Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
152Thin · 40–59
139Opaque · 0–39
17security candidates with opaque commit messaging
This commit only updates marketing materials: it refreshes the README wording, adds an F-Droid badge, swaps screenshots and feature graphics, and edits the app store description. No program code, configuration, or dependency files were cha…
This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …
New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…
Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…
This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …
Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…
This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …
This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…
This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …
Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.
This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…
Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…
This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…
This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…
This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…
Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.
This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…
Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…
Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
AI review queuedSet build numberby Keeqler · 0d903495 · Nov 24, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Set build number
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only changes the app's build number in the package configuration file (from version 1.0.1 to 1.0.1+5). It does not modify any code, dependencies, permissions, or security settings. There is no security relevance.
AI review queuedBump versionby Keeqler · 095a5f1e · Nov 21, 2025 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler
Bump version
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only changes the application's version number in a configuration file (from 1.0.0+4 to 1.0.1). There are no code changes, no security fixes, and no functional changes visible in the diff.
AI review queuedPrompt for wallet password on desktopby Keeqler · c6768610 · Nov 13, 2025 · 13 filesMessage 45 · ThinLow 44Details
Commit message · Keeqler
Prompt for wallet password on desktop
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Low 44/100
This commit adds a password prompt for the Skylight Wallet app when running on desktop computers (Linux, Windows, macOS). Previously, the app only used the phone's biometric/PIN lock, which isn't reliably available on desktop. The change makes desktop users create and enter a wallet password to protect their funds. It is a security improvement, not a vulnerability fix, though the password is held in memory while the app runs and is not persisted on desktop.
Security candidateFix some screens too wide on desktopby Keeqler · d033aa20 · Nov 11, 2025 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · Keeqler
Fix some screens too wide on desktop
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 15/100
This commit is a routine user-interface layout fix. It limits how wide three wallet setup screens can stretch on desktop computers by wrapping them in a centered container with a maximum width. There is no security-relevant change.
AI review queuedMake layouts adapt to larger screensby Keeqler · dfb2e047 · Nov 7, 2025 · 16 filesMessage 45 · ThinInformational 18Details
Commit message · Keeqler
Make layouts adapt to larger screens
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100
This commit is a routine UI polish for the Skylight Monero wallet. It makes screens adapt better to large monitors and tablets, adds a desktop copy-address button, fixes a macOS notification bug, and replaces a full-screen transaction details page with a popup dialog. There is no clear security vulnerability in the changes, but one small behavior change is worth noting: the old receive screen copied the address silently when tapped, while the new code shows a confirmation message. Most of the diff is reformatting and layout work.
AI review queuedMake features work on Linuxby Keeqler · 800d4f87 · Nov 5, 2025 · 16 filesMessage 45 · ThinLow 31Details
Commit message · Keeqler
Make features work on Linux
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 31/100
This commit adds Linux support to a Monero wallet app. Most changes are ordinary cross-platform plumbing, but two items deserve a closer look: a new helper script edits a binary shared library to clear an 'executable stack' flag, and the app now stores wallet files, Tor data, and logs in the user's home directory under a hidden folder on Linux. The commit itself does not describe these as security fixes, and there is no external advisory or researcher attribution supplied.
AI review queuedBump build numberby Keeqler · 2f07a7f1 · Oct 31, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Bump build number
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only increases the app's build number from 3 to 4 in a configuration file. It makes no code changes and has no security relevance.
AI review queuedPotential fix for possible crash when wallet is deletedby Keeqler · 151f6625 · Oct 31, 2025 · 1 fileMessage 50 · ThinInformational 23Details
Commit message · Keeqler
Potential fix for possible crash when wallet is deleted
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Informational 23/100
This is a one-line defensive fix in a Dart wallet app. It prevents the app from notifying UI listeners about a connection change if the underlying wallet object has already been deleted. The change likely avoids a crash or inconsistent UI state when a wallet is removed, but it is not a security vulnerability that an attacker can directly exploit.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · Low 36/100
This commit adds a safety check to a cryptocurrency wallet so that, when the server can no longer create new subaddresses, the app warns the user and falls back to reusing an already-used subaddress instead of silently failing or leaking privacy. It is a defensive/privacy-hardening change, not an obvious vulnerability fix, but it addresses a real privacy edge case: address reuse weakens transaction privacy.
Security candidateMinor refactoring and subaddress check result cachingby Keeqler · 791f0f67 · Oct 30, 2025 · 8 filesMessage 50 · ThinInformational 14Details
Commit message · Keeqler
Minor refactoring and subaddress check result caching
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolseed or entropy pathsigning or wallet path
AI analysis · Informational 14/100
This commit is a routine cleanup of a Monero wallet app. It mainly moves repeated startup steps into a single helper function, caches whether the server supports subaddresses in local app storage, and improves loading indicators on the connection setup screen. There is no obvious security bug introduced, but the change is not purely cosmetic because it alters when and how the app checks server capabilities and stores that result.
AI review queuedBump build numberby Keeqler · 75dd1c91 · Oct 29, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Bump build number
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only increases the app's build number from 2 to 3 in a configuration file. There are no code changes, no security fixes, and no functional changes of any kind.
Security candidateAdd subaddress support checkby Keeqler · 03c9f0c5 · Oct 29, 2025 · 11 filesMessage 35 · OpaqueLow 37Details
Commit message · Keeqler
Add subaddress support check
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · Low 37/100
This commit adds a feature that checks whether the user's chosen Monero light-wallet server supports subaddresses. Before this change, the app could show a subaddress even when the server did not support it, which could cause incoming transactions to be missed. The change also removes a stored user preference that always defaulted to showing the primary address, and instead auto-detects server capability and defaults to showing a subaddress when supported. The most notable security-relevant side effect is that the app now sends the wallet's secret view key to the light-wallet server during the check, and it does so over plain HTTP unless the user has enabled SSL/Tor. That is a privacy-sensitive design choice, but it is consistent with how Monero light wallets already operate.
