Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
152Thin · 40–59
139Opaque · 0–39
17security candidates with opaque commit messaging
This commit only updates marketing materials: it refreshes the README wording, adds an F-Droid badge, swaps screenshots and feature graphics, and edits the app store description. No program code, configuration, or dependency files were cha…
This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …
New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…
Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…
This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …
Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…
This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …
This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…
This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …
Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.
This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…
Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…
This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…
This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…
This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…
Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.
This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…
Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…
Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
AI review queuedFix notifications, use secure storage more, iOS background syncby Justin Ehrenhofer · 04037188 · Aug 4, 2026 · 27 filesMessage 50 · ThinModerate 64Details
Commit message · Justin Ehrenhofer
Fix notifications, use secure storage more, iOS background sync
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Moderate 64/100
This commit is a large hardening and bug-fix patch for a mobile Monero wallet. It fixes several privacy and reliability problems: it stops the app from silently falling back to clearnet when Tor is required, moves sensitive address-book and transaction data out of plain storage into encrypted storage, prevents the app from overwriting a corrupted address book with an empty one, fixes notification bugs that could spam or miss transaction alerts, and adds proper iOS background sync. The changes are defensive and reduce the chance of leaking a user's view key, IP address, or contacts.
AI review queuedImprove background syncingby Justin Ehrenhofer · 4a59d406 · Aug 4, 2026 · 3 filesMessage 35 · OpaqueLow 25Details
Commit message · Justin Ehrenhofer
Improve background syncing
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 25/100
This commit fixes a background-sync bug in a cryptocurrency wallet app. Previously, when a background or foreground sync task finished, the wallet's scanning thread could keep running and its progress would be discarded because the wallet was never closed. The change explicitly pauses scanning and saves (checkpoints) the wallet before the task ends, and it also stops early if the sync gets stuck. There is no attacker-controlled behavior here; it is a reliability/bug-fix patch.
AI review queued[Draft] Fix loadsby Justin Ehrenhofer · 38124032 · Aug 4, 2026 · 4 filesMessage 28 · OpaqueModerate 59Details
Commit message · Justin Ehrenhofer
[Draft] Fix loads
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Moderate 59/100
This commit fixes several wallet-loading bugs in a Monero wallet app. The most important change corrects how restored wallets are created: previously the app told the backend that every restored wallet was 'new', which made it skip scanning old transactions, so users could see a zero balance after restoring. The patch also prevents the app from opening the same wallet file twice, stops repeated connection attempts from racing each other, and makes the app detect when a wallet exists in the opposite mode (full node vs light wallet server). These are reliability and correctness fixes rather than remote attack vectors, but the 'new wallet' flag bug could cause real funds to appear missing.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 18/100
This commit improves build reliability and supply-chain consistency for the Skylight Wallet. It switches the source of a key Monero-related library from a personal GitHub account (vtnerd) to the project's own organization (magicgrants), and it replaces a script that pinned the Rust compiler version for only the Tor plugin with a script that also pins the version for the OpenAlias plugin. There is no direct evidence of a security vulnerability being fixed; the changes are best described as hardening build reproducibility and reducing trust in an external repository.
AI review queuedProper fee estimationby Keeqler · 93764cc9 · Aug 4, 2026 · 7 filesMessage 28 · OpaqueLow 33Details
Commit message · Keeqler
Proper fee estimation
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 33/100
This commit changes how the Skylight Wallet app estimates Monero transaction fees. Previously, the app calculated fees by actually building full draft transactions and then reusing those draft transactions when the user pressed send. Now it uses a dedicated native fee-estimation function and always builds the real transaction only when the user confirms the send. The change also switches the underlying Monero library from a personal repository (vtnerd/monero_c) to an organization-owned fork (magicgrants/monero_c). The main security-relevant effect is reducing the risk that a stale or reused draft transaction gets sent accidentally, and it removes a retry loop that could have produced misleading fee information. There is no explicit security bug fixed in the diff itself, so the security relevance is moderate and inferred.
