SW
← All projectsSparrow

Sparrow Wallet

Desktop Bitcoin wallet focused on security, privacy, multisignature, and hardware signers.

BitcoinHardware integrationSoftware walletsNormal
Repository coverage

411 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

71security candidates271second-pass queue399AI analyses
84commits · 30 days
152commits · 60 days
250commits · 180 days
405commits · 365 days
Backfill bands
Aug 5 → Feb 6100 seen9 candidatesComplete
Feb 6 → Jun 6128 seen15 candidatesComplete
Jun 6 → Jul 67 seen1 candidatesComplete
Jul 6 → Aug 546 seen8 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

48/100 average clarity
0Strong · 80–100
35Adequate · 60–79
325Thin · 40–59
51Opaque · 0–39
2security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Craig Raw39767385648
doblon8313048
nzb-tuxxx212060
Michele Balistreri212048
nroktib111050
Liz Lightning202045
PeterXMR101045
Ian McKenzie101050
ottosch101050
craigraw101060
Analysis record

Published AI watches

Last scanned 21 minutes ago

Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove the surplus signatures progress bar segments a finalized multisig transaction discards

This commit fixes a UI display bug in Sparrow Wallet's signature progress bar. When a multi-signature Bitcoin transaction becomes finalized, extra signatures beyond the required threshold are discarded. Previously, the progress bar did not…

UI state desynchronization after multisig finalizationProgress bar segment count mismatch with actual signature setNo change to cryptographic or transaction validation code
40f77206by Craig Raw+9−12 files
No security note in commit
Informational 15 AI analysisMessage 38 · Opaque
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

bump to v2.5.6

This commit is a routine version bump from 2.5.5 to 2.5.6. It only changes version strings in four files (build configuration, documentation, macOS app metadata, and a Java source constant). There are no code logic changes, no bug fixes, a…

f7f36d00by Craig Raw+4−44 files
No security note in commit
Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

use a framerate-capped interpolated timeline for the server toggle and wallet tab loading pulse animations, and stop any running server toggle pulse before starting a new one

This commit tweaks two visual animations in the Sparrow Wallet desktop app: the server connection toggle pulse and the wallet loading pulse. It caps how often the screen is redrawn during the pulse and makes sure any already-running pulse …

Resource-consumption / performance hardening: capped animation framerate reduces CPU/GPU load from continuous 60 Hz redraws.State-management hardening: stopping an existing pulse before starting a new one prevents accumulation of running Timelines.No direct security flaw is present in the diff; signals are defensive-hardening in nature.
4da29f4eby Craig Raw+7−132 files
No security note in commit
Low 45 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cut pasted amounts to the unit precision in the send tab and send to many, and stop the csv import skipping fractional sats and exponent amounts

This commit fixes how Sparrow Wallet handles pasted or imported Bitcoin amounts. Previously, very small or oddly formatted amounts (like scientific notation '1e-8' or fractional satoshis) could be misread or silently skipped during CSV imp…

Amount parsing inconsistency between UI paste and CSV importSilent swallowing of NumberFormatException could skip payment rowsUse of Double.parseDouble for monetary amounts
9e999d3fby Craig Raw+39−362 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add a system theme option that follows the os light or dark setting, and make it the default for new installs

This commit adds a new 'System' theme option to the Sparrow Wallet desktop app that automatically follows the operating system's light or dark mode setting, and makes it the default for new installations. It also updates various UI compone…

a573f22aby Craig Raw+90−3215 files
No security note in commit
Low 36 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

refuse bitbox02 keystore import and discovery for legacy p2sh and p2pkh wallets it cannot sign for, and hide those script types from the device import menus

This commit tightens how Sparrow Wallet handles BitBox02 hardware wallets when working with older Bitcoin address formats (legacy P2PKH and P2SH). Previously, the app could let a user import or discover a wallet that the BitBox02 cannot ac…

