130commits · 30 days
248commits · 60 days
1102commits · 180 days
2008commits · 365 days
Backfill bands
Aug 5 → Feb 6787 seen32 candidatesComplete
Feb 6 → Jun 6878 seen53 candidatesComplete
Jun 6 → Jul 6211 seen15 candidatesComplete
Jul 6 → Aug 5184 seen2 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

66/100 average clarity
510Strong · 80–100
1085Adequate · 60–79
567Thin · 40–59
151Opaque · 0–39
20security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Andrew Poelstra23179157290
Mitchell Bagot649193645068
Tobin C. Harding41566410063
jrakibi944994068
Nick Johnson19121190060
Jamil Lambert, PhD11919116061
satsfy (Renato Britto)381527066
Fmt Bot331431045
Trevor Arjeski111111069
Shing Him Ng31731056
Martin Habovstiak30628068
Ismail Daif22622050
Analysis record

Published AI watches

Last scanned 21 minutes ago

Moderate 62 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6954: units: serialize unsigned amounts as u64

This commit fixes a mismatch in how unsigned Bitcoin amounts were serialized versus deserialized when using certain compact binary formats. Previously, an unsigned amount (like 100 satoshis) was written as a signed number, which caused for…

Data integrity bug: serialized values decode to different numeric values in varint binary formatsRange-check failure: Amount::MAX and large values near the cap fail deserialization after round-tripSerde serialize/deserialize hint mismatch for unsigned amount types
295c9d8aby Andrew Poelstra+66−112 files
No security note in commit
Low 25 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6955: key_expression: preserve master-key invariants in Xpub Arbitrary

This change fixes a bug in test-only code that generates random fake Bitcoin extended public keys (xpubs). Previously, when generating a master xpub (depth 0), the code could pick random values for the parent fingerprint and child number, …

BIP32 master-key invariant violation in generated test dataEncode/decode round-trip failure for generated master xpubsFix aligns Xpub::arbitrary with existing Xpriv::arbitrary behavior
4116ecc6by Andrew Poelstra+35−31 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6947: build(deps): bump cargo-bins/cargo-binstall from 1.21.0 to 1.21.1

This commit updates the version of a helper tool (cargo-binstall) used only inside GitHub Actions automation. It is a routine dependency bump by Dependabot and does not change any code that ships to users. There is no indication of a secur…

c1be49cbby Andrew Poelstra+2−22 files
No security note in commit
High 70 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6919: Sanitize serde size hints before allocating

This commit fixes a denial-of-service weakness in how the library deserializes lists of Bitcoin data (witnesses, amounts, fee rates) from untrusted input. Before the fix, a few bytes of attacker-controlled data could claim a list would con…

Untrusted serde size hint fed directly into Vec::with_capacityPotential memory exhaustion / OOM kill from small malicious inputDenial-of-service vector in deserialization paths
55ddbc0cby Andrew Poelstra+88−105 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

This commit fixes how the Rust Bitcoin library calculates old-style (legacy) transaction signatures when the spending script contains a special opcode called OP_CODESEPARATOR. Previously the library did not handle this opcode at all, which…

Protocol correctness fix for legacy sighash serializationOP_CODESEPARATOR handling added to match Bitcoin Core consensus behaviorPreviously omitted test vectors restored, indicating prior non-compliance
5b815281by Andrew Poelstra+600−3093 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6948: build(deps): bump taiki-e/install-action from 2.83.2 to 2.85.4

This is a routine update by Dependabot to the version of a third-party GitHub Action used in the project's automated testing workflows. The change only affects internal continuous integration (CI) scripts, not the actual Bitcoin library co…

d1431904by Andrew Poelstra+2−22 files
No security note in commit
Low 33 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

This commit fixes a small but real bug in a Rust helper that reads fixed-size chunks from a data slice. The helper was supposed to safely return 'nothing' when asked to read past the end of the data, but it accidentally added two numbers t…

Integer overflow in bounds-checking helperContract violation: method documented to return None on out-of-bounds access could panic insteadDebug-build panic (denial of service) possible
c6e80843by Andrew Poelstra+2−11 file
Vendor flagged security relevance
Moderate 62 AI analysisMessage 73 · Adequate
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Fix integer overflow in `get_array`

