MG
← All projectsMAGIC Grants

Skylight Wallet

Modern open-source self-custody Monero light wallet using Monero LWS.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

299 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

39security candidates178second-pass queue217AI analyses
77commits · 30 days
98commits · 60 days
139commits · 180 days
292commits · 365 days
Backfill bands
Sep 27 → Mar 31160 seen18 candidatesComplete
Mar 31 → Jul 2928 seen4 candidatesComplete
Jul 29 → Aug 2834 seen3 candidatesComplete
Aug 28 → Sep 2748 seen9 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
151Thin · 40–59
138Opaque · 0–39
17security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Keeqler25135185236
Justin Ehrenhofer42428240
Licaon_Kter302034
SamsungGalaxyPlayer202035
jermanuts100045
Analysis record

Published AI watches

Last scanned 19 minutes ago

Low 32 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #178 from MAGICGrants/2.1.0-release-fixes

This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …

New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
320c02ceby Justin Ehrenhofer+383−362427 files
No security note in commit
Informational 3 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update pins

This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…

Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
7125d971by Justin Ehrenhofer+25−252 files
No security note in commit
Informational 0 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'main' into 2.1.0-release-fixes

This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…

50b25b5eby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 18 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Skip fetching unused submodules

This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …

Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
8c5b00d3by Justin Ehrenhofer+9−33 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #179 from MAGICGrants/update-moneroc-libs

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…

3df9967aby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …

2cf30607by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix desktop builds

This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…

e0eaa15fby Justin Ehrenhofer+11−22 files
No security note in commit
Low 34 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #176 from MAGICGrants/desktop-ui

This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …

Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
d6d9d318by Justin Ehrenhofer+3922−151454 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.

993a1147by Justin Ehrenhofer+1−11 file
No security note in commit
Low 46 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Updates for Monero 0.18.5.3

This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…

Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
5f5eea3eby Justin Ehrenhofer+37−296 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #175 from MAGICGrants/update-moneroc-libs

This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…

424f9588by Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…

1e620a30by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Show fiat API failure as a warning triangle by the balance; aligns with Spice

This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…

09609000by Keeqler+64−541 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix mobile screen transitions

This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…

9456bbbdby Keeqler+3−11 file
No security note in commit
Informational 18 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix create password screen showing up on mobile; format

This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…

Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
6483d8a1by Keeqler+163−729 files
No security note in commit
Informational 15 AI analysisMessage 73 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge remote-tracking branch 'origin/send-wallet-core' into brightness-fix

This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.

1f4209d3by Keeqler+77−10512 files
No security note in commit
Informational 23 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #173 from MAGICGrants/review-prompt

This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…

Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
6528c1cbby Keeqler+165−19 files
No security note in commit
Informational 17 AI analysisMessage 68 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'desktop-ui' into brightness-fix

This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…

Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
2932c7e0by Keeqler+3592−143843 files
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.

dcb087efby Keeqler+1−11 file
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 408 to 409 in a configuration file. No code, dependencies, or security settings were changed. There is no security relevance.

e69ac4eeby Keeqler+1−11 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedRemove debug codeby Keeqler · f60da793 · Jan 15, 2026 · 1 fileMessage 28 · OpaqueInformational 22Details
Commit message · Keeqler

Remove debug code

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 22/100

This commit removes leftover debugging code from a background task that checks for new wallet transactions. It deletes a console log message and, more importantly, removes a temporary '+1' fudge added to the transaction count. That fudge could have caused the app to think there was one more transaction than actually existed, which might trigger unnecessary notifications or confusion, but it does not appear to let an attacker steal funds or take control.

AI review queuedAdd monero_c build for real ios, more fixes and adjustmentsby Keeqler · 1d5b4ad3 · Jan 15, 2026 · 13 filesMessage 50 · ThinInformational 18Details
Commit message · Keeqler

Add monero_c build for real ios, more fixes and adjustments

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit is mostly a routine iOS build-system update for a Monero wallet app. It swaps a single-architecture iOS framework for a universal 'xcframework' that supports both real iPhones and the simulator, and makes a few small platform-specific cleanups in the Dart code. There is no clear security bug being fixed here; it looks like normal development work to get the iOS app building and running correctly.