Prevents user from configuring a signing device for wallet types the device cannot sign forCould avoid funds becoming unspendable or requiring complex recovery if a user unknowingly imported an unsupported legacy script typeReplaces hard-coded device-specific logic with a generic capability model, reducing future similar issues
de169b18by Craig Raw+23−73 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

reject unknown command line options and values given to flags with an error and exit code instead of starting on the default network, and accept the --option=value form

This commit tightens how Sparrow Wallet handles command-line arguments. Previously, typos or unexpected values could silently be ignored, causing the wallet to start on the default Bitcoin network instead of the one the user intended. Now,…

Command-line argument parsing now rejects unknown options instead of silently ignoring themBoolean flags now reject `--flag=value` forms that would otherwise silently pass the value through as a file/URI argumentProgram now exits with non-zero status on argument errors, reducing risk of unintended default-network startup
46197586by Craig Raw+26−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ignore amount digits beyond the selected unit precision in the send tab amount and fee fields and the send to many grid, instead of truncating them in the payment

This commit fixes a UI bug in the Sparrow Bitcoin wallet where typing or pasting too many decimal digits into amount or fee fields could be silently truncated, potentially causing a user to send a different amount than they saw on screen. …

Precision-loss / truncation bug in financial input fieldsUser-facing amount/fee mismatch between displayed value and parsed valueInput validation now tied to unit-specific precision (satoshis indivisible)
6cde97adby Craig Raw+48−315 files
No security note in commit
Low 41 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

derive public keys from the seed when importing a sparrow wallet file

This commit changes how Sparrow Wallet restores its own wallet files. Previously, when importing a Sparrow wallet file, the public keys (used to find transactions and addresses) might not be correctly rebuilt from the seed phrase. The fix …

Correctness fix for key material restoration during wallet importAdds test coverage for encrypted and unencrypted seed-based wallet importAdds test coverage for watch-only wallet import
1fb4e8bbby Craig Raw+149−23 files
No security note in commit
Informational 21 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add file import of the xpub descriptor jade writes to usb storage

This commit adds the ability to import a Bitcoin wallet's extended public key (xpub) into Sparrow Wallet from a file written by a Blockstream Jade hardware wallet via USB storage. Previously, Jade only supported QR-code import. The change …

New file import path parses external descriptor data and converts it to a keystoreScript type mismatch is explicitly rejected with an IllegalArgumentExceptionSilent payments policy (SINGLE_SP) is explicitly rejected
c4b53879by Craig Raw+74−44 files
No security note in commit
Low 34 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

include the non-witness utxo in psbts for krux keystores, and in the qr display when the psbt has more than one input

This commit changes how Sparrow Wallet builds QR codes for partially-signed Bitcoin transactions (PSBTs). For certain hardware wallets (Krux), it now includes extra data (the full previous transaction, called 'non-witness utxo') in the QR …

Hardware wallet signing correctness: missing non-witness UTXO data can cause some signers to reject or mis-handle multi-input segwit PSBTsQR payload size increase: larger QR codes may be harder to scan reliably, potentially affecting usabilitySubproject update (drongo) likely contains related serialization logic changes
0e2c402fby Craig Raw+4−32 files
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

clear a scanned wallet when a file, text payload or unrecognised qr is imported in the same pane

This commit fixes a UI state bug in Sparrow Wallet's import pane. Previously, when a user scanned or imported a wallet and then imported a non-wallet file, text payload, or unrecognized QR code in the same pane, the previously loaded walle…

Stale UI state could mislead users about which wallet is loadedCross-import state retention in single import paneUser interface consistency fix with security-relevant consequences
d7ded1e7by Craig Raw+4−21 file
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

lock the cormorant store against client connection reads and serve history as a copy, and close the client socket however its handler exits

This commit fixes two reliability issues in Sparrow Wallet's built-in Electrum server (Cormorant). First, it makes sure the internal transaction store is locked while being read or updated, and returns a fresh copy of a wallet's history so…

Concurrency: shared mutable store accessed by client handler and polling threads now synchronizedData consistency: history returned as a defensive copy to avoid iterator seeing concurrent modificationsResource leak: client socket now closed in finally block regardless of exception path
6cc4d50aby Craig Raw+57−94 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

ensure cormorant responses and notifications are always serialized per client connection

