Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
152Thin · 40–59
139Opaque · 0–39
17security candidates with opaque commit messaging
This commit only updates marketing materials: it refreshes the README wording, adds an F-Droid badge, swaps screenshots and feature graphics, and edits the app store description. No program code, configuration, or dependency files were cha…
This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …
New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…
Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…
This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …
Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…
This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …
This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…
This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …
Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.
This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…
Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…
This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…
This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…
This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…
Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.
This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…
Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…
Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
AI review queuedBump versionby Keeqler · 8040f577 · Jan 23, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler
Bump version
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only changes the application's version number in a configuration file, from 1.0.5+10 to 1.0.6+11. There are no code changes, no security fixes, and no functional changes visible in the diff.
AI review queuedTrim seed input in restore wallet screenby Keeqler · 922dc979 · Jan 23, 2026 · 1 fileMessage 45 · ThinInformational 19Details
Commit message · Keeqler
Trim seed input in restore wallet screen
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit fixes a minor user-experience bug in the wallet restore screen. Previously, if a user accidentally typed or pasted their secret recovery phrase with leading or trailing spaces, the app would treat it as invalid and fail to restore the wallet. The change simply removes those extra spaces before checking the phrase. It is not a security vulnerability and does not expose funds or data.
AI review queuedRemove unused code for keep-alive socks requests and fix socks requests timing outby Keeqler · bfcdb82c · Jan 23, 2026 · 2 filesMessage 50 · ThinLow 32Details
Commit message · Keeqler
Remove unused code for keep-alive socks requests and fix socks requests timing out
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Low 32/100
This commit removes a reused SOCKS connection pool and forces every network request to use a fresh connection that closes immediately after use. It also extends a connection test timeout from 10 to 20 seconds and cleans up unused proxy-port variables. The stated goal is to fix SOCKS requests that were timing out. There is no direct evidence in the commit of a security vulnerability being patched, but the change does remove a class of risks that connection pools can introduce, such as accidentally sending sensitive request data on a connection previously authenticated under different wallet state.
AI review queuedImprove readmeby Justin Ehrenhofer · 18fe1789 · Jan 23, 2026 · 3 filesMessage 18 · OpaqueInformational 15Details
Commit message · Justin Ehrenhofer
Improve readme
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only updates the project's README and adds two image assets: a feature graphic and a Google Play badge. There are no code changes, no configuration changes, and no security-relevant modifications.
AI review queuedFix package versionby Keeqler · 12aa36f1 · Jan 23, 2026 · 4 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Fix package version
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a routine packaging and metadata update. It fixes how version numbers are handled in build scripts (allowing with or without a 'v' prefix), updates the application's version number from 1.0.4 to 1.0.5, and tweaks the package description and maintainer fields. There is no security-relevant change.
AI review queuedAdd .deb buildsby Keeqler · 4a5e1e35 · Jan 23, 2026 · 6 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Add .deb builds
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit adds the ability to build and release Debian (.deb) packages for the Skylight Wallet Linux app. It also removes an unused import in one Dart source file. There is no security-relevant change: no bug fixes, no vulnerability patches, no permission changes to existing files, and no new risky behavior.
AI review queuedRemove debug code and bump buid numberby Keeqler · d1b02daa · Jan 21, 2026 · 2 filesMessage 45 · ThinInformational 17Details
Commit message · Keeqler
Remove debug code and bump buid number
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100
This commit removes a single line of leftover debug code that was causing a fake incoming-transaction notification to appear every time the wallet home screen loaded. It also bumps the app's build number. There is no obvious security vulnerability in the removed code, but shipping debug notifications in a production build is a quality and trust issue.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
credential or privilege state
AI analysis · Informational 13/100
This commit removes a Docker command-line flag that made the build container run as the current host user instead of the container's default user. The stated goal is to fix build permission problems. In itself, the change does not add a known vulnerability, but it means the build will now run as whatever user is configured inside the builder image. If that image runs as root, files created in the mounted workspace could end up owned by root, and any build-time scripts or tools will execute with the container user's privileges. There is no direct evidence in the commit that this is a security fix or that it introduces an exploitable flaw.