This commit fixes a bug in a Rust helper method called `get_array`, which is meant to safely read a fixed-size chunk from a slice and return nothing if the requested range is out of bounds. The bug was that the code added the caller's offs…

Integer overflow in bounds calculationPotential panic due to violated internal length expectationCaller-controlled arithmetic used for memory access bounds
56fb1287by Martin Habovstiak+2−11 file
Vendor flagged security relevance
High 71 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6915: primitives: Fix `Witness` handling of oversized items

This commit fixes a bug in how the Rust Bitcoin library counts and compares transaction witness data when a witness contains an oversized item. Previously, several functions relied on an iterator that silently skips oversized items, causin…

Inconsistent serialization/iterator behavior for oversized witness itemswtxid collision risk between transactions differing only in oversized witness bytesIncorrect witness equality for oversized single-item stacks
e1ed5884by Andrew Poelstra+106−273 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6922: Use `try_fold` instead of `fold` in `Sum` impl

This is a code-quality and performance improvement, not a security fix. It changes how the library adds up lists of Bitcoin amounts so that it stops early once an overflow is detected, rather than continuing to process the rest of the list…

No security-relevant signal in commit message or diffRefactor preserves overflow-checking behavior (short-circuits instead of continuing)New API method `NumOpResult::from_result` is a pure inverse of existing `into_result`
86e4d5daby Andrew Poelstra+60−562 files
No security note in commit
Moderate 52 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6893: units: Reject malformed amount strings

This update fixes a bug in how the library reads Bitcoin amount strings like '1.5 BTC'. Previously, certain malformed inputs such as '.', '._', '1_', '1_.0', and '1._0' were incorrectly accepted and treated as valid amounts (often zero), i…

Input validation bypass in amount parserMalformed strings silently parsed as zero or ordinary amountsUnderscore separator placement not enforced
fcb14622by Andrew Poelstra+88−343 files
Vendor flagged security relevance
Low 48 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6921: units: fix div_by_fee_rate_ceil precision

This commit fixes a rounding bug in how the rust-bitcoin library calculates the minimum transaction weight needed to pay a given fee at a given fee rate. The old code rounded the fee rate up too early, which could produce a weight slightly…

Incorrect fee-weight calculation due to premature integer roundingPotential transaction fee shortfall when using div_by_fee_rate_ceilOverflow protection added for Amount::MAX * 4_000_000 intermediate value
b31212e0by Andrew Poelstra+38−82 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6898: Release tracking PR: `consensus-encoding 1.3.0`

This is a routine release-management commit that bumps the version number of the `bitcoin-consensus-encoding` crate from 1.2.0 to 1.3.0 and updates lock files accordingly. It contains no code changes that fix or introduce a security issue.…

0cfc7908by Andrew Poelstra+37−349 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6909: build(deps): bump actions/labeler from 6.2.0 to 7.0.0

This commit updates a GitHub Actions automation tool (actions/labeler) used to automatically tag pull requests with labels. It is a routine dependency version bump from 6.2.0 to 7.0.0, with no indication of a security fix or vulnerability.…

4ed7c068by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6910: build(deps): bump actions/checkout from 7.0.0 to 7.0.1

This commit is a routine update to the GitHub Actions checkout tool used by the project's automated workflows. It only changes version numbers in configuration files and does not alter the actual Bitcoin library code that users run. There …

328c4ae9by Andrew Poelstra+37−3717 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6911: build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0

This commit updates a GitHub Actions helper used to install a Python tool called uv, which runs the zizmor security scanner. The change only bumps the pinned version of the helper from 8.3.2 to 9.0.0. The new version's release notes mentio…

No security-relevant signals in commit or upstream release notesDependency bump in CI only, not in library codeNo CVE or advisory referenced
67600795by Andrew Poelstra+2−22 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6912: build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3