This commit fixes a race condition in Sparrow Wallet's built-in Electrum server (Cormorant). Previously, a response to a wallet client and an asynchronous notification (like a new block or a balance update) could be written to the same net…

Race condition on shared socket output streamConcurrent writes from RPC response path and event-bus notification pathPotential interleaving/framing of JSON-RPC messages on same TCP connection
6d9d3014by Craig Raw+146−303 files
No security note in commit
Low 27 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

wake a silent payments history waiter when a failed widening restores a completed scan, rather than leaving it parked for the session

This commit fixes a bug in Sparrow Wallet's silent-payments scanning cache. If a background scan had already finished, then a later 'widening' request to extend the scan failed and rolled back, any history request that arrived during the f…

Concurrency / condition-variable waiter starvationSilent-payments history lookup hang / wallet UI unresponsivenessFailure-recovery path missing signal on rollback
7868a94dby Craig Raw+100−122 files
No security note in commit
Informational 18 AI analysisMessage 60 · Adequate
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

guard a short server.version response in the desktop and terminal connection tests

This commit fixes a minor crash bug in Sparrow Wallet's connection-test screens. Previously, if a Bitcoin Electrum server answered the version request with an unusually short response, the wallet would try to read list items that didn't ex…

Input validation hardening for external server responseIndexOutOfBoundsException prevented in UI feedback pathNo cryptographic, authentication, or transaction logic touched
66348fafby Craig Raw+4−42 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

omit a paynym contact whose payment code does not parse rather than keeping it with a null code or failing the whole paynym response

This commit fixes a bug in Sparrow Wallet's PayNym (BIP47 reusable payment code) contact handling. Previously, if a single contact in your PayNym following/followers list had a malformed payment code, the app either kept a broken contact w…

Null payment code previously stored in contact objectPotential NullPointerException or downstream dereference of null PaymentCode in contact lists/searchWhole PayNym response could fail on one malformed contact
94ebb849by Craig Raw+43−114 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip the exchange currencies request in offline mode in the desktop and terminal general settings

This change stops Sparrow Wallet from trying to fetch live fiat-currency exchange rates when the user has explicitly chosen 'offline mode'. Instead of making a network request that is doomed to fail, it now reuses the currency already save…

Avoids unnecessary network egress in offline modeReduces error/warning noise for expected offline behavior
b91f7993by Craig Raw+15−12 files
No security note in commit
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip addresses already given out under a label and widen the gap limit on an explicit advance in the terminal receive dialog

This commit fixes two related Bitcoin wallet behaviors in Sparrow. First, when you ask for a new receive address, the wallet now skips any address that already has a label, because a label means that address was already given to someone. P…

Address reuse prevention: labeled-but-empty addresses are now skipped consistently across desktop and terminal receive flowsGap-limit widening on explicit advance reduces risk of missing funds during wallet recovery/rescanLogic centralized in WalletForm to reduce UI-specific divergence
cae870ceby Craig Raw+85−164 files
No security note in commit
Low 44 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

cap bbqr display and pdf encodings at the 1295 parts the header can number, using larger parts for data that needs more rather than emitting a sequence that cannot be reassembled

This commit fixes a bug in Sparrow Wallet's BBQ QR code format. Previously, if a large transaction or data blob needed more than 1,295 QR-code-sized pieces, the app would generate pieces with impossible sequence numbers that could not be r…

Integer/sequence-number overflow-like limit violation in a data-encoding protocolPotential denial-of-service or data-integrity failure when exporting large transactions via QRRound-trip unit test added to prevent regression
4b5326d8by Craig Raw+27−12 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefix handling of non-standard key derivations when writing output descriptorsby Craig Raw · ab99f1d3 · Jan 15, 2026 · 2 filesMessage 50 · ThinLow 32Details
Commit message · Craig Raw

fix handling of non-standard key derivations when writing output descriptors

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 32/100

This commit fixes how Sparrow Wallet writes output descriptors when a wallet uses a non-standard key derivation path. Previously, the code stripped the leading 'm/' from the derivation path in a simplistic way, which could produce incorrect descriptors for unusual paths. The fix now uses a dedicated parser/formatter (KeyDerivation.parsePath/writePath) to handle the path correctly. This is primarily a correctness/reliability fix, but incorrect descriptors could in theory lead to users backing up or sharing wrong wallet configuration data.

