MG
← All projectsMAGIC Grants

Skylight Wallet

Modern open-source self-custody Monero light wallet using Monero LWS.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

299 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

39security candidates178second-pass queue217AI analyses
77commits · 30 days
98commits · 60 days
139commits · 180 days
292commits · 365 days
Backfill bands
Sep 27 → Mar 31160 seen18 candidatesComplete
Mar 31 → Jul 2928 seen4 candidatesComplete
Jul 29 → Aug 2834 seen3 candidatesComplete
Aug 28 → Sep 2748 seen9 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
151Thin · 40–59
138Opaque · 0–39
17security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Keeqler25135185236
Justin Ehrenhofer42428240
Licaon_Kter302034
SamsungGalaxyPlayer202035
jermanuts100045
Analysis record

Published AI watches

Last scanned 49 minutes ago

Low 32 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #178 from MAGICGrants/2.1.0-release-fixes

This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …

New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
320c02ceby Justin Ehrenhofer+383−362427 files
No security note in commit
Informational 3 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update pins

This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…

Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
7125d971by Justin Ehrenhofer+25−252 files
No security note in commit
Informational 0 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'main' into 2.1.0-release-fixes

This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…

50b25b5eby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 18 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Skip fetching unused submodules

This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …

Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
8c5b00d3by Justin Ehrenhofer+9−33 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #179 from MAGICGrants/update-moneroc-libs

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…

3df9967aby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …

2cf30607by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix desktop builds

This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…

e0eaa15fby Justin Ehrenhofer+11−22 files
No security note in commit
Low 34 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #176 from MAGICGrants/desktop-ui

This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …

Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
d6d9d318by Justin Ehrenhofer+3922−151454 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.

993a1147by Justin Ehrenhofer+1−11 file
No security note in commit
Low 46 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Updates for Monero 0.18.5.3

This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…

Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
5f5eea3eby Justin Ehrenhofer+37−296 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #175 from MAGICGrants/update-moneroc-libs

This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…

424f9588by Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…

1e620a30by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Show fiat API failure as a warning triangle by the balance; aligns with Spice

This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…

09609000by Keeqler+64−541 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix mobile screen transitions

This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…

9456bbbdby Keeqler+3−11 file
No security note in commit
Informational 18 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix create password screen showing up on mobile; format

This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…

Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
6483d8a1by Keeqler+163−729 files
No security note in commit
Informational 15 AI analysisMessage 73 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge remote-tracking branch 'origin/send-wallet-core' into brightness-fix

This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.

1f4209d3by Keeqler+77−10512 files
No security note in commit
Informational 23 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #173 from MAGICGrants/review-prompt

This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…

Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
6528c1cbby Keeqler+165−19 files
No security note in commit
Informational 17 AI analysisMessage 68 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'desktop-ui' into brightness-fix

This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…

Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
2932c7e0by Keeqler+3592−143843 files
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.

dcb087efby Keeqler+1−11 file
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 408 to 409 in a configuration file. No code, dependencies, or security settings were changed. There is no security relevance.

e69ac4eeby Keeqler+1−11 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedUpdate monero_cby Keeqler · c9c5bcd3 · Dec 10, 2025 · 5 filesMessage 18 · OpaqueInformational 3Details
Commit message · Keeqler

Update monero_c

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 3/100

This commit updates precompiled Monero wallet library files and the matching Dart package reference in a dependency lock file. The actual source code changes are not visible because the libraries are binary files. There is no information in the commit message or supplied references indicating this update fixes or introduces any security issue.

Security candidateMake restore height optional, use polyseed restore date and add bip39 supportby Keeqler · b044227b · Dec 10, 2025 · 11 filesMessage 50 · ThinInformational 23Details
Commit message · Keeqler

Make restore height optional, use polyseed restore date and add bip39 support

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialcryptography-sensitive pathsigning or wallet path
AI analysis · Informational 23/100

This commit changes how users restore a Monero wallet in the Skylight Wallet app. It makes the 'restore height' field optional, automatically fills it for newer Polyseed seeds, and adds support for restoring from BIP39-style mnemonic phrases (common 12/24-word seeds). The changes are mostly usability improvements, but they touch sensitive wallet-recovery code and introduce new dependencies for seed handling. There is no direct evidence in the commit of a security vulnerability, but the new BIP39 conversion logic and the changed restore flow deserve careful review because mistakes here could lead to users restoring the wrong wallet or leaking keys.