This is a routine Dependabot update that changes the pinned version of GitHub's official CodeQL upload-sarif action from 4.37.0 to 4.37.3 in a single CI workflow. The action only uploads static analysis results to GitHub; it does not touch…

b51cec63by Andrew Poelstra+1−11 file
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6913: build(deps): bump dtolnay/rust-toolchain from 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de

This is a routine update to a GitHub Actions helper used to install Rust during automated testing. It only changes the pinned version of the dtolnay/rust-toolchain action in workflow files. There is no change to the actual rust-bitcoin lib…

90330d15by Andrew Poelstra+8−84 files
No security note in commit
Informational 20 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6906: consensus_encoding, primitives: expose exact encoding size for block and transaction

This commit adds a way to ask, in advance, exactly how many bytes a Bitcoin block or transaction will take when serialized. It is a feature addition for the library's encoding system, not a fix for a vulnerability. There is no indication i…

No security-relevant signals in commit message or diffFeature addition: expose exact encoded sizeNo mention of vulnerability, CVE, bug bounty, or security report
1a365d53by Andrew Poelstra+129−1068 files
No security note in commit
Informational 15 AI analysisMessage 88 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

build(deps): bump dtolnay/rust-toolchain

This is a routine update by Dependabot that changes which version of a popular GitHub Action (dtolnay/rust-toolchain) is used to install Rust in automated CI workflows. The commit only updates pinned commit hashes in workflow files; it doe…

a31e0b0eby dependabot[bot]+8−84 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedprimitives: prevent null prevout in non-coinbase transactionsby jrakibi · c71db422 · Dec 28, 2025 · 1 fileMessage 73 · AdequateModerate 60Details
Commit message · jrakibi

primitives: prevent null prevout in non-coinbase transactions

Non-coinbase transactions must not contain a null prevout (coinbase prevout)
Add this validation to the transaction decoder to reject txs
that violate this rule.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 60/100

This commit adds a safety check in the Rust Bitcoin library's transaction decoder. It ensures that any transaction with more than one input cannot contain a 'coinbase-style' empty previous transaction reference. Such a reference is only allowed in the special coinbase transaction that creates new coins. Without this check, a malformed or malicious transaction could slip through and potentially cause incorrect behavior in software using this library to parse Bitcoin transactions.

Lower-priority2025-12-28 automated rustfmt nightlyby Fmt Bot · f6f6345d · Dec 28, 2025 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · Fmt Bot

2025-12-28 automated rustfmt nightly

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This is an automated code-formatting commit. It only changes whitespace, line breaks, import order, and minor punctuation to match the latest rustfmt style. No program logic, APIs, or security behavior changed.

Lower-priorityp2p: Use `primitives` in `bip152` testsby rustaceanrob · 53586dce · Dec 26, 2025 · 1 fileMessage 78 · AdequateInformational 15Details
Commit message · rustaceanrob

p2p: Use `primitives` in `bip152` tests

Small follow up to #5342 and a step in #5411

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100

This is a minor internal code cleanup in the test suite only. It changes which internal Rust module provides certain Bitcoin data types used in tests, with no functional change to the library or any user-facing behavior.

AI review queuedFix decoder bug when ending before decoding prefixby Shing Him Ng · 5d4f9cff · Dec 26, 2025 · 1 fileMessage 73 · AdequateModerate 50Details
Commit message · Shing Him Ng

Fix decoder bug when ending before decoding prefix

Before this fix, calling `ByteVecDecoder.end()` on a decoder that hadn't
finished reading in the full prefix would result in a valid result of an
empty vec. This should instead result in an error, since the decoder
shouldn't be able to decode something with an incomplete prefix.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Moderate 50/100

This commit fixes a bug in a Bitcoin data decoder. Previously, if you stopped decoding early—before the full length prefix was read—the decoder would incorrectly report success with an empty result instead of reporting an error. The fix makes the decoder correctly return an 'unexpected end of data' error in those cases. This could matter for anyone parsing Bitcoin protocol data from partial or truncated inputs.