AI review queueduse precise fee rates estimate from mempool.spaceby Craig Raw · 53857389 · Jan 15, 2026 · 1 fileMessage 45 · ThinInformational 21Details
Commit message · Craig Raw

use precise fee rates estimate from mempool.space

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit changes the Bitcoin fee-rate data source used by Sparrow Wallet from mempool.space's standard recommended-fee endpoint to its more precise fee-estimate endpoint. It is a minor data-source change, not a code-level security fix. There is no indication in the commit that this resolves a security vulnerability.

AI review queuedconvert from tilepane to gridpane to resolve mnemonic words layout issueby Craig Raw · 98576d40 · Jan 14, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · Craig Raw

convert from tilepane to gridpane to resolve mnemonic words layout issue

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a purely cosmetic UI change in the Sparrow Wallet desktop app. It swaps the JavaFX layout component used to display BIP39 mnemonic word fields from a TilePane to a GridPane so the 12 or 24 seed words line up in a tidy grid. There is no change to how seed words are generated, stored, validated, or protected, and no security-relevant behavior is introduced or fixed.

AI review queuedadd additional fee rate limit check for high fee transactionsby Craig Raw · 96f7d4bd · Jan 13, 2026 · 1 fileMessage 50 · ThinLow 45Details
Commit message · Craig Raw

add additional fee rate limit check for high fee transactions

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 45/100

This commit adds an extra safety check in Sparrow Wallet that warns users before broadcasting Bitcoin transactions with extremely high fee rates. Previously, the wallet only warned if the fee rate exceeded the top of a long-term fee rate range. Now it also warns if the fee rate is more than 100 times the default fee rate. This helps prevent users from accidentally overpaying transaction fees, which could be caused by user error, wallet misconfiguration, or potentially a malicious or compromised transaction.

Security candidateadd support for keycard via smart card interfaceby Michele Balistreri · 0c679627 · Jan 13, 2026 · 18 filesMessage 45 · ThinLow 25Details
Commit message · Michele Balistreri

add support for keycard via smart card interface

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 25/100

This commit adds a brand-new feature to Sparrow Wallet: support for Keycard hardware wallets via a smart card interface. It introduces many new Java files that handle low-level smart card communication, secure channel encryption, PIN handling, key derivation, and signing. The change is a large feature addition (+3,250 lines) rather than a small bug fix. There is no direct evidence in the commit message or diff that this fixes a known security vulnerability, and no external references were provided. Some implementation details—such as hardcoded pairing passwords, a TODO comment about device certificate verification, and a fallback to a default derivation path—could become security concerns if misused, but they are not proven vulnerabilities on their own.

AI review queuedadd user agent to coingecko exchange source requestby Craig Raw · 0515d805 · Jan 13, 2026 · 1 fileMessage 50 · ThinInformational 19Details
Commit message · Craig Raw

add user agent to coingecko exchange source request

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit changes how Sparrow Wallet asks CoinGecko for currency exchange rates. It now sends a fake web-browser 'User-Agent' header instead of none. This is likely a workaround because CoinGecko started blocking or rate-limiting requests that had no user agent. It is not a fix for a vulnerability in Sparrow itself, but it does make Sparrow's exchange-rate requests slightly more identifiable and could affect privacy if the same user agent is reused elsewhere.

AI review queuedavoid extraneous error logging on card enumerationby Craig Raw · cf15760d · Jan 13, 2026 · 2 filesMessage 50 · ThinInformational 11Details
Commit message · Craig Raw

avoid extraneous error logging on card enumeration

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 11/100

This commit makes two small logging and error-handling changes in code that talks to smart cards (hardware wallets). It downgrades one routine card-enumeration error from 'error' to 'info' level, and turns a swallowed CBOR parsing error into a thrown exception. There is no indication these changes fix a security vulnerability; they appear to be code-quality or diagnostic-noise improvements.