AI review queuedUpdate monero_cby Keeqler · 7d07171c · Dec 9, 2025 · 5 filesMessage 18 · OpaqueInformational 3Details
Commit message · Keeqler

Update monero_c

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 3/100

This commit updates pre-built Monero library files and the version of a related Dart package, but provides no description of why the update was made. The actual code inside the updated libraries is not shown, so we cannot tell from this commit alone whether it fixes a security issue, adds a feature, or is just routine maintenance.

AI review queuedCall refresh methods properlyby Keeqler · 1c4ef40a · Dec 9, 2025 · 1 fileMessage 35 · OpaqueInformational 22Details
Commit message · Keeqler

Call refresh methods properly

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 22/100

This commit changes how a cryptocurrency wallet app refreshes its data. Previously, three refresh operations ran at the same time in separate background workers. Now they run one after another. The commit message simply says 'Call refresh methods properly.' There is no explicit security explanation in the commit or supplied references, so any security relevance is speculative. The change likely fixes a race condition or crash caused by concurrent access to the same wallet memory, which could in turn prevent inconsistent wallet state or denial-of-service for the user.

Security candidateFix legacy seed restore failby Keeqler · fa0b1e87 · Dec 9, 2025 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · Keeqler

Fix legacy seed restore fail

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit fixes a bug where restoring an older-style cryptocurrency wallet seed would fail. The app now also accepts a specific temporary 'No response from HTTP server' state from the underlying wallet library as a valid signal to proceed with the restore. It also removes an unused import in a seed-generation screen. There is no direct evidence this is a security vulnerability; it appears to be a reliability/bug-fix change.

Security candidateOptimize loading in generate seed screenby Keeqler · ded7bdf3 · Dec 5, 2025 · 3 filesMessage 45 · ThinInformational 16Details
Commit message · Keeqler

Optimize loading in generate seed screen

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 16/100

This commit speeds up the wallet creation screen by fetching the blockchain height ahead of time and by running some setup steps in the background instead of waiting for each one to finish. The changes are framed as a performance optimization. There is no direct evidence in the commit that this fixes a security vulnerability, but it does change how sensitive wallet setup tasks are sequenced and how a shared cache is accessed.

Security candidatePin intlby Keeqler · 1dae3b40 · Dec 4, 2025 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler

Pin intl

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Informational 15/100

This commit changes a single dependency version in a Dart package file from a flexible version range (^0.20.2) to an exact pinned version (0.20.2). This is a routine build/dependency management change with no visible security relevance in the commit itself or supplied references.

Security candidatePin versionsby Keeqler · 72e05e62 · Dec 4, 2025 · 3 filesMessage 18 · OpaqueLow 34Details
Commit message · Keeqler

Pin versions

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Low 34/100

This commit locks down the exact versions of software building blocks used by the Skylight Wallet app and its Docker build image. It upgrades Flutter from 3.27.1 to 3.38.3, pins the Dart SDK to 3.10.1, and replaces flexible version ranges (like ^1.0.8) with exact versions in the project's dependency list. It also refreshes the lock file with newer patch/minor versions of many supporting libraries. The change is primarily a supply-chain hygiene improvement: it makes builds more reproducible and prevents unexpected future updates, but it also pulls in newer library versions that may contain routine bug and security fixes.

AI review queuedAutomatic builds with gh actionsby Keeqler · dfd656c8 · Dec 4, 2025 · 7 filesMessage 45 · ThinInformational 11Details
Commit message · Keeqler

Automatic builds with gh actions

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 11/100

This commit adds an automated GitHub Actions release pipeline for a wallet app. It builds Android and Linux packages, signs them with GPG and Android release keys, and publishes them on GitHub Releases. There is no direct evidence of a security vulnerability in the code changes themselves, but the pipeline handles sensitive secrets and includes a prebuilt binary library that changed without source diff visibility.

AI review queuedDisable navigation bar button when already activeby Keeqler · 0dc71fea · Nov 27, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Keeqler

Disable navigation bar button when already active

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a minor user-interface polish change. It stops a navigation button from doing anything if the user is already on the page it would open. There is no security relevance in the commit message or code change.

AI review queuedFix monero_libwallet2_api_c.so not loading on linuxby Keeqler · 3ea552be · Nov 27, 2025 · 1 fileMessage 50 · ThinInformational 4Details
Commit message · Keeqler

Fix monero_libwallet2_api_c.so not loading on linux

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 4/100

This commit replaces a Linux shared library file (monero_libwallet2_api_c.so) with a new version to fix a loading problem on Linux. The actual source code changes are not visible because the file is a compiled binary. There is no evidence in the commit message or diff that this change is security-related.