Lower-prioritybenches: Add benchmark to test duplicate-inputs worst case scenarioby jrakibi · 5871fcbc · Dec 26, 2025 · 2 filesMessage 83 · StrongInformational 15Details
Commit message · jrakibi

benches: Add benchmark to test duplicate-inputs worst case scenario

Compares BTreeSet, sorted list, and pairwise checks.
Results show pairwise performing significantly better, even for
larger input sizes

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit only adds a new performance benchmark. It does not change any library code, fix any bug, or alter behavior. The benchmark measures how fast different methods can detect duplicate transaction inputs in a worst-case scenario. There is no security issue in the commit itself.

Lower-priorityFix documentation typo for Address::p2tr_tweakedby Nadav Ivgi · d0706987 · Dec 22, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Nadav Ivgi

Fix documentation typo for Address::p2tr_tweaked

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit fixes a single-word typo in a documentation comment. The word 'pre-tweaked' was changed to 'tweaked' to accurately describe the function's parameter. There is no code change and no security impact.

Lower-prioritybitcoin: Bump version to 0.33.0-beta.1by Tobin C. Harding · 1e5b3fe2 · Dec 22, 2025 · 4 filesMessage 80 · StrongInformational 15Details
Commit message · Tobin C. Harding

bitcoin: Bump version to 0.33.0-beta.1

Due to re-release of the whole stack thanks to a `internals` major
release.

Bump the version and update the lock files.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This commit is a routine version bump from 0.33.0-beta.0 to 0.33.0-beta.1 for the rust-bitcoin library. It only changes version numbers in package metadata and lock files, plus reorders a changelog list. There is no code change and no security relevance.

Lower-prioritybase58ck: Bump version to 0.3.0by Tobin C. Harding · a86943ea · Dec 22, 2025 · 5 filesMessage 68 · AdequateInformational 15Details
Commit message · Tobin C. Harding

base58ck: Bump version to 0.3.0

In preparation for release bump the version, add a changelog, and
update the lock files.

Note there have been no public changes to this crate other than
bumping the MSRV and updating dependencies.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit is a routine version bump for a small Rust library called base58ck. It updates version numbers in package files, refreshes lock files, and adds a changelog entry. There are no code changes that fix or introduce any security issue.

Lower-priorityprimitives: Bump version to 1.0.0-rc.2by Tobin C. Harding · 02f94eb6 · Dec 22, 2025 · 6 filesMessage 72 · AdequateInformational 15Details
Commit message · Tobin C. Harding

primitives: Bump version to 1.0.0-rc.2

Due to `internals` major release; bump the version and update the lock
files.

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This commit is a routine version bump for the bitcoin-primitives crate from 1.0.0-rc.1 to 1.0.0-rc.2, triggered by a new major release of an internal dependency. It updates version numbers in package manifests and lock files, and adjusts one test to import newly available type names. There is no security-relevant code change.

Lower-priorityconsensus_encoding: Bump version to 1.0.0-rc.3by Tobin C. Harding · de63f951 · Dec 22, 2025 · 9 filesMessage 68 · AdequateInformational 15Details
Commit message · Tobin C. Harding

consensus_encoding: Bump version to 1.0.0-rc.3

Bump the version and update the lock files - I did not check for
changelog, we can do this right at the end of the RC cycle.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit is a routine version bump for a Rust library package called bitcoin-consensus-encoding, moving it from release candidate 2 to release candidate 3. It only updates version numbers in package metadata and lock files. There are no code changes, bug fixes, or security-related modifications visible in the diff.

Lower-priorityunits: Bump version to 1.0.0-rc.4by Tobin C. Harding · be755715 · Dec 22, 2025 · 6 filesMessage 72 · AdequateInformational 15Details
Commit message · Tobin C. Harding

units: Bump version to 1.0.0-rc.4

Due to `internals` major release; bump the version and update the lock
files.

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This commit is a routine version bump for the bitcoin-units crate from 1.0.0-rc.3 to 1.0.0-rc.4, triggered by a major release of an internal dependency. It only changes version numbers in package manifests and lock files. There is no code change, no bug fix, and no security relevance.

