MG
← All projectsMAGIC Grants

Skylight Wallet

Modern open-source self-custody Monero light wallet using Monero LWS.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

299 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

39security candidates178second-pass queue217AI analyses
77commits · 30 days
101commits · 60 days
139commits · 180 days
292commits · 365 days
Backfill bands
Sep 27 → Mar 31160 seen18 candidatesComplete
Mar 31 → Jul 2928 seen4 candidatesComplete
Jul 29 → Aug 2834 seen3 candidatesComplete
Aug 28 → Sep 2748 seen9 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
151Thin · 40–59
138Opaque · 0–39
17security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Keeqler25135185236
Justin Ehrenhofer42428240
Licaon_Kter302034
SamsungGalaxyPlayer202035
jermanuts100045
Analysis record

Published AI watches

Last scanned 48 minutes ago

Low 32 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #178 from MAGICGrants/2.1.0-release-fixes

This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …

New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
320c02ceby Justin Ehrenhofer+383−362427 files
No security note in commit
Informational 3 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update pins

This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…

Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
7125d971by Justin Ehrenhofer+25−252 files
No security note in commit
Informational 0 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'main' into 2.1.0-release-fixes

This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…

50b25b5eby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 18 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Skip fetching unused submodules

This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …

Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
8c5b00d3by Justin Ehrenhofer+9−33 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #179 from MAGICGrants/update-moneroc-libs

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…

3df9967aby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …

2cf30607by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix desktop builds

This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…

e0eaa15fby Justin Ehrenhofer+11−22 files
No security note in commit
Low 34 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #176 from MAGICGrants/desktop-ui

This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …

Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
d6d9d318by Justin Ehrenhofer+3922−151454 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.

993a1147by Justin Ehrenhofer+1−11 file
No security note in commit
Low 46 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Updates for Monero 0.18.5.3

This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…

Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
5f5eea3eby Justin Ehrenhofer+37−296 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #175 from MAGICGrants/update-moneroc-libs

This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…

424f9588by Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…

1e620a30by SamsungGalaxyPlayer+0−07 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Show fiat API failure as a warning triangle by the balance; aligns with Spice

This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…

09609000by Keeqler+64−541 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix mobile screen transitions

This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…

9456bbbdby Keeqler+3−11 file
No security note in commit
Informational 18 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix create password screen showing up on mobile; format

This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…

Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
6483d8a1by Keeqler+163−729 files
No security note in commit
Informational 15 AI analysisMessage 73 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge remote-tracking branch 'origin/send-wallet-core' into brightness-fix

This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.

1f4209d3by Keeqler+77−10512 files
No security note in commit
Informational 23 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #173 from MAGICGrants/review-prompt

This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…

Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
6528c1cbby Keeqler+165−19 files
No security note in commit
Informational 17 AI analysisMessage 68 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'desktop-ui' into brightness-fix

This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…

Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
2932c7e0by Keeqler+3592−143843 files
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.

dcb087efby Keeqler+1−11 file
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Bump build

This commit only increases the app's internal build number from 408 to 409 in a configuration file. No code, dependencies, or security settings were changed. There is no security relevance.

e69ac4eeby Keeqler+1−11 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedImprove decimal handlingby Justin Ehrenhofer · 87f84ae1 · Sep 17, 2026 · 3 filesMessage 28 · OpaqueModerate 64Details
Commit message · Justin Ehrenhofer

Improve decimal handling

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Moderate 64/100

This commit fixes a Monero wallet bug where the amount a user wanted to send could silently change because the app was converting the typed amount into a 'double' (a computer number format with limited precision) before turning it into the exact atomic units the blockchain actually uses. The patch keeps the amount as text the whole way through, so the value the user sees is the value that gets spent. It also fixes a related bug where tapping 'Max' for large balances could produce unusable scientific notation like '5e-7'.

AI review queuedFix: Delete additional itemsby Justin Ehrenhofer · 6a84d569 · Sep 16, 2026 · 2 filesMessage 47 · ThinModerate 57Details
Commit message · Justin Ehrenhofer

Fix: Delete additional items

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 57/100

This commit fixes a bug in the wallet-deletion process. Previously, the app deleted wallet files while a background sync service still had them open in another process. That could leave deleted wallet data partially restored on disk, or cause the app to keep syncing a wallet the user asked to remove. The fix tells the sync service to stop first, then deletes the wallet through the core library's proper teardown path.