AI review queued[Draft] OA2by Justin Ehrenhofer · f7a9ba07 · Aug 2, 2026 · 7 filesMessage 0 · OpaqueInformational 12Details
Commit message · Justin Ehrenhofer
[Draft] OA2
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 12/100
This commit is a feature draft that upgrades the wallet's OpenAlias support from version 1 to also support the newer OpenAlias v2 standard. It adds safer parsing, DNSSEC-over-Tor resolution, and displays a sanitized recipient name on the confirmation screen. There is no indication in the commit that it fixes a known security bug; it reads as a defensive-by-design feature implementation.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 35/100
This is a large feature update for the Skylight Monero wallet that brings in improvements from another project called Spice. It adds support for connecting directly to a full Monero node (not just a light wallet server), background and continuous syncing, a more secure clipboard for copying sensitive data, QR-code wallet restoration, and a new OpenAlias resolver. The changes are mostly defensive: they improve privacy, reduce clipboard leaks, and make transaction sending more precise. There is no clear security vulnerability introduced by the patch, but because it is a very large change touching many security-sensitive areas (wallet files, network connections, background services, and clipboard handling), it deserves careful review and testing before release.
AI review queuedDo not include dependency metadata in apkby Keeqler · 314952b7 · Jul 7, 2026 · 1 fileMessage 45 · ThinInformational 19Details
Commit message · Keeqler
Do not include dependency metadata in apk
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 19/100
This change stops the Android app package from embedding a list of its third-party libraries. The commit message says this is needed so F-Droid (an alternative app store focused on privacy and open-source apps) will accept the app, because F-Droid rejects the extra data block that contains that library list. This is a packaging/policy change, not a fix for a code vulnerability. It slightly reduces information an attacker could gather from the published APK, but it does not by itself make the app safer to use.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access controlauthentication path
AI analysis · Informational 16/100
This commit fixes the mobile wallet's automated build process so it always uses the same Rust compiler version when building a privacy-sensitive networking component (the Tor plugin). Without the fix, the build could silently use whatever the latest 'stable' Rust release is at the time, making releases non-reproducible and potentially introducing unexpected behavior or compiler-related issues. It also copies a pre-installed Rust toolchain into the build container so the build does not fail from a missing rustup. This is a build-hardening and reliability change, not a direct fix for an active security vulnerability in the wallet itself.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access controldocumentation-only discount
AI analysis · Informational 19/100
This commit updates the versions of third-party GitHub Actions used in the project's automated build and release pipelines and locks them to specific, unchangeable commit hashes. It also adds a minor workaround for a Homebrew warning. The change is a routine supply-chain hardening measure; it does not introduce any obvious security vulnerability and likely reduces the risk of a compromised or malicious action update silently affecting future builds.
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 3/100
This commit swaps out precompiled Monero wallet library files across Android, iOS, Linux, and Windows for newer versions. The actual code inside those libraries is not shown, so we cannot tell from this commit alone whether the update fixes a security bug, adds a feature, or is just routine maintenance. The only visible source change is a reordering of iOS framework entries in a packaging metadata file.
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 18/100
This commit improves build reproducibility: it pins exact software versions (Docker images, source-code commits, Android NDK), uses fixed build paths, and removes non-deterministic timestamps. These are defensive hardening changes that make it easier for anyone to independently verify that the published app was built from the claimed source code. There is no direct vulnerability fix here, but the changes reduce supply-chain risk and make future tampering harder to hide.
AI review queuedFix appimagetool hashby Keeqler · d7656876 · Jun 30, 2026 · 1 fileMessage 28 · OpaqueLow 25Details
Commit message · Keeqler
Fix appimagetool hash
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100
This commit updates a SHA256 checksum used to verify the appimagetool download during the wallet's build process. The old hash no longer matched the file being downloaded, which would break builds. The change itself is a routine hash correction, but because the commit only changes the hash and does not show the corresponding appimagetool version or release being updated, it is impossible to confirm from the diff alone whether the new hash matches a legitimate upstream release or a tampered one.