Lower-priorityinternals: Bump version to 0.5.0by Tobin C. Harding · c1a2e97c · Dec 22, 2025 · 10 filesMessage 60 · AdequateInformational 15Details
Commit message · Tobin C. Harding

internals: Bump version to 0.5.0

Add changelog entry, bump the version, update the lock files.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit is a routine version bump for the internal 'bitcoin-internals' Rust package from 0.4.2 to 0.5.0. It updates version numbers in package manifests, lock files, and adds a changelog entry describing two minor internal code cleanups. There is no indication of any security fix or vulnerability being addressed.

Lower-priorityhashes: Bump version to 0.19.0by Tobin C. Harding · d88ff62f · Dec 22, 2025 · 8 filesMessage 80 · StrongInformational 15Details
Commit message · Tobin C. Harding

hashes: Bump version to 0.19.0

In preparation for release add a changelog entry, bump the version
number, and update the lock files.

This release is only needed because we just bumped the version of
`internals`.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This commit is a routine version bump for the bitcoin_hashes crate from 0.18.0 to 0.19.0. It updates version numbers in package manifests and lock files, and adds a changelog entry explaining the release was only needed because an internal dependency (bitcoin-internals) was upgraded. There are no code changes and no security relevance.

Lower-priorityinternals: Add a changelog for the 0.4.1 releaseby Tobin C. Harding · 174cf4ae · Dec 22, 2025 · 1 fileMessage 68 · AdequateInformational 15Details
Commit message · Tobin C. Harding

internals: Add a changelog for the 0.4.1 release

In Nashville, in the work to get `primitives` out we rushed an
`internals` minor release that was actually breaking and should have
been a major release. For some reason at that time I omitted a
changelog, in hindsite now I look at the diff to `macros` I am not
surprised I missed the breaking change.

git diff internals-0.4.0 bitcoin-internals-0.4.1 -- internals/src/macros.rs

Add a changelog for the `internals v0.4.1` release. Note in it that
the release violated semver rules.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only adds a changelog file documenting that a previous minor release (internals v0.4.1) accidentally included breaking changes and will be yanked. It changes no source code, build scripts, or runtime behavior. There is no security vulnerability here—just a documentation note about a semver policy mistake.

Lower-priorityMove compact_size decoding into primitives witnessby Mitchell Bagot · f4157256 · Dec 22, 2025 · 6 filesMessage 73 · AdequateInformational 18Details
Commit message · Mitchell Bagot

Move compact_size decoding into primitives witness

The compact_size module provides a single function decode_unchecked
that is only used by the witnesses in primitives. Since encoding
has already been moved to CompactSizeEncoder, we can move this
decoding function and remove internals::compact_size entirely.

Move decode_unchecked from internals::compact_size to witness.rs
in primitives and remove compact_size module from internals.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 18/100

This commit is a simple internal code reorganization: it moves a helper function that decodes Bitcoin's compact-size integers from a shared 'internals' module into the only place that actually uses it, the witness handling code. The function's behavior, including its safety checks and panic conditions, is copied unchanged. There is no indication this fixes or introduces a security bug.

AI review queuedMove internals::compact_size encoding into CompactSizeEncoderby Mitchell Bagot · 46097693 · Dec 22, 2025 · 15 filesMessage 73 · AdequateInformational 15Details
Commit message · Mitchell Bagot

Move internals::compact_size encoding into CompactSizeEncoder

Currently, the CompactSizeEncoder calls into the internals::compact_size
module to perform the actual encoding process. This creates a strange
API where there are two ways to do the same thing, one of which differs
from how other encoders work.

Move encode and encoded_size from internals::compact_size to the
CompactSizeEncoder in consensus_encoding. Replace usage of
compact_size::encode with pub(crate) function in primitives and
direct usage of CompactSizeEncoder in bitcoin.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine internal code cleanup. It moves the logic for encoding Bitcoin 'compact size' numbers from one internal helper module into a dedicated encoder type, then updates call sites to use the new location. There is no security fix or behavior change intended.

Lower-priorityprimitives: Add test to kill mutants in Witness::sizeby Mitchell Bagot · 1719fdad · Dec 22, 2025 · 1 fileMessage 95 · StrongInformational 15Details
Commit message · Mitchell Bagot

primitives: Add test to kill mutants in Witness::size

The size function in Witness has mutants due to a lack of test coverage.

