MG
← All projectsMAGIC Grants

Skylight Wallet

Modern open-source self-custody Monero light wallet using Monero LWS.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

299 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

39security candidates178second-pass queue217AI analyses
77commits · 30 days
101commits · 60 days
139commits · 180 days
292commits · 365 days
Backfill bands
Sep 27 → Mar 31160 seen18 candidatesComplete
Mar 31 → Jul 2928 seen4 candidatesComplete
Jul 29 → Aug 2834 seen3 candidatesComplete
Aug 28 → Sep 2748 seen9 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
151Thin · 40–59
138Opaque · 0–39
17security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Keeqler25135185236
Justin Ehrenhofer42428240
Licaon_Kter302034
SamsungGalaxyPlayer202035
jermanuts100045
Analysis record

Published AI watches

Last scanned 19 minutes ago

Low 32 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #178 from MAGICGrants/2.1.0-release-fixes

This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …

New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
320c02ceby Justin Ehrenhofer+383−362427 files
No security note in commit
Informational 3 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update pins

This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…

Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
7125d971by Justin Ehrenhofer+25−252 files
No security note in commit
Informational 0 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'main' into 2.1.0-release-fixes

This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…

50b25b5eby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 18 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Skip fetching unused submodules

This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …

Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
8c5b00d3by Justin Ehrenhofer+9−33 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #179 from MAGICGrants/update-moneroc-libs

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…

3df9967aby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …

2cf30607by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix desktop builds

This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…

e0eaa15fby Justin Ehrenhofer+11−22 files
No security note in commit
Low 34 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #176 from MAGICGrants/desktop-ui

This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …

Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
d6d9d318by Justin Ehrenhofer+3922−151454 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.

993a1147by Justin Ehrenhofer+1−11 file
No security note in commit
Low 46 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Updates for Monero 0.18.5.3

This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…

Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
5f5eea3eby Justin Ehrenhofer+37−296 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #175 from MAGICGrants/update-moneroc-libs

This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…

424f9588by Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…

1e620a30by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Show fiat API failure as a warning triangle by the balance; aligns with Spice

This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…

09609000by Keeqler+64−541 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix mobile screen transitions

This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…

9456bbbdby Keeqler+3−11 file
No security note in commit
Informational 18 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix create password screen showing up on mobile; format

This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…

Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
6483d8a1by Keeqler+163−729 files
No security note in commit
Informational 15 AI analysisMessage 73 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge remote-tracking branch 'origin/send-wallet-core' into brightness-fix

This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.

1f4209d3by Keeqler+77−10512 files
No security note in commit
Informational 23 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #173 from MAGICGrants/review-prompt

This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…

Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
6528c1cbby Keeqler+165−19 files
No security note in commit
Informational 17 AI analysisMessage 68 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'desktop-ui' into brightness-fix

This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…

Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
2932c7e0by Keeqler+3592−143843 files
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.

dcb087efby Keeqler+1−11 file
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 408 to 409 in a configuration file. No code, dependencies, or security settings were changed. There is no security relevance.

e69ac4eeby Keeqler+1−11 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityUpdate monero_c and wallet-core pinsby Keeqler · 9d2aa729 · Sep 18, 2026 · 3 filesMessage 45 · ThinTriage 0Details
Commit message · Keeqler

Update monero_c and wallet-core pins

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedBump buildby Keeqler · e69ac4ee · Sep 18, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler

Bump build

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only increases the app's internal build number from 408 to 409 in a configuration file. No code, dependencies, or security settings were changed. There is no security relevance.

AI review queuedMerge pull request #166 from MAGICGrants/update-moneroc-libsby Keeqler · 39a3898a · Sep 18, 2026 · 7 filesMessage 58 · ThinInformational 0Details
Commit message · Keeqler

Merge pull request #166 from MAGICGrants/update-moneroc-libs

Update monero_c libraries

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 0/100

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and the commit message does not describe any security fix. There is no visible evidence of a vulnerability or malicious change.

AI review queuedUpdate monero_c librariesby Keeqler · bee363ca · Sep 18, 2026 · 7 filesMessage 35 · OpaqueInformational 0Details
Commit message · Keeqler

Update monero_c libraries

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 0/100

This commit only replaces precompiled Monero wallet library files (binary .so/.dll/framework files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the underlying libraries is provided. There is not enough visible information to determine whether this update fixes a security issue, adds a feature, or is a routine maintenance bump.

Security candidateMerge pull request #164 from MAGICGrants/moneroc-pin-updateby Keeqler · 4cad895d · Sep 18, 2026 · 3 filesMessage 58 · ThinInformational 3Details
Commit message · Keeqler

Merge pull request #164 from MAGICGrants/moneroc-pin-update

Update wallet-core and monero_c pin

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
access controlmerge-commit duplicate discount
AI analysis · Informational 3/100

This commit only updates version pins (commit hash references) for two external code libraries used by the Skylight Wallet app: monero_c and wallet-core. The actual code changes in those libraries are not shown in this commit. There is no description of any security fix, bug fix, or feature change. Based on this commit alone, we cannot determine whether the update fixes a security issue, introduces one, or is a routine maintenance change.