AI review queuedremove unnecessary lark .gitmodulesby Craig Raw · f28f15df · Jan 13, 2026 · 1 fileMessage 35 · OpaqueInformational 12Details
Commit message · Craig Raw

remove unnecessary lark .gitmodules

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 12/100

This commit removes an unnecessary Git submodule configuration entry named 'lark' from the .gitmodules file. It is a minor repository cleanup change with no apparent security relevance.

Security candidateadd any missing key path information to psbts once signing wallet is chosenby Craig Raw · 34900d29 · Jan 3, 2026 · 2 filesMessage 50 · ThinLow 29Details
Commit message · Craig Raw

add any missing key path information to psbts once signing wallet is chosen

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 29/100

This commit changes Sparrow Wallet so that, when a user chooses a wallet to sign a Bitcoin transaction (PSBT), the app automatically fills in any missing key-path details needed for signing. The change is small and appears to be a usability/fix improvement rather than a clear security patch. There is no vendor statement or external reference saying this fixes a vulnerability, so we cannot confidently label it as a security fix.

AI review queuedadd warning when entering outdated slip132 values into a watch-only wallet of a different script typeby Craig Raw · 430f2ee3 · Dec 23, 2025 · 1 fileMessage 50 · ThinLow 30Details
Commit message · Craig Raw

add warning when entering outdated slip132 values into a watch-only wallet of a different script type

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 30/100

This commit adds a warning message in Sparrow Wallet when a user pastes an older-style extended public key (SLIP132 format) into a watch-only wallet that uses a different Bitcoin address type. It does not change wallet logic or fix a vulnerability; it only alerts the user to a possible mismatch so they can correct it. The change is defensive UX, not a security patch.

AI review queuedminor trezor v2 fixesby Craig Raw · 74160ba3 · Dec 20, 2025 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · Craig Raw

minor trezor v2 fixes

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit changes the left and right margins of a text input dialog box from 60 pixels to 65 pixels. It is purely a cosmetic/layout adjustment for the Trezor hardware wallet v2 integration and has no security relevance.

Security candidateimprove thp pairing flow, and add passphrase session supportby Craig Raw · 59d85cdd · Dec 18, 2025 · 2 filesMessage 50 · ThinInformational 18Details
Commit message · Craig Raw

improve thp pairing flow, and add passphrase session support

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 18/100

This commit improves the user interface for pairing a Trezor hardware wallet with Sparrow Wallet. It adds a numeric-only input filter for the pairing code, makes the text larger, and shows the device name in pairing messages. There is no clear security vulnerability in the changes.

AI review queuedadd trezor safe 7 noise config implementationby Craig Raw · 04064219 · Dec 17, 2025 · 2 filesMessage 45 · ThinInformational 20Details
Commit message · Craig Raw

add trezor safe 7 noise config implementation

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit adds support for pairing the Trezor Safe 7 hardware wallet with Sparrow Wallet. It introduces a JavaFX dialog flow that asks the user to confirm pairing and enter a pairing code shown on the device. The change is a feature addition for a new hardware device and does not, on its own, appear to be a security vulnerability. The pairing secrets are stored in a local JSON file, similar to how the existing BitBox02 pairing is handled.

Lower-priorityupdate to macos-15-intel runnerby Craig Raw · 4ddd09fe · Dec 11, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Craig Raw

update to macos-15-intel runner

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit simply changes one of the macOS build machines used by the project's automated packaging workflow from an older GitHub-provided runner (macOS 13) to a newer Intel-based runner (macOS 15). It is a routine infrastructure update with no visible security relevance.

AI review queuedadd ledger nano gen5 supportby Craig Raw · a49edb7c · Dec 11, 2025 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · Craig Raw

add ledger nano gen5 support

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds support for a new Ledger hardware wallet model (Ledger Nano generation 5) and also includes a small UI update to recognize the Trezor Safe 7 model in a list of devices that support passphrase toggling. There is nothing in the code changes that suggests a security vulnerability or malicious behavior.