AI review queuedUnify lock requests between appsby Justin Ehrenhofer · e00c311e · Sep 12, 2026 · 8 filesMessage 45 · ThinHigh 74Details
Commit message · Justin Ehrenhofer

Unify lock requests between apps

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · High 74/100

This commit fixes two real security gaps in a mobile cryptocurrency wallet. First, when the app was sent to the background and later reopened, it could return to an already-unlocked wallet with the password still in memory, letting anyone with the phone reach the seed phrase. The patch now locks the app on resume. Second, simply viewing the seed/secret keys only showed a warning sheet; now it also requires a fingerprint or face scan first. The commit message frames this as 'unifying lock requests between apps,' but the code comments and changes clearly describe the underlying security problems.

AI review queuedAdd QR restoreby Justin Ehrenhofer · d9690c4e · Sep 12, 2026 · 3 filesMessage 28 · OpaqueLow 25Details
Commit message · Justin Ehrenhofer

Add QR restore

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 25/100

This commit removes a local QR-restore parser and switches the wallet to use a shared parser from another package. It also fixes two unrelated bugs in the send screen: one that could permanently block fee estimates after a single failure, and another that displayed tiny 'Max' balances in scientific notation, breaking sending. There is no obvious security vulnerability in the diff itself; the main concern is whether the new shared parser is as safe as the old one, which cannot be judged from this commit alone.

AI review queuedSupport Face IDby Justin Ehrenhofer · 3af605e7 · Sep 11, 2026 · 7 filesMessage 28 · OpaqueInformational 15Details
Commit message · Justin Ehrenhofer

Support Face ID

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit adds Face ID and Touch ID support to unlock the Skylight Wallet app on iOS. It is a feature addition, not a security fix. There is no evidence in the commit of a vulnerability, bug, or security-relevant change beyond normal biometric authentication integration.

AI review queuedFix keyboard covering settingby Justin Ehrenhofer · 02de68b0 · Sep 11, 2026 · 1 fileMessage 35 · OpaqueInformational 21Details
Commit message · Justin Ehrenhofer

Fix keyboard covering setting

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 21/100

This commit fixes a user-interface bug in the wallet's settings screen. Previously, when the on-screen keyboard appeared, it could cover the bottom of a settings form because the popup sheet was sized using the full screen height. The change subtracts the keyboard area from the available height so the sheet shrinks accordingly, keeping input fields visible and usable. There is no security issue here.

AI review queuedUpdate Skylight stringsby Justin Ehrenhofer · 83affa51 · Sep 11, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · Justin Ehrenhofer

Update Skylight strings

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes user-facing text strings in the Skylight Wallet app. It updates labels, descriptions, and warnings shown to users in English and Portuguese to be clearer and more informative about privacy and security risks. No code logic, security behavior, or functionality was modified.

AI review queuedUpdate monero_c librariesby Keeqler · 59fae2b2 · Sep 11, 2026 · 11 filesMessage 35 · OpaqueInformational 3Details
Commit message · Keeqler

Update monero_c libraries

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 3/100

This commit swaps out precompiled Monero wallet library files for newer versions across Android, iOS, Linux, and Windows. The only human-readable change is updating the iOS framework's bundle identifier from 'com.skylight.MoneroWallet' to 'org.magicgrants.MoneroWallet'. The actual code inside the binary libraries is not shown, so we cannot tell from this commit alone whether the update fixes security bugs, introduces them, or is purely routine maintenance.

AI review queuedDisable desktop buildsby Keeqler · 479b5d9a · Sep 11, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Disable desktop builds

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply turns off automated desktop builds for Linux and Windows in the project's release pipeline. It does not change any wallet code, fix a bug, or introduce a security feature. The Android build remains active, and the release job no longer waits for the disabled desktop jobs.

