SS
← All projectsSeedSigner

SeedSigner

Stateless, air-gapped Bitcoin signing software for Raspberry Pi hardware.

BitcoinHardware walletsNormal
Repository coverage

187 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

134security candidates25second-pass queue116AI analyses
8commits · 30 days
8commits · 60 days
37commits · 180 days
187commits · 365 days
Backfill bands
Aug 5 → Feb 6150 seen8 candidatesComplete
Feb 6 → Jun 629 seen0 candidatesComplete
Jun 6 → Jul 60 seen0 candidatesComplete
Jul 6 → Aug 57 seen1 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

44/100 average clarity
4Strong · 80–100
30Adequate · 60–79
89Thin · 40–59
64Opaque · 0–39
42security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
kdmukai1177975039
okaybro171413063
Nick Klockenga14134061
PROWLERx1510106020
alvroble1277055
FazleRabbbiferdaus172866061
biel411037
Advait111060
Kshitij111033
securesigner111050
S1DDHEY111045
newtonick100045
Analysis record

Published AI watches

Last scanned 42 minutes ago

Low 43 AI analysisMessage 77 · Adequate
SS SeedSignerSeedSigner BitcoinHardware wallets

fix: replace removed `get_seed` call in `PSBTSelectSeedView`

This commit fixes a bug where selecting an existing seed during PSBT signing would crash because the code called a method (`get_seed`) that no longer exists. The fix uses the already-loaded list of seeds directly. The crash is a reliabilit…

Fixes a runtime exception (AttributeError) in a signing workflowPrevents workflow failure when user selects an existing seed for PSBT signingAdds regression test covering the previously broken code path
442b7a1aby okaybro+13−12 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
SS SeedSignerSeedSigner BitcoinHardware wallets

refactor: use `Seed` instead of `seed_num`

This commit is a straightforward internal code cleanup: it replaces the use of numeric seed indexes (seed_num) with direct references to Seed objects throughout the user interface and tests. There is no security-relevant change; it is pure…

65e312c9by okaybro+238−2698 files
No security note in commit
Informational 23 AI analysisMessage 45 · Thin
SS SeedSignerSeedSigner BitcoinHardware wallets

Minor bugfix to correct if/else path

This commit fixes a small logic bug in SeedSigner, a hardware-wallet-like signing device. The code was checking whether a seed's fingerprint string was empty, but it should have been checking whether the seed has a passphrase. The bug coul…

Logic bug in seed finalization flowIncorrect fingerprint display conditionPotential user confusion during seed setup
c52577a9by kdmukai+3−21 file
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
SS SeedSignerSeedSigner BitcoinHardware wallets

fix comment

This commit only fixes the indentation of a comment line so it is properly formatted as a code comment. No executable code, logic, or behavior was changed.

cf37ac2aby PROWLERx15+2−21 file
No security note in commit
Informational 15 AI analysisMessage 33 · Opaque
SS SeedSignerSeedSigner BitcoinHardware wallets

update comment

This commit only rewrites an inline code comment to describe the same back-button behavior more clearly. No actual code logic, function calls, or data handling changed.

94485e52by Kshitij+4−41 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
SS SeedSignerSeedSigner BitcoinHardware wallets

added comment explaining changes

This commit only adds a clarifying comment to existing code. It does not change any program behavior, fix a bug, or alter security logic. The comment explains that pressing the back button during seed phrase entry can mean either aborting …

d0b729a5by PROWLERx15+4−11 file
No security note in commit
Low 34 AI analysisMessage 35 · Opaque
SS SeedSignerSeedSigner BitcoinHardware wallets

update conditional branch

This commit changes how the back button behaves during two seed-related screens. In the first screen, it simplifies the logic so that the pending mnemonic is only discarded when leaving from the first word. In the second screen, it removes…

Back-button control flow altered in seed creation UIPending mnemonic discard logic narrowed to first-word exit onlyRemoval of back-button guard before button_data indexing in finalize view
ef7d3716by PROWLERx15+3−71 file
No security note in commit
Informational 19 AI analysisMessage 28 · Opaque
SS SeedSignerSeedSigner BitcoinHardware wallets

fix back navigation

This commit fixes two minor user-interface navigation bugs in a Bitcoin seed-signer device app. In one screen, pressing the hardware back button after entering a mnemonic incorrectly dumped the user at the main menu instead of going back. …