AI review queuedRelease workflow fixby Keeqler · c37ea94b · Jan 20, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Release workflow fix
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit changes the release workflow to run build commands in a non-login shell instead of a login shell. There is no security issue here. The change likely fixes a build problem caused by the login shell loading environment files or running scripts that interfered with the build container setup.
AI review queuedUpdate versionby Keeqler · 4f32bdb3 · Jan 20, 2026 · 3 filesMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler
Update version
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only updates version numbers: the app version (1.0.3+7 to 1.0.4+8), the Flutter SDK used in the Docker builder (3.38.5 to 3.38.7), and the Dart SDK constraint (3.10.4 to 3.10.7). There are no code changes, no bug fixes, and no security-related changes visible in the diff.
AI review queuedUpdate monero_c librariesby Keeqler · f454127f · Jan 17, 2026 · 10 filesMessage 35 · OpaqueInformational 3Details
Commit message · Keeqler
Update monero_c libraries
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 3/100
This commit swaps out pre-built Monero wallet library files for newer versions across Android, iOS, and Linux. The actual code inside those libraries is binary and not shown, so we cannot tell from this commit alone whether the update fixes a security bug, adds a feature, or is routine maintenance. The only readable change is an iOS framework metadata tweak that removes a background-fetch mode and sets a minimum iOS version of 15.0.
AI review queuedFix monero_c ios buildby Keeqler · 71d5ce40 · Jan 16, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Fix monero_c ios build
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit is a routine fix to the project's automated build pipeline for iOS. It restructures how iPhone and iPhone Simulator libraries are built and packaged into an Apple XCFramework, but it does not change any wallet code, cryptography, or user-facing behavior. There is no indication of a security issue.
AI review queuedRemove debug codeby Keeqler · f60da793 · Jan 15, 2026 · 1 fileMessage 28 · OpaqueInformational 22Details
Commit message · Keeqler
Remove debug code
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 22/100
This commit removes leftover debugging code from a background task that checks for new wallet transactions. It deletes a console log message and, more importantly, removes a temporary '+1' fudge added to the transaction count. That fudge could have caused the app to think there was one more transaction than actually existed, which might trigger unnecessary notifications or confusion, but it does not appear to let an attacker steal funds or take control.
AI review queuedAdd monero_c build for real ios, more fixes and adjustmentsby Keeqler · 1d5b4ad3 · Jan 15, 2026 · 13 filesMessage 50 · ThinInformational 18Details
Commit message · Keeqler
Add monero_c build for real ios, more fixes and adjustments
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100
This commit is mostly a routine iOS build-system update for a Monero wallet app. It swaps a single-architecture iOS framework for a universal 'xcframework' that supports both real iPhones and the simulator, and makes a few small platform-specific cleanups in the Dart code. There is no clear security bug being fixed here; it looks like normal development work to get the iOS app building and running correctly.
AI review queuedwipby Keeqler · ab5b771e · Jan 8, 2026 · 32 filesMessage 0 · OpaqueInformational 24Details
Commit message · Keeqler
wip
0/100 · OpaqueMessage clarity
! Generic or placeholder subject! Too few words to establish purpose! No meaningful explanatory body! Contains work-in-progress language
This is a large work-in-progress commit for a Monero wallet app. It mainly adds iOS support (CocoaPods setup, a bundled MoneroWallet framework, notification and logging export features) and hardens error handling in the Tor/SOCKS networking code. There is no clear security fix or vulnerability being patched. A few debug leftovers, such as a hardcoded '+1' in transaction counting and a test notification fired on every wallet home screen load, look like unfinished development code rather than intentional malicious changes. The bundled binary framework cannot be inspected from the diff, so its provenance and safety are unknown.
AI review queuedPrevent artifacts from being committed in monero_c build workflowby Keeqler · e39b1f29 · Dec 30, 2025 · 5 filesMessage 50 · ThinInformational 19Details
Commit message · Keeqler
Prevent artifacts from being committed in monero_c build workflow
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This change stops a GitHub Actions workflow from accidentally including pre-built binary files (called 'artifacts') when it creates automated pull requests. Those binaries were being deleted from the repository and the workflow now removes them before opening a PR. This is a repository hygiene and supply-chain safety fix, not a direct vulnerability in running software.