AI review queuedMerge pull request #165 from MAGICGrants/fixesby Keeqler · e34eef4e · Sep 18, 2026 · 5 filesMessage 53 · ThinLow 49Details
Commit message · Keeqler

Merge pull request #165 from MAGICGrants/fixes

2.0.0 Fixes

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Low 49/100

This update fixes a display bug in a Monero wallet app where the receive screen could show a payment address and a subaddress number that did not match. The mismatch could mislead a user into thinking funds were sent to one numbered account when they were actually sent to another, creating confusion and possible accounting/payment errors. The patch reads the address and its index together as a single value so they stay consistent.

Security candidateUpdate wallet-core pinby Keeqler · dc97aed9 · Sep 18, 2026 · 2 filesMessage 28 · OpaqueInformational 3Details
Commit message · Keeqler

Update wallet-core pin

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Informational 3/100

This commit only changes which version of an internal software library (wallet-core) the Skylight Wallet app depends on. It updates a reference code (a Git commit hash) in two package-management files. The commit message does not say why the update was made, and no security-related explanation is provided. Without seeing what actually changed inside the wallet-core library between the two referenced versions, we cannot tell whether this fixes a security problem, adds a feature, or is just routine maintenance.

Security candidateUpdate wallet-core pinby Keeqler · 6fc90e27 · Sep 18, 2026 · 2 filesMessage 28 · OpaqueInformational 4Details
Commit message · Keeqler

Update wallet-core pin

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Informational 4/100

This commit only changes how the app pulls in its shared wallet library. It switches from a local folder reference to a pinned Git commit from the same project's online repository, and updates that pinned version to a newer commit. There is no visible code change in the app itself, and nothing in the commit message or diff indicates a security fix or vulnerability.

Security candidateUpdate monero_c pinby Keeqler · f8ca4c37 · Sep 18, 2026 · 3 filesMessage 28 · OpaqueLow 25Details
Commit message · Keeqler

Update monero_c pin

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Low 25/100

This commit updates a dependency pin for the core Monero library used by the Skylight Wallet app and switches several wallet helper packages from remote Git downloads to local file paths. The change itself is a routine dependency bump and local development path change. There is no direct evidence in the commit that this fixes a security vulnerability, but updating a pinned cryptographic/wallet library can sometimes include security fixes from upstream. We cannot confirm that without inspecting the upstream library changes, which are not provided.

AI review queuedMonero address fixesby Justin Ehrenhofer · ae157ba7 · Sep 18, 2026 · 3 filesMessage 28 · OpaqueModerate 59Details
Commit message · Justin Ehrenhofer

Monero address fixes

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This commit fixes a bug in the Skylight Wallet's Monero receive screen where the wallet could display one subaddress while labeling it with the index of a different subaddress. The fix bundles the address and its index into a single value so they are always read together consistently. If left unfixed, a user could copy and share a receiving address that is mismatched with the label, potentially causing payments to be credited to the wrong wallet entry or making reconciliation confusing. There is no direct evidence of malicious exploitation; it appears to be a correctness and usability fix.

Lower-priorityFix: always show primary addressby Justin Ehrenhofer · f8c674aa · Sep 18, 2026 · 2 filesMessage 57 · ThinTriage 0Details
Commit message · Justin Ehrenhofer

Fix: always show primary address

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI review queuedMerge pull request #163 from MAGICGrants/conn-example-fixby Keeqler · 9123a94c · Sep 18, 2026 · 8 filesMessage 58 · ThinInformational 15Details
Commit message · Keeqler

Merge pull request #163 from MAGICGrants/conn-example-fix

Use wallet-core connection examples

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine UI cleanup. It removes hard-coded placeholder text examples for server addresses from the app's translation files and instead asks the underlying wallet library for example addresses. There is no security-relevant change here—only where the example text comes from.

AI review queuedBump buildby Keeqler · 4a12746f · Sep 18, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler

Bump build

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only increases the app's build number from 407 to 408 in a configuration file. It changes no code, no dependencies, and no security settings. There is no security relevance.

AI review queuedUse wallet-core connection examplesby Keeqler · caec09b1 · Sep 18, 2026 · 7 filesMessage 45 · ThinInformational 12Details
Commit message · Keeqler

Use wallet-core connection examples

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit changes where the example server addresses come from in the wallet's connection setup screen. Previously, placeholder text like 'lws.example.com:18090' and 'node.example.com:18081' was hard-coded in the app's translation files. Now the app asks the underlying wallet-core library for an example address instead. There is no visible security bug being fixed here; it appears to be a code cleanup or consistency improvement.