No security-relevant keywords in commit title or messageNo changes to cryptography, key handling, or authenticationChange is purely UI navigation flow
5c7dcd17by PROWLERx15+4−41 file
No security note in commit
Low 46 AI analysisMessage 45 · Thin
SS SeedSignerSeedSigner BitcoinHardware wallets

replaced os.popen() with inbuilt file handling

This commit replaces a shell command used to read the Raspberry Pi CPU serial number with safer built-in Python file reading. The old code ran the command 'cat /proc/cpuinfo | grep Serial' through the operating system shell, which is gener…

Removal of os.popen shell invocationReplacement of shell pipeline with native file I/ODefensive hardening in entropy collection path
a00810caby S1DDHEY+6−41 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
SS SeedSignerSeedSigner BitcoinHardware wallets

Add missing "beta" designation for Czech

This commit simply adds the word '(beta)' to the Czech language label in the settings, matching how other unfinished translations are already labeled. It is a cosmetic/UI labeling change with no security relevance.

990686f7by kdmukai+1−11 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
SS SeedSignerSeedSigner BitcoinHardware wallets

Finalize v0.8.7 languages

This commit simply reorganizes which languages are labeled as 'beta' or 'incomplete' in the SeedSigner settings menu. It adds, removes, and re-categorizes language display names (for example moving Czech to beta and Greek to incomplete). T…

8dbaa548by kdmukai+12−101 file
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
SS SeedSignerSeedSigner BitcoinHardware wallets

chore: bump version to 0.8.7

This commit is a routine version bump from 0.8.6 to 0.8.7. It only changes three version-number strings in project metadata and a translation template. There is no code behavior change, no bug fix, and no security relevance visible in the …

27c8aa35by okaybro+4−43 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
SS SeedSignerSeedSigner BitcoinHardware wallets

minor comment updates

This commit only changes two source-code comments in a single GUI component file. One adds a developer TODO note about consolidating font file locations, and the other fixes a typo in an existing comment. No executable code, logic, or beha…

848fbc03by Nick Klockenga+2−11 file
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
SS SeedSignerSeedSigner BitcoinHardware wallets

refactor(l10n): make multisig wallet policy display translatable

This commit is a straightforward user-interface refactor that makes multisig wallet policy text translatable. It replaces hard-coded English strings like '2 of 3' with localizable template strings, adds a small helper to extract threshold …

7f7f977aby okaybro+59−66 files
No security note in commit
Informational 15 AI analysisMessage 77 · Adequate
SS SeedSignerSeedSigner BitcoinHardware wallets

fix(IOTestScreen): stop blanking out "Clear" button for the screenshot renderer

This is a tiny user-interface fix for a hardware wallet project. It changes when a button label is hidden so that screenshot/translation tools can see the word "Clear", while real devices still start with an empty button. There is no secur…

3e1f8625by okaybro+5−11 file
No security note in commit
Informational 16 AI analysisMessage 35 · Opaque
SS SeedSignerSeedSigner BitcoinHardware wallets

Improvements for SettingsQR Generator

This commit makes small, non-security improvements to how SeedSigner discovers language files and how settings are exported. It removes a script that could write a settings definition file to a microSD card, but that script only ran when a…

Removal of a standalone export script that wrote to /mnt/microsd when executed on the device hostnamePath traversal/reliability improvement: replaces cwd-based path construction with resolved pathlib pathsNo explicit security bug, CVE, or vulnerability fix present in the diff
fa111d8dby kdmukai+24−271 file
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
SS SeedSignerSeedSigner BitcoinHardware wallets

fix(l10n): update MicroSD toast timer terminology and add translator notes

This commit is a non-security change. It renames the user-facing label 'MicroSD toast timer' to 'MicroSD notification duration' and adds two translator comments to help people translate the terms into other languages. No code behavior chan…

aa4b8e06by okaybro+3−11 file
No security note in commit
Informational 15 AI analysisMessage 77 · Adequate
SS SeedSignerSeedSigner BitcoinHardware wallets