AI review queuedFix rust toolchain extractionby Keeqler · 0e83d894 · Sep 11, 2026 · 1 fileMessage 35 · OpaqueInformational 18Details
Commit message · Keeqler

Fix rust toolchain extraction

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 18/100

This is a one-line shell script fix that changes how the build script reads the required Rust compiler version from a configuration file. The old method could fail to extract the version correctly in some cases, potentially causing a build to use the wrong Rust toolchain. The new method is simpler and more robust. There is no direct evidence this is a security vulnerability, but build reproducibility and toolchain correctness are security-relevant for software supply-chain integrity.

AI review queuedBump and update pinsby Keeqler · 6fd9bf0b · Sep 10, 2026 · 3 filesMessage 28 · OpaqueInformational 6Details
Commit message · Keeqler

Bump and update pins

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 6/100

This commit simply updates version numbers and switches several software dependencies to newer pinned versions. There is no visible code change in the app itself, and the commit message gives no indication that any security problem is being fixed. Without inspecting the actual contents of the updated dependency versions, we cannot tell whether this update addresses a security issue or is just routine maintenance.

AI review queuedBring improvements from spiceby Keeqler · f1ed0e19 · Sep 10, 2026 · 16 filesMessage 35 · OpaqueInformational 15Details
Commit message · Keeqler

Bring improvements from spice

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine product update that brings user-interface improvements from another wallet project ("spice") into Skylight Wallet. It changes labels and help text, updates the address-book design, adds a language picker to the welcome screen, and refreshes the privacy policy and terms of service. There is no evidence of a security fix or vulnerability being introduced.

AI review queuedDark themeby Keeqler · fe7f552d · Sep 10, 2026 · 2 filesMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler

Dark theme

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is purely a visual redesign of the app's dark theme. It changes color values—making backgrounds darker and switching accent colors to a Monero orange shade—but does not alter any security logic, data handling, or network behavior.

AI review queuedRename verbose loggingby Keeqler · 17ee48d9 · Aug 20, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Rename verbose logging

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only renames the user-facing label for a setting from 'Verbose Logging' to 'Enable Logging to File' (and the Portuguese equivalent). It changes displayed text strings in localization files, not how logging works, what data is logged, or any security behavior. There is no security issue here.

AI review queuedAdopt shared wallet_ui dialogs, logging, and biometric auth from wallet-core; Bug fixesby Keeqler · eb5494df · Aug 19, 2026 · 10 filesMessage 55 · ThinInformational 17Details
Commit message · Keeqler

Adopt shared wallet_ui dialogs, logging, and biometric auth from wallet-core; Bug fixes

55/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit mostly moves existing features—log exporting, delete-wallet dialog, and biometric unlock—into a shared library called wallet-core, and tweaks on-screen keyboard behavior. It is a refactoring and bug-fix patch, not a clear security fix. There is no direct evidence in the commit that it repairs a vulnerability, though centralizing sensitive code like biometric auth and wallet deletion in a shared library can make future security maintenance easier.

AI review queuedConsume wallet core tx detailsby Keeqler · fb2bd03b · Aug 19, 2026 · 10 filesMessage 45 · ThinInformational 12Details
Commit message · Keeqler

Consume wallet core tx details

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit is a routine UI refactor. It removes the app's own transaction-details popup and starts using a shared one from a related 'wallet-core' library. It also adds a couple of new translated labels, such as 'Change' and 'Copied to clipboard'. There is nothing in the diff that looks like a security fix or vulnerability.

AI review queuedAdopt wallet-core packages for fiat, background sync, notifications, and preferencesby Keeqler · e190e085 · Aug 18, 2026 · 15 filesMessage 50 · ThinLow 31Details
Commit message · Keeqler

Adopt wallet-core packages for fiat, background sync, notifications, and preferences

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 31/100

This commit is a large refactoring change that moves several wallet features—fiat exchange rates, background syncing, notifications, and preference storage—out of the Skylight Wallet app and into shared 'wallet-core' packages. The app now imports and configures those packages instead of containing its own implementations. The change itself is architectural: it deletes hundreds of lines of local code and replaces them with thin wrappers and configuration calls. There is no obvious new security bug in the diff, but because the actual logic now lives in external packages that are not shown, the full security effect cannot be judged from this commit alone.