AI review queuedMerge pull request #162 from MAGICGrants/fixesby Keeqler · 7c132d94 · Sep 17, 2026 · 29 filesMessage 53 · ThinModerate 61Details
Commit message · Keeqler

Merge pull request #162 from MAGICGrants/fixes

2.0.0 Fixes

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Moderate 61/100

This is a large bug-fix and refactoring update for the Skylight Wallet app. The most important security-relevant changes fix ways the app could send or store money incorrectly: amounts were being converted through imprecise 'double' numbers, which could slightly alter the value the user intended to send; the 'Max' send button could fail or produce wrong values for large balances; the address book was moved into shared wallet-core code so both apps use one secure storage format; and deleting a wallet now properly stops the background sync service first, preventing the deleted wallet from being recreated by a still-running background task. Several other changes improve error handling, sharing, and connection settings so users do not accidentally save a private-server address as a public one.

Lower-priorityBump wallet-core and build numberby Keeqler · cb707ce6 · Sep 17, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Keeqler

Bump wallet-core and build number

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedTor, Decimal fixesby Justin Ehrenhofer · 25361082 · Sep 17, 2026 · 7 filesMessage 28 · OpaqueLow 45Details
Commit message · Justin Ehrenhofer

Tor, Decimal fixes

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 45/100

This commit fixes two practical bugs in a Monero wallet app. First, it stops comparing money amounts using floating-point 'double' numbers, which can round incorrectly and let a user think they are sending their full balance when they are not (or vice versa). It now compares exact integer 'piconero' units. Second, it makes the Tor connection logic respect the user's Tor setting: if Tor is set to 'external' or 'disabled', the app no longer blindly tries to start its built-in Tor and waits two minutes. These are correctness/reliability fixes rather than obvious remote-hack vulnerabilities, but they could affect privacy and funds handling.

Lower-priorityMigrate Tor to `wallet-core`by Justin Ehrenhofer · 92ea15ff · Sep 17, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Justin Ehrenhofer

Migrate Tor to `wallet-core`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityUse better `wallet-core` datesby Justin Ehrenhofer · d5e3a761 · Sep 17, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Justin Ehrenhofer

Use better `wallet-core` dates

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityBlock screenshots on lws details screenby Justin Ehrenhofer · 09426e18 · Sep 17, 2026 · 1 fileMessage 60 · AdequateTriage 0Details
Commit message · Justin Ehrenhofer

Block screenshots on lws details screen

This makes it consistent with the other LWS details screens

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Lower-priorityMigrate contacts to `wallet-core`by Justin Ehrenhofer · baf37eb3 · Sep 17, 2026 · 5 filesMessage 45 · ThinTriage 0Details
Commit message · Justin Ehrenhofer

Migrate contacts to `wallet-core`

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedImprove decimal handlingby Justin Ehrenhofer · 87f84ae1 · Sep 17, 2026 · 3 filesMessage 28 · OpaqueModerate 64Details
Commit message · Justin Ehrenhofer

Improve decimal handling

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Moderate 64/100

This commit fixes a Monero wallet bug where the amount a user wanted to send could silently change because the app was converting the typed amount into a 'double' (a computer number format with limited precision) before turning it into the exact atomic units the blockchain actually uses. The patch keeps the amount as text the whole way through, so the value the user sees is the value that gets spent. It also fixes a related bug where tapping 'Max' for large balances could produce unusable scientific notation like '5e-7'.

Security candidateBetter isolate node vs lws connectionsby Justin Ehrenhofer · dd96af76 · Sep 16, 2026 · 3 filesMessage 60 · AdequateHigh 72Details
Commit message · Justin Ehrenhofer

Better isolate node vs lws connections

We don't want to accidentally send the view key to a node

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · High 72/100

This commit fixes a Monero wallet bug where the app could accidentally save a private 'view key' to a regular Monero node instead of a lightweight wallet server (LWS). The fix separates saved server addresses for the two connection modes so that switching modes doesn't leave the wrong server address in the settings field. If the wrong address were saved, the user's private view key could be exposed to a node operator, allowing them to see all incoming transactions for that wallet.

Lower-priorityFix: Edit contact spacingby Justin Ehrenhofer · b43f3d7b · Sep 16, 2026 · 1 fileMessage 47 · ThinTriage 0Details
Commit message · Justin Ehrenhofer

Fix: Edit contact spacing

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
AI review queuedFix: Delete additional itemsby Justin Ehrenhofer · 6a84d569 · Sep 16, 2026 · 2 filesMessage 47 · ThinModerate 57Details
Commit message · Justin Ehrenhofer

Fix: Delete additional items

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 57/100

This commit fixes a bug in the wallet-deletion process. Previously, the app deleted wallet files while a background sync service still had them open in another process. That could leave deleted wallet data partially restored on disk, or cause the app to keep syncing a wallet the user asked to remove. The fix tells the sync service to stop first, then deletes the wallet through the core library's proper teardown path.