Lower-priorityRemove debug code, minor ui changes and fix tor issuesby Keeqler · a759ea2c · Jan 8, 2026 · 13 filesMessage 50 · ThinTriage 0Details
Commit message · Keeqler

Remove debug code, minor ui changes and fix tor issues

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedwipby Keeqler · ab5b771e · Jan 8, 2026 · 32 filesMessage 0 · OpaqueInformational 24Details
Commit message · Keeqler

wip

0/100 · OpaqueMessage clarity
! Generic or placeholder subject! Too few words to establish purpose! No meaningful explanatory body! Contains work-in-progress language
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 24/100

This is a large work-in-progress commit for a Monero wallet app. It mainly adds iOS support (CocoaPods setup, a bundled MoneroWallet framework, notification and logging export features) and hardens error handling in the Tor/SOCKS networking code. There is no clear security fix or vulnerability being patched. A few debug leftovers, such as a hardcoded '+1' in transaction counting and a test notification fired on every wallet home screen load, look like unfinished development code rather than intentional malicious changes. The bundled binary framework cannot be inspected from the diff, so its provenance and safety are unknown.

AI review queuedPrevent artifacts from being committed in monero_c build workflowby Keeqler · e39b1f29 · Dec 30, 2025 · 5 filesMessage 50 · ThinInformational 19Details
Commit message · Keeqler

Prevent artifacts from being committed in monero_c build workflow

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This change stops a GitHub Actions workflow from accidentally including pre-built binary files (called 'artifacts') when it creates automated pull requests. Those binaries were being deleted from the repository and the workflow now removes them before opening a PR. This is a repository hygiene and supply-chain safety fix, not a direct vulnerability in running software.

AI review queuedUpdate monero_c librariesby Keeqler · 8088c83e · Dec 30, 2025 · 9 filesMessage 35 · OpaqueInformational 0Details
Commit message · Keeqler

Update monero_c libraries

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 0/100

This commit updates pre-built Monero library files (binary .so files) and points a dependency to a newer version of the upstream monero_c code. The actual source code changes are not visible because the files are compiled binaries. There is no information in the commit message or supplied references saying this update fixes a security problem, introduces a vulnerability, or changes any behavior at all. On its own, this looks like a routine dependency refresh.

AI review queuedFix history auto refresh when pending tx is present and minor ui fixesby Keeqler · b36f4857 · Dec 30, 2025 · 3 filesMessage 50 · ThinInformational 21Details
Commit message · Keeqler

Fix history auto refresh when pending tx is present and minor ui fixes

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit fixes a bug where the transaction history auto-refresh would break when a transaction was still pending (not yet mined). It also makes small user-interface tweaks, such as making list items easier to tap and widening text boxes in transaction details. There is no clear security vulnerability being patched.

Lower-priorityAdd missing apt package to build-monero.shby Keeqler · 8bcf8ee9 · Dec 30, 2025 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Keeqler

Add missing apt package to build-monero.sh

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedAdd reviewersby Keeqler · e4e06c46 · Dec 30, 2025 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler

Add reviewers

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply adds two GitHub usernames to a workflow so they are automatically asked to review future pull requests. It does not change any application code, build logic, secrets, permissions, or security settings.

AI review queuedFix pathby Keeqler · e328b74a · Dec 30, 2025 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler

Fix path

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit corrects a simple typo in a GitHub Actions workflow file. The workflow was supposed to trigger when the file itself changed, but the path had an extra '.yml' extension ('build-builder-image.yml.yml' instead of 'build-builder-image.yml'). This is a routine configuration fix with no security implications.

AI review queuedAdd monero_c build workflowby Keeqler · f717dd42 · Dec 30, 2025 · 5 filesMessage 35 · OpaqueInformational 17Details
Commit message · Keeqler

Add monero_c build workflow

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100

This commit adds automated GitHub Actions workflows to build a Monero wallet library from an external source and create pull requests with the compiled binaries. It also renames a Dockerfile and moves an existing script that removes an executable-stack flag from a Linux library. The changes are mostly build-infrastructure housekeeping. There is no direct evidence of a security vulnerability being introduced, but the workflow does clone and build code from a third-party repository (vtnerd/monero_c) without pinned commit verification at build time, and it later edits pubspec.lock using a remote branch's current commit hash. That creates a supply-chain risk if the upstream repository is compromised, but it is not a confirmed incident.

Lower-priorityAdd connection settings to settings screenby Keeqler · 8cfdf1dc · Dec 30, 2025 · 9 filesMessage 45 · ThinTriage 0Details
Commit message · Keeqler

Add connection settings to settings screen

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedAdd use orbot/invizible checkbox to tor settings screenby Keeqler · bb2e15b8 · Dec 30, 2025 · 10 filesMessage 50 · ThinInformational 19Details
Commit message · Keeqler

Add use orbot/invizible checkbox to tor settings screen

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit adds a user-facing checkbox that lets mobile users choose to route the app's Tor traffic through the separate Orbot/InviZible app instead of a manually entered proxy port. It also changes the default external Tor port from 9150 to 9050 and makes a hardcoded error message translatable. There is no obvious security vulnerability in the diff; it is a feature/configuration improvement.