AI review queuedUpdate monero_c librariesby Keeqler · 8088c83e · Dec 30, 2025 · 9 filesMessage 35 · OpaqueInformational 0Details
Commit message · Keeqler
Update monero_c libraries
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 0/100
This commit updates pre-built Monero library files (binary .so files) and points a dependency to a newer version of the upstream monero_c code. The actual source code changes are not visible because the files are compiled binaries. There is no information in the commit message or supplied references saying this update fixes a security problem, introduces a vulnerability, or changes any behavior at all. On its own, this looks like a routine dependency refresh.
AI review queuedFix history auto refresh when pending tx is present and minor ui fixesby Keeqler · b36f4857 · Dec 30, 2025 · 3 filesMessage 50 · ThinInformational 21Details
Commit message · Keeqler
Fix history auto refresh when pending tx is present and minor ui fixes
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100
This commit fixes a bug where the transaction history auto-refresh would break when a transaction was still pending (not yet mined). It also makes small user-interface tweaks, such as making list items easier to tap and widening text boxes in transaction details. There is no clear security vulnerability being patched.
AI review queuedAdd reviewersby Keeqler · e4e06c46 · Dec 30, 2025 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler
Add reviewers
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
This commit simply adds two GitHub usernames to a workflow so they are automatically asked to review future pull requests. It does not change any application code, build logic, secrets, permissions, or security settings.
AI review queuedFix pathby Keeqler · e328b74a · Dec 30, 2025 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler
Fix path
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
This commit corrects a simple typo in a GitHub Actions workflow file. The workflow was supposed to trigger when the file itself changed, but the path had an extra '.yml' extension ('build-builder-image.yml.yml' instead of 'build-builder-image.yml'). This is a routine configuration fix with no security implications.
AI review queuedAdd monero_c build workflowby Keeqler · f717dd42 · Dec 30, 2025 · 5 filesMessage 35 · OpaqueInformational 17Details
Commit message · Keeqler
Add monero_c build workflow
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100
This commit adds automated GitHub Actions workflows to build a Monero wallet library from an external source and create pull requests with the compiled binaries. It also renames a Dockerfile and moves an existing script that removes an executable-stack flag from a Linux library. The changes are mostly build-infrastructure housekeeping. There is no direct evidence of a security vulnerability being introduced, but the workflow does clone and build code from a third-party repository (vtnerd/monero_c) without pinned commit verification at build time, and it later edits pubspec.lock using a remote branch's current commit hash. That creates a supply-chain risk if the upstream repository is compromised, but it is not a confirmed incident.
AI review queuedAdd use orbot/invizible checkbox to tor settings screenby Keeqler · bb2e15b8 · Dec 30, 2025 · 10 filesMessage 50 · ThinInformational 19Details
Commit message · Keeqler
Add use orbot/invizible checkbox to tor settings screen
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit adds a user-facing checkbox that lets mobile users choose to route the app's Tor traffic through the separate Orbot/InviZible app instead of a manually entered proxy port. It also changes the default external Tor port from 9150 to 9050 and makes a hardcoded error message translatable. There is no obvious security vulnerability in the diff; it is a feature/configuration improvement.
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 34/100
This commit adds user-configurable Tor settings to the Skylight Wallet app. Users can now choose between built-in Tor, an external Tor proxy, or disabling Tor entirely. It also updates how the app fetches exchange rates and blockchain heights so they respect the new Tor setting. There is no clear security bug in the patch itself, but it introduces a 'Tor disabled' mode and changes how network traffic is routed, which could affect user privacy if the settings are mishandled or bypassed.
AI review queuedFix builder workflow againby Keeqler · 627f1d92 · Dec 16, 2025 · 1 fileMessage 35 · OpaqueInformational 18Details
Commit message · Keeqler
Fix builder workflow again
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
This is a small GitHub Actions workflow fix. It corrects a path trigger so the workflow runs when the workflow file itself changes, and adds a missing 'attestations: write' permission needed for newer GitHub artifact attestation features. There is no direct security vulnerability in the diff; it is a maintenance/configuration correction.
AI review queuedFix builder workflowby Keeqler · 3f336ba6 · Dec 16, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Fix builder workflow
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit adds a new GitHub Actions workflow file that automatically builds and publishes a Docker builder image when the main branch changes. It is a routine CI/CD configuration change with no apparent security defect.