fix(l10n): use named variables in `NetworkMismatchView` message

This commit is a minor localization (translation) improvement. It changes how a user-facing error message is assembled so translators can more easily work with named placeholders instead of numbered ones. There is no security-relevant chan…

b7f394e9by okaybro+6−41 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefix: replace removed `get_seed` call in `PSBTSelectSeedView`by okaybro · 442b7a1a · Jul 22, 2026 · 2 filesMessage 77 · AdequateLow 43Details
Commit message · okaybro

fix: replace removed `get_seed` call in `PSBTSelectSeedView`

Co-authored-by: Nick Klockenga <127377+newtonick@users.noreply.github.com>

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing boundaryseed or entropy pathsigning or wallet path
AI analysis · Low 43/100

This commit fixes a bug where selecting an existing seed during PSBT signing would crash because the code called a method (`get_seed`) that no longer exists. The fix uses the already-loaded list of seeds directly. The crash is a reliability issue, not a direct theft-of-funds vulnerability, but it could prevent a user from signing a transaction at a critical moment.

Security candidatechore: update seedsigner-screenshots submodule to latest devby okaybro · 387fa91f · Jul 21, 2026 · 1 fileMessage 77 · AdequateInformational 15Details
Commit message · okaybro

chore: update seedsigner-screenshots submodule to latest dev

Bumps the screenshots submodule from c157f6e to f04b02c (28 commits),
picking up the v0.8.7 screenshot updates.

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit only updates a submodule containing screenshots used for documentation or testing. There is no code change to the SeedSigner application itself, so it has no security impact on users.

Security candidaterefactor: use `Seed` instead of `seed_num`by okaybro · 65e312c9 · Jul 21, 2026 · 8 filesMessage 57 · ThinInformational 15Details
Commit message · okaybro

refactor: use `Seed` instead of `seed_num`

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a straightforward internal code cleanup: it replaces the use of numeric seed indexes (seed_num) with direct references to Seed objects throughout the user interface and tests. There is no security-relevant change; it is purely a refactoring to make the code clearer and avoid index-based lookups.

Security candidateMinor bugfix to correct if/else pathby kdmukai · c52577a9 · Jul 15, 2026 · 1 fileMessage 45 · ThinInformational 23Details
Commit message · kdmukai

Minor bugfix to correct if/else path

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 23/100

This commit fixes a small logic bug in SeedSigner, a hardware-wallet-like signing device. The code was checking whether a seed's fingerprint string was empty, but it should have been checking whether the seed has a passphrase. The bug could cause the app to skip computing or displaying the seed fingerprint at the wrong time, potentially confusing the user about which seed they are finalizing. There is no direct evidence in the commit that this is a security vulnerability, and no exploit path is described.

Security candidatefix commentby PROWLERx15 · cf37ac2a · Jun 2, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · PROWLERx15

fix comment

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit only fixes the indentation of a comment line so it is properly formatted as a code comment. No executable code, logic, or behavior was changed.

Security candidateupdate commentby Kshitij · 94485e52 · Jun 2, 2026 · 1 fileMessage 33 · OpaqueInformational 15Details
Commit message · Kshitij

update comment

Co-authored-by: kdmukai <934746+kdmukai@users.noreply.github.com>

33/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body! Too few words to establish purpose! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit only rewrites an inline code comment to describe the same back-button behavior more clearly. No actual code logic, function calls, or data handling changed.

Security candidateadded comment explaining changesby PROWLERx15 · d0b729a5 · Jun 1, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · PROWLERx15

added comment explaining changes

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit only adds a clarifying comment to existing code. It does not change any program behavior, fix a bug, or alter security logic. The comment explains that pressing the back button during seed phrase entry can mean either aborting entirely (on the first word) or returning to the previous word (on later words), and that aborting requires discarding the partially entered mnemonic.

Security candidateupdate conditional branchby PROWLERx15 · ef7d3716 · Apr 9, 2026 · 1 fileMessage 35 · OpaqueLow 34Details
Commit message · PROWLERx15

update conditional branch

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 34/100

This commit changes how the back button behaves during two seed-related screens. In the first screen, it simplifies the logic so that the pending mnemonic is only discarded when leaving from the first word. In the second screen, it removes the back-button handling entirely, meaning pressing back on the finalization screen no longer returns to the previous view. The commit message gives no security context, and the changes appear to be a UI-flow bugfix rather than a security fix, though removing back-button handling could affect user workflow or data persistence in subtle ways.