Lower-priorityFix race condintions when logging to fileby Keeqler · 6c91a83a · Nov 27, 2025 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Keeqler

Fix race condintions when logging to file

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedBump versionby Keeqler · 521227e9 · Nov 27, 2025 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler

Bump version

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes the application's version number from 1.0.1+5 to 1.0.2+6 in a configuration file. There are no code changes, no security fixes, and no functional changes visible in this patch.

AI review queuedPrevent logs from getting spammed with connection statusby Keeqler · 86dfcf05 · Nov 26, 2025 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Keeqler

Prevent logs from getting spammed with connection status

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply reduces noisy logging. It removes two routine debug messages that were printed every time the wallet checked its connection, and adds one cleaner message only when the connection status actually changes. There is no security fix here.

AI review queuedAdd libwallet2 build for armeabi-v7aby Keeqler · b64be1ab · Nov 26, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Keeqler

Add libwallet2 build for armeabi-v7a

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds a precompiled binary library file for 32-bit ARM Android devices (armeabi-v7a). It is a build/packaging change with no source code modifications visible in the diff. There is no evidence in the commit or supplied references that this change fixes or introduces a security vulnerability.

AI review queuedNew libwallet2 builds and a few tweaksby Keeqler · a333015c · Nov 26, 2025 · 6 filesMessage 45 · ThinLow 29Details
Commit message · Keeqler

New libwallet2 builds and a few tweaks

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit updates pre-built Monero wallet library files, fixes leftover Git merge-conflict markers in the app's startup code, and limits a custom certificate-file workaround to Android only. The merge-conflict cleanup is a routine code tidying change. The certificate change means non-Android platforms will now rely on normal system certificate verification instead of a bundled certificate file, which is generally a good thing but could affect connection behavior. The library updates are opaque binary changes whose security implications cannot be judged from the diff alone.

AI review queuedMinor UI text changeby Keeqler · 7a9a73a9 · Nov 25, 2025 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Minor UI text change

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes two user-visible warning messages in the app's translation files. In English and Portuguese, the warning about running out of subaddresses now says 'used address' instead of 'used subaddress'. There is no code, security logic, or behavior change.

Lower-priorityAccept protocol connection address inputby Keeqler · a7a1a434 · Nov 25, 2025 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Keeqler

Accept protocol connection address input

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidateFix max subaddresses warning bugby Keeqler · d4aadea1 · Nov 25, 2025 · 1 fileMessage 45 · ThinLow 25Details
Commit message · Keeqler

Fix max subaddresses warning bug

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · Low 25/100

This commit fixes a bug in a cryptocurrency wallet app where a warning about reaching the maximum number of subaddresses (separate receiving addresses) could appear at the wrong time or with wrong data. The changes remove a condition that only saved wallet state after transactions were loaded, and they stop assuming a default value of 1 when the saved subaddress index is missing. The security relevance is indirect: it mainly prevents user confusion and possible app misbehavior, not a direct theft or remote attack.

Lower-priorityFix different fees between send and send details screensby Keeqler · aa44ee7d · Nov 24, 2025 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Keeqler

Fix different fees between send and send details screens

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedFix appimage build nameby Keeqler · 7a05fe41 · Nov 24, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Fix appimage build name

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes the filename of the built AppImage package. The build tool was producing a file named like 'Skylight_Wallet-...' but the script later looked for 'skylight-wallet-...' (lowercase), so the final output message and any downstream steps could not find the file. The patch renames the generated file to the expected lowercase name and adds a clear error if it is missing. There is no security relevance.

AI review queuedAdd appimage build scriptby Keeqler · b409571f · Nov 24, 2025 · 8 filesMessage 35 · OpaqueInformational 15Details
Commit message · Keeqler

Add appimage build script

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds a new Linux AppImage build script and packaging files for the Skylight Wallet application, plus a window icon and minor dependency updates. There is no security-relevant code change and no indication of a vulnerability being fixed.

AI review queuedSet build numberby Keeqler · 0d903495 · Nov 24, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Set build number

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes the app's build number in the package configuration file (from version 1.0.1 to 1.0.1+5). It does not modify any code, dependencies, permissions, or security settings. There is no security relevance.

AI review queuedBump versionby Keeqler · 095a5f1e · Nov 21, 2025 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler

Bump version

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes the application's version number in a configuration file (from 1.0.0+4 to 1.0.1). There are no code changes, no security fixes, and no functional changes visible in the diff.

Lower-priorityLWS string improvements for ptbrby Keeqler · 0bc91030 · Nov 21, 2025 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Keeqler

LWS string improvements for ptbr

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body