AI review queuedRelease fixby Keeqler · d942e6dd · Jun 30, 2026 · 2 filesMessage 0 · OpaqueInformational 19Details
Commit message · Keeqler
Release fix
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 19/100
This commit makes two small build-pipeline changes: it pins Windows release builds to a specific older Windows Server 2022 runner image instead of the latest one, and it updates the expected checksum and filename for the AppImage build tool downloaded during Linux release builds. There is no direct evidence in the commit that these changes fix a security vulnerability. The most plausible security-relevant effect is supply-chain risk reduction: pinning the Windows runner avoids unexpected changes from future 'windows-latest' updates, and updating the AppImage tool checksum ensures the downloaded build tool matches a known version. However, the commit message gives no security context, so this is speculative.
AI review queuedBump versionby Keeqler · a6417155 · Jun 30, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler
Bump version
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only changes the app's version number from 1.0.10 to 1.0.11 in a configuration file. There are no code changes, no security fixes, and no functional changes visible in this commit.
Add instructions for release signature verification
65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification✓ Names security-relevant behavior explicitly! No meaningful explanatory body
This commit only adds documentation to the README explaining how users can verify that downloaded release files are genuine using GPG signatures. It does not change any code, build process, or signing keys, and it does not fix or introduce any security vulnerability.
AI review queuedUpdate checkout actionby Keeqler · c8838b0d · May 7, 2026 · 3 filesMessage 28 · OpaqueInformational 19Details
Commit message · Keeqler
Update checkout action
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit simply updates the GitHub Actions 'checkout' step from version 4 to version 6 in several workflow files. It is a routine dependency/maintenance change with no visible security fix or vulnerability introduced in the diff itself.
AI review queuedBump build noby Keeqler · 038506f2 · May 7, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Bump build no
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only increases the app's build number from 18 to 19 in a configuration file (pubspec.yaml). There are no code changes, no security fixes, and no behavior changes. It is a routine version bump.
AI review queuedBumpby Keeqler · ad84c608 · May 7, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler
Bump
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only increases the app's version number from 1.0.9+17 to 1.0.10+18 in a configuration file. There are no code changes, no dependency updates, and no security-related content visible in the diff.
AI review queuedAdd fiat api setupby Keeqler · 68571dca · May 7, 2026 · 14 filesMessage 28 · OpaqueLow 27Details
Commit message · Keeqler
Add fiat api setup
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 27/100
This commit adds a new setup screen and settings for choosing how the wallet fetches the Monero-to-fiat exchange rate. Users can now pick Tor-only (the default), clearnet (direct internet), or disabled. The clearnet option fetches the rate directly from Kraken's API without routing through Tor, which the app labels as 'not private.' This is a privacy-relevant change, not a code-execution vulnerability, because it lets users intentionally trade some privacy for reliability. The commit also renames many 'connection' labels to 'LWS' (light-wallet server) to avoid confusion with the new fiat API connection.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only increases the app's build number from 17 to 18 in a configuration file. It contains no code changes, no security fixes, and no functional changes.
AI review queuedAdd monero_c as submoduleby Keeqler · b1c86f5a · Apr 29, 2026 · 2 filesMessage 35 · OpaqueInformational 15Details
Commit message · Keeqler
Add monero_c as submodule
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit simply adds a Git submodule pointing to an external Monero C library. There is no code change, no vulnerability introduced in the diff itself, and no security-relevant content beyond registering a dependency source.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only adds F-Droid store listing files—descriptions, screenshots, and icons. It does not change any wallet code, permissions, network behavior, or security settings. There is no security issue here.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit simply increases the app's build number from 15 to 16 in a configuration file. It makes no code changes and presents no security relevance.