Security candidatefix back navigationby PROWLERx15 · 5c7dcd17 · Apr 6, 2026 · 1 fileMessage 28 · OpaqueInformational 19Details
Commit message · PROWLERx15

fix back navigation

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 19/100

This commit fixes two minor user-interface navigation bugs in a Bitcoin seed-signer device app. In one screen, pressing the hardware back button after entering a mnemonic incorrectly dumped the user at the main menu instead of going back. In another screen, the back-button response was checked too late, after normal menu choices, which could make the back button behave oddly. These are usability fixes, not security fixes.

Security candidatereplaced os.popen() with inbuilt file handlingby S1DDHEY · a00810ca · Apr 4, 2026 · 1 fileMessage 45 · ThinLow 46Details
Commit message · S1DDHEY

replaced os.popen() with inbuilt file handling

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 46/100

This commit replaces a shell command used to read the Raspberry Pi CPU serial number with safer built-in Python file reading. The old code ran the command 'cat /proc/cpuinfo | grep Serial' through the operating system shell, which is generally discouraged because it can be risky if any part of the command string is ever influenced by untrusted input. In this specific case, the command string was hardcoded and contained no user input, so the direct risk is low. The change is a defensive hardening improvement rather than a fix for an active vulnerability.

Security candidateAdd missing "beta" designation for Czechby kdmukai · 990686f7 · Mar 6, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · kdmukai

Add missing "beta" designation for Czech

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit simply adds the word '(beta)' to the Czech language label in the settings, matching how other unfinished translations are already labeled. It is a cosmetic/UI labeling change with no security relevance.

Security candidateFinalize v0.8.7 languagesby kdmukai · 8dbaa548 · Mar 6, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · kdmukai

Finalize v0.8.7 languages

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit simply reorganizes which languages are labeled as 'beta' or 'incomplete' in the SeedSigner settings menu. It adds, removes, and re-categorizes language display names (for example moving Czech to beta and Greek to incomplete). There is no change to security logic, cryptography, or user data handling.

Security candidatechore: bump version to 0.8.7by okaybro · 27c8aa35 · Mar 5, 2026 · 3 filesMessage 57 · ThinInformational 15Details
Commit message · okaybro

chore: bump version to 0.8.7

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine version bump from 0.8.6 to 0.8.7. It only changes three version-number strings in project metadata and a translation template. There is no code behavior change, no bug fix, and no security relevance visible in the diff.

Security candidateminor comment updatesby Nick Klockenga · 848fbc03 · Feb 20, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Nick Klockenga

minor comment updates

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit only changes two source-code comments in a single GUI component file. One adds a developer TODO note about consolidating font file locations, and the other fixes a typo in an existing comment. No executable code, logic, or behavior was altered.

Security candidaterefactor(l10n): update translator notes for multisig policy displayby okaybro · 4c94f427 · Feb 19, 2026 · 3 filesMessage 62 · AdequateInformational 15Details
Commit message · okaybro

refactor(l10n): update translator notes for multisig policy display

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit only rewrites the explanatory notes shown to translators so they understand what the numbers in a multisig wallet policy mean. No code behavior, user-facing text, or security logic changed.

Security candidaterefactor(l10n): make multisig wallet policy display translatableby okaybro · 7f7f977a · Feb 19, 2026 · 6 filesMessage 62 · AdequateInformational 15Details
Commit message · okaybro

refactor(l10n): make multisig wallet policy display translatable

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a straightforward user-interface refactor that makes multisig wallet policy text translatable. It replaces hard-coded English strings like '2 of 3' with localizable template strings, adds a small helper to extract threshold and participant counts from descriptors, and updates tests. There is no security-relevant change and no indication of a vulnerability being fixed.