Security candidateTor settingsby Keeqler · 5cea4663 · Dec 23, 2025 · 24 filesMessage 18 · OpaqueLow 34Details
Commit message · Keeqler

Tor settings

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 34/100

This commit adds user-configurable Tor settings to the Skylight Wallet app. Users can now choose between built-in Tor, an external Tor proxy, or disabling Tor entirely. It also updates how the app fetches exchange rates and blockchain heights so they respect the new Tor setting. There is no clear security bug in the patch itself, but it introduces a 'Tor disabled' mode and changes how network traffic is routed, which could affect user privacy if the settings are mishandled or bypassed.

AI review queuedFix builder workflow againby Keeqler · 627f1d92 · Dec 16, 2025 · 1 fileMessage 35 · OpaqueInformational 18Details
Commit message · Keeqler

Fix builder workflow again

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 18/100

This is a small GitHub Actions workflow fix. It corrects a path trigger so the workflow runs when the workflow file itself changes, and adds a missing 'attestations: write' permission needed for newer GitHub artifact attestation features. There is no direct security vulnerability in the diff; it is a maintenance/configuration correction.

AI review queuedFix builder workflowby Keeqler · 3f336ba6 · Dec 16, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Fix builder workflow

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit adds a new GitHub Actions workflow file that automatically builds and publishes a Docker builder image when the main branch changes. It is a routine CI/CD configuration change with no apparent security defect.

Lower-priorityAdd builder image build workflow and have separate jobs for each app build targetby Keeqler · fba0b735 · Dec 16, 2025 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Keeqler

Add builder image build workflow and have separate jobs for each app build target

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedRemove unconfirmed outgoing transactions workaroundby Keeqler · 7ebb9cfb · Dec 16, 2025 · 2 filesMessage 50 · ThinInformational 22Details
Commit message · Keeqler

Remove unconfirmed outgoing transactions workaround

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 22/100

This commit removes a temporary workaround that stored unconfirmed outgoing transactions in the app's local settings. The app now relies on the underlying Monero wallet library to report pending transactions directly. The change also updates the transaction list UI so that transactions with no block height (height == -1) are shown as unconfirmed. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a cleanup of technical debt that may reduce the risk of stale or misleading transaction data.

AI review queuedUpdate monero_cby Keeqler · 3f00a757 · Dec 15, 2025 · 4 filesMessage 18 · OpaqueInformational 0Details
Commit message · Keeqler

Update monero_c

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 0/100

This commit updates four precompiled Monero library files (binary .so files for Android and Linux) to a newer version. The actual source code changes inside those binaries are not visible in the commit, and no description of why the update was made is provided. There is nothing in the commit message or diff that indicates a security fix, vulnerability, or malicious change.

AI review queuedBump flutter versionby Keeqler · 14dadac0 · Dec 15, 2025 · 3 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Bump flutter version

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply updates the Flutter software development kit version from 3.38.3 to 3.38.5 and the Dart SDK version from 3.10.1 to 3.10.4 in build configuration files. There is no indication of a security fix or vulnerability being addressed.

Lower-priorityDisplay app version and build in settings screenby Keeqler · a4cff038 · Dec 15, 2025 · 4 filesMessage 45 · ThinTriage 0Details
Commit message · Keeqler

Display app version and build in settings screen

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidateFix workflow gpg signingby Keeqler · efe213e5 · Dec 13, 2025 · 1 fileMessage 28 · OpaqueInformational 18Details
Commit message · Keeqler

Fix workflow gpg signing

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
signing boundarydocumentation-only discount
AI analysis · Informational 18/100

This commit fixes a GitHub Actions release workflow that was supposed to sign Android and Linux app files with GPG. Before the fix, the signing command likely failed because it could not unlock the GPG private key without a passphrase. The change passes the GPG passphrase from a GitHub secret into the signing step so the automated signing can complete. It is a build-pipeline fix, not a vulnerability in the wallet application itself.

AI review queuedFix appimage build scriptby Keeqler · 27348572 · Dec 13, 2025 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Keeqler

Fix appimage build script

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply updates the build script to download a newer version of the standard AppImage packaging tool (appimagetool) and records the matching SHA256 checksum. There is no indication of a security vulnerability or malicious change in the diff itself.

AI review queuedBump versionby Keeqler · ec9afeee · Dec 13, 2025 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler

Bump version

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes the app's version number from 1.0.2+6 to 1.0.3+7 in a configuration file. There are no code changes, no security fixes, and no functional changes visible in the diff.

Lower-priorityDisplay "starting tor" in connection screen if not connected and "use tor" is checkedby Keeqler · d219a399 · Dec 12, 2025 · 6 filesMessage 50 · ThinTriage 0Details
Commit message · Keeqler

Display "starting tor" in connection screen if not connected and "use tor" is checked

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body