Add test to cover the Witness::size function, and kill relevant mutants.

Authored by: Tobin C. Harding <me@tobin.cc>

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit only adds a new unit test for an existing function (Witness::size). It does not change any production code, fix any bug, or alter behavior. There is no security relevance.

AI review queued2025-12-21 automated rustfmt nightlyby Fmt Bot · 1da9343f · Dec 21, 2025 · 8 filesMessage 45 · ThinInformational 15Details
Commit message · Fmt Bot

2025-12-21 automated rustfmt nightly

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is an automated code-formatting run by rustfmt. It only changes whitespace, line breaks, and the order of import statements. There are no functional changes, no bug fixes, and no security-related alterations.

Lower-priorityhashes: Add api filesby Mitchell Bagot · e81934e9 · Dec 19, 2025 · 4 filesMessage 51 · ThinInformational 15Details
Commit message · Mitchell Bagot

hashes: Add api files

Currently only stable crates have API files. Since some features may
cross crate boundaries, and involve breaking changes to the API of
crates under the stable crates, it's important to track the API of
these crates also.

Add hashes to check-api just function and add initial API files.

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit only adds public API snapshot files for the `hashes` crate and updates the script that checks for API changes. It does not modify any source code, behavior, or functionality. There is no security impact.

Lower-priorityAdd missing serde tests for unitsby Jakub Gladysz · f8d623e4 · Dec 18, 2025 · 2 filesMessage 55 · ThinInformational 15Details
Commit message · Jakub Gladysz

Add missing serde tests for units

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only adds new automated tests for serializing and deserializing Bitcoin unit types (like fee rates, block heights, lock times, and sequence numbers). It does not change any production library code, so it cannot introduce a security vulnerability or fix one directly.

Lower-priorityRename serde tests in unitsby Jakub Gladysz · b7bbee89 · Dec 18, 2025 · 1 fileMessage 55 · ThinInformational 15Details
Commit message · Jakub Gladysz

Rename serde tests in units

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only renames six test functions in a Rust test file to make their names more descriptive (adding 'amount' to clarify they test amount serialization). It changes no actual code behavior, no logic, and no public API. There is no security relevance.

Lower-priorityRename struct fields in units serde testby Jakub Gladysz · 8912345f · Dec 18, 2025 · 1 fileMessage 55 · ThinInformational 15Details
Commit message · Jakub Gladysz

Rename struct fields in units serde test

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only renames three test-only struct fields from single-letter names (a, b, c) to descriptive names (block_height, block_height_interval, weight) inside a single Rust test file. It does not change any production code, logic, serialization format, or behavior. There is no security relevance.

Lower-priorityRemove redundant import from sequence.rsby Jakub Gladysz · 197968bd · Dec 18, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Jakub Gladysz

Remove redundant import from sequence.rs

Cleans up the warning

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit removes an unused import from a single Rust source file to silence a compiler warning. It does not change any behavior, logic, or security properties of the code.

Lower-priorityp2p: upgrade to workspace lint rulesby Nick Johnson · d8930384 · Dec 17, 2025 · 8 filesMessage 45 · ThinInformational 15Details
Commit message · Nick Johnson

p2p: upgrade to workspace lint rules

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a routine code-quality cleanup for the rust-bitcoin peer-to-peer (p2p) crate. It switches the crate from its own custom Clippy lint rules to the shared workspace lint rules, and makes the matching style fixes: reformatting numeric literals, adding backticks to documentation links, replacing manual loops with references, and changing a couple of function signatures to take references instead of owned values. There is no security fix here.

Lower-priorityinternals: upgrade to workspace lint rulesby Nick Johnson · d8de11d7 · Dec 17, 2025 · 10 filesMessage 45 · ThinInformational 15Details
Commit message · Nick Johnson

internals: upgrade to workspace lint rules

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a routine code-quality cleanup for the internals subcrate. It switches the crate from its own custom lint rules to the workspace-wide lint rules, then fixes the style warnings that the stricter rules produced. There are no functional changes to how the library behaves, and no security fixes or vulnerabilities are introduced.