AI review queuedAdd READMEby Keeqler · a7101ae7 · Oct 24, 2025 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler
Add README
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
This commit only adds and updates the project's README file. It introduces no code changes, no configuration changes, and no functional modifications to the wallet application. There is no security relevance in the diff itself.
AI review queuedAdd loading spinner in seed screenby Keeqler · d7bb5eca · Oct 24, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Keeqler
Add loading spinner in seed screen
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit adds a visual loading spinner to the wallet restore screen and prevents the restore button from triggering multiple restore attempts at once. It is a user-experience improvement, not a security fix.
AI review queuedBump build numberby Keeqler · 35ab4051 · Oct 23, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Bump build number
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only changes the app's build number from 1 to 2 in a configuration file. It does not modify any code, fix any behavior, or affect security in any way.
AI review queuedAdd tx priority selectby Keeqler · a439703d · Oct 23, 2025 · 7 filesMessage 28 · OpaqueInformational 20Details
Commit message · Keeqler
Add tx priority select
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 20/100
This commit adds a transaction fee priority selector to a Monero wallet app. It lets users choose Low, Normal, or High transaction priority and shows estimated fees. The change also moves OpenAlias address resolution onto a background thread. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a user-facing feature improvement.
AI review queuedAdd missing currency symbolsby Keeqler · 9f121c39 · Oct 22, 2025 · 2 filesMessage 35 · OpaqueInformational 15Details
Commit message · Keeqler
Add missing currency symbols
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit simply adds correct currency symbols (like £ for British pounds or ¥ for Japanese yen) to the wallet's display. It is a user-interface improvement with no security relevance.
AI review queuedFix not connecting after restoreby Keeqler · c32dfc54 · Oct 22, 2025 · 1 fileMessage 45 · ThinInformational 21Details
Commit message · Keeqler
Fix not connecting after restore
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100
This commit fixes a bug where restoring a wallet from a recovery phrase left the wallet in a disconnected state. After the fix, the app automatically refreshes the wallet, loads account statistics, and connects to the network daemon once the restore completes. There is no indication this was a security vulnerability; it appears to be a functional bug fix for wallet connectivity.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundaryauthentication path
AI analysis · Informational 15/100
This commit is a routine build configuration change. It sets up proper Android release signing (so the app can be published on app stores) and updates the app's package name and copyright strings across Android, iOS, macOS, and Windows from placeholder/example values to the real project identity (MAGIC Grants / Skylight Wallet). There is no security vulnerability here.
AI review queuedMinor changesby Keeqler · df381bf7 · Oct 21, 2025 · 2 filesMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler
Minor changes
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit makes two tiny cleanups: it removes two harmless warning log messages that were printed when a background timer ran before a wallet was opened, and it removes the 'const' keyword from one UI padding value. There is no security issue here.
AI review queuedDemo modeby Keeqler · 93fedb26 · Oct 21, 2025 · 1 fileMessage 0 · OpaqueLow 27Details
Commit message · Keeqler
Demo mode
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 27/100
This commit adds a 'demo mode' to the wallet app. When the app is built with a special environment flag and the user types 'demo' as the server address, the app skips the real network connection test and pretends it succeeded. This is a development/testing convenience, but it could let someone bypass the actual connection check if they can trigger or build the app in demo mode.
AI review queuedFix minor memory leak after wallet is deletedby Keeqler · 3cae1bff · Oct 17, 2025 · 1 fileMessage 45 · ThinInformational 23Details
Commit message · Keeqler
Fix minor memory leak after wallet is deleted
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100
This commit fixes a minor memory leak that could occur after a wallet is deleted in the Skylight Wallet app. It adds safety checks so background timer tasks stop trying to work with a wallet that no longer exists, and it prevents an error in one stats-loading task from crashing the whole refresh process. The changes are defensive and improve stability, but they do not appear to be a security fix for an actively exploitable vulnerability.
AI review queuedWipe address book and pending outgoing txs list when wallet is deletedby Keeqler · a3f079fb · Oct 17, 2025 · 1 fileMessage 50 · ThinLow 46Details
Commit message · Keeqler
Wipe address book and pending outgoing txs list when wallet is deleted
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 46/100
This commit fixes a cleanup bug: when a user deletes their wallet, the app now also removes the saved address book (contacts) and any pending outgoing transactions from phone storage. Before this fix, those details could remain on the device after the wallet was supposedly deleted, which is a privacy and data-retention issue rather than a direct money-stealing bug.
AI review queuedAddress bookby Keeqler · 4d111ea4 · Oct 17, 2025 · 13 filesMessage 18 · OpaqueInformational 20Details
Commit message · Keeqler
Address book
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 20/100
This commit adds a new address-book feature to the Skylight Wallet app. Users can now save named contacts with Monero addresses, pick them when sending funds, and see the contact name on the confirmation screen. The data is stored on the device using the same shared-preferences mechanism already used for other app settings. There is no indication in the commit that this is a security fix or that it addresses any reported vulnerability.
AI review queuedBetter restore seed validationby Keeqler · 6662ab49 · Oct 16, 2025 · 5 filesMessage 35 · OpaqueLow 31Details
Commit message · Keeqler
Better restore seed validation
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 31/100
This commit improves how a cryptocurrency wallet app validates recovery seeds when a user restores a wallet. It adds checks for empty input fields, distinguishes clearly between an invalid seed and other unexpected errors, and logs more details when something goes wrong. The changes are defensive: they make the restore process more reliable and give users clearer error messages, but they do not by themselves create a security vulnerability.