Security candidatefix(IOTestScreen): stop blanking out "Clear" button for the screenshot rendererby okaybro · 3e1f8625 · Feb 18, 2026 · 1 fileMessage 77 · AdequateInformational 15Details
Commit message · okaybro

fix(IOTestScreen): stop blanking out "Clear" button for the screenshot renderer

Co-authored-by: kdmukai <934746+kdmukai@users.noreply.github.com>

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This is a tiny user-interface fix for a hardware wallet project. It changes when a button label is hidden so that screenshot/translation tools can see the word "Clear", while real devices still start with an empty button. There is no security issue here.

Security candidateImprovements for SettingsQR Generatorby kdmukai · fa111d8d · Feb 17, 2026 · 1 fileMessage 35 · OpaqueInformational 16Details
Commit message · kdmukai

Improvements for SettingsQR Generator

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 16/100

This commit makes small, non-security improvements to how SeedSigner discovers language files and how settings are exported. It removes a script that could write a settings definition file to a microSD card, but that script only ran when a developer manually executed the file. There is no clear security vulnerability being fixed.

Security candidatefix(l10n): update MicroSD toast timer terminology and add translator notesby okaybro · aa4b8e06 · Feb 16, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · okaybro

fix(l10n): update MicroSD toast timer terminology and add translator notes

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a non-security change. It renames the user-facing label 'MicroSD toast timer' to 'MicroSD notification duration' and adds two translator comments to help people translate the terms into other languages. No code behavior changes.

Security candidatefix(l10n): use named variables in `NetworkMismatchView` messageby okaybro · b7f394e9 · Feb 16, 2026 · 1 fileMessage 77 · AdequateInformational 15Details
Commit message · okaybro

fix(l10n): use named variables in `NetworkMismatchView` message

Co-authored-by: kdmukai <934746+kdmukai@users.noreply.github.com>

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a minor localization (translation) improvement. It changes how a user-facing error message is assembled so translators can more easily work with named placeholders instead of numbered ones. There is no security-relevant change.

Security candidatefix(l10n): mark missing strings for translationby okaybro · 12a8e1c4 · Feb 16, 2026 · 2 filesMessage 57 · ThinInformational 15Details
Commit message · okaybro

fix(l10n): mark missing strings for translation

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit only wraps a few user-visible English text strings with translation markers so they can be translated into other languages. It does not change program logic, access controls, cryptography, or any security behavior. There is no security issue here.

Security candidatebufixes: dataclass; paramby kdmukai · 0b373b32 · Jan 20, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · kdmukai

bufixes: dataclass; param

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This is a tiny code cleanup commit in a single display driver file. It adds the Python dataclass decorator to a class and renames one method parameter from 'state' to 'enabled' to match the rest of the code. There is no visible security relevance.

Security candidateRename to `BaseDisplayDriver`; ili9341 changesby kdmukai · 777f6041 · Jan 20, 2026 · 4 filesMessage 45 · ThinInformational 15Details
Commit message · kdmukai

Rename to `BaseDisplayDriver`; ili9341 changes

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine internal code cleanup. It renames the parent display class from DisplayDriver to BaseDisplayDriver, makes a couple of methods optional instead of requiring every display subclass to implement them, and adjusts the ILI9341 display driver to inherit from the new base class. There is no visible security fix or vulnerability being addressed.

Security candidateRefactor `DisplayDriver` to be a true parent class; add Factoryby kdmukai · 6fed5e88 · Jan 20, 2026 · 4 filesMessage 50 · ThinInformational 15Details
Commit message · kdmukai

Refactor `DisplayDriver` to be a true parent class; add Factory

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine internal code reorganization. It restructures how the SeedSigner app creates and manages its screen drivers, turning the existing display controller into a parent class and adding a factory pattern. There is no indication this change fixes a security bug or introduces a security vulnerability.

Security candidateBetter bulletproofingby kdmukai · dd9b3ece · Jan 20, 2026 · 2 filesMessage 18 · OpaqueLow 35Details
Commit message · kdmukai

Better bulletproofing

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 35/100

This commit hardens how SeedSigner loads multiselect settings from saved files or QR codes. Previously, an empty or malformed multiselect value (for example, an empty string, a lone comma, or a missing entry) could leave the setting empty, which might cause unexpected behavior when the app later uses that setting. The patch now strips empty pieces from comma-separated input and falls back to the default value whenever the result is empty. A new test checks four empty/missing cases.