AI review queuedGet rid of legacy WalletModelby Keeqler · 10a9192c · Aug 12, 2026 · 11 filesMessage 45 · ThinInformational 20Details
Commit message · Keeqler

Get rid of legacy WalletModel

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit removes the old 'WalletModel' wallet engine and switches the Skylight Wallet app to use only the newer 'wallet-core' engine. It is a large cleanup/refactoring change: about 2,000 lines of the old engine code are deleted, feature flags are removed, and screens now always talk to the shared wallet-core adapter. There is no direct evidence in the commit of a security vulnerability being fixed; it reads as a completion of a migration that had already been running behind a feature flag.

AI review queuedCorrectly show sync status in continuous sync notificationby Keeqler · 025a6a20 · Aug 12, 2026 · 4 filesMessage 50 · ThinInformational 15Details
Commit message · Keeqler

Correctly show sync status in continuous sync notification

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit fixes a small user-interface timing bug in the Skylight Wallet mobile app. It makes the ongoing background-sync notification show 'Wallet up to date' only when the wallet is actually caught up, instead of briefly showing it too early or staying stuck on 'Syncing…' when the wallet is already synced. There is no security-relevant change here.

AI review queuedFix fiat api warn icon showing up when api disabledby Keeqler · b02ff9e0 · Aug 12, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · Keeqler

Fix fiat api warn icon showing up when api disabled

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit fixes a minor user-interface bug in a cryptocurrency wallet app. When the user had disabled the fiat price API, a red warning icon was incorrectly shown as if the API had failed. The change simply hides that warning icon when the API is intentionally disabled. There is no security issue here.

AI review queuedBg/fg sync and tx notificationsby Keeqler · 689d81c4 · Aug 11, 2026 · 7 filesMessage 45 · ThinInformational 19Details
Commit message · Keeqler

Bg/fg sync and tx notifications

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit is a routine feature patch that wires up background and foreground wallet synchronization and adds incoming transaction notifications across mobile and desktop. It does not appear to fix a security vulnerability; it is part of an ongoing migration to a shared 'wallet-core' backend. The changes mostly move existing logic into helper functions and add notification gating so users are not spammed or re-notified.

AI review queuedFix delayed connection status changeby Keeqler · 373937fd · Aug 10, 2026 · 1 fileMessage 45 · ThinInformational 24Details
Commit message · Keeqler

Fix delayed connection status change

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit changes how the wallet reacts when the user switches between server types (a local node versus a lightweight server). Instead of immediately rebuilding and resyncing the wallet in the foreground, the app now delegates that work to a dedicated method. The stated goal is to fix a delayed or stale connection-status display. The diff itself is a one-line refactor and does not contain any obvious security bug or fix for one.

AI review queuedUpdate release.ymlby Licaon_Kter · 3dded6fa · Aug 7, 2026 · 1 fileMessage 28 · OpaqueInformational 17Details
Commit message · Licaon_Kter

Update release.yml

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 17/100

This commit changes the automated release build script to add `--enforce-lockfile` to a Flutter package command. That flag tells the build tool to use exactly the dependency versions recorded in the project's lock file and not silently upgrade or change packages. It is a supply-chain hardening measure that reduces the chance of an unexpected or malicious package version sneaking into a release build, but it is not a fix for a known active vulnerability.

AI review queuedenforce flutter lockfileby Licaon_Kter · bcdcf738 · Aug 7, 2026 · 1 fileMessage 28 · OpaqueLow 29Details
Commit message · Licaon_Kter

enforce flutter lockfile

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 29/100

This commit changes the F-Droid build script to add the '--enforce-lockfile' flag when Flutter downloads its package dependencies. In plain terms, it tells the build tool: 'only install the exact versions of dependencies recorded in the lockfile, and fail if the lockfile is missing or out of sync.' This is a supply-chain hardening measure. It reduces the risk that a build silently picks up a newer, potentially malicious or buggy version of a dependency, but it is not a fix for a known active vulnerability.

AI review queuedBump build numberby Keeqler · 572b280e · Aug 7, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler

Bump build number

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only increases the app's build number from 403 to 404 in a configuration file. It makes no code changes and has no security relevance.