Lower-priorityupdate drongo for bip93 package exportby Craig Raw · 5275cab4 · Dec 9, 2025 · 1 fileMessage 45 · ThinInformational 4Details
Commit message · Craig Raw

update drongo for bip93 package export

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 4/100

This commit updates a dependency called 'drongo' to a newer version that exports a 'bip93' package. BIP-93 is a Bitcoin standard for encoding seed phrases in a language-independent way. The change itself is a one-line version bump in a dependency list, with no code changes visible and no security-related description in the commit message.

AI review queuedadd codex32 importer to software keystore import workflowby Ian McKenzie · 4dcd463d · Dec 9, 2025 · 4 filesMessage 50 · ThinInformational 16Details
Commit message · Ian McKenzie

add codex32 importer to software keystore import workflow

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit adds a new feature to Sparrow Wallet that lets users import a Bitcoin keystore from a Codex32 (BIP93) secret share. Codex32 is a standard for encoding a seed or secret as a human-readable string with a checksum. The change is purely additive: it introduces a new import pane, a new BIP93 importer class, and wires them into the existing software keystore import workflow. There is no indication in the commit that this fixes a security bug; it appears to be a normal feature addition.

Security candidateminor ui changes to master private key importby Craig Raw · f900f6dc · Dec 4, 2025 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · Craig Raw

minor ui changes to master private key import

50/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
secret or key materialcryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100

This commit makes two small user-interface tweaks to the screen where a user imports a master private key: it changes a title to say 'Enter master private key', makes the Import button the default button that activates when the user presses Enter, and adds a period to a description sentence. There is no security-relevant code change.

AI review queuedensure plugdev is added as a system groupby Craig Raw · b0ab6c9d · Dec 3, 2025 · 4 filesMessage 45 · ThinInformational 21Details
Commit message · Craig Raw

ensure plugdev is added as a system group

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit changes how the Linux installer creates the 'plugdev' group. Previously it created a normal user group; now it creates it as a system group using the -r flag. System groups are intended for services and hardware access, and using one here is more conventional for a group that grants device access. The change is a packaging/installation hardening improvement, not a fix for an active exploit.

Lower-priorityimprove calculation of taproot tweaked keysby Craig Raw · b8a703ad · Dec 1, 2025 · 1 fileMessage 45 · ThinModerate 53Details
Commit message · Craig Raw

improve calculation of taproot tweaked keys

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Moderate 53/100

This commit claims to improve how Sparrow Wallet calculates Taproot tweaked keys, which are a cryptographic detail used in Bitcoin's newer Taproot address type. A flaw in this calculation could in theory cause incorrect addresses, make funds unspendable, or weaken privacy, but the actual code change is not visible in the supplied materials. Only the one-line summary and file name ('drongo') are provided.

Lower-priorityupdate drongo with bech32 refactorby Craig Raw · 4185a8dc · Nov 27, 2025 · 1 fileMessage 45 · ThinInformational 2Details
Commit message · Craig Raw

update drongo with bech32 refactor

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 2/100

This commit updates a sub-component named 'drongo' to include a 'bech32 refactor'. Bech32 is a Bitcoin address format. The actual code changes are not visible because the diff was not supplied, and no verified references were provided. There is no direct evidence this update fixes or introduces a security problem.

AI review queuedfollowup to display address for watch-only walletsby Craig Raw · a6081970 · Nov 26, 2025 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Craig Raw

followup to display address for watch-only wallets

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a small UI follow-up fix that changes when the 'Display Address' button is shown for watch-only wallets. Previously, the button only appeared if all keystores were watch-only software wallets. Now it appears if any keystore is watch-only or a hardware USB device. There is no security issue visible in the change.

Lower-priorityupdate block logo fill for dark themeby Craig Raw · b4630043 · Nov 25, 2025 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Craig Raw

update block logo fill for dark theme

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit only changes the color fill of a small logo image used in the Sparrow Wallet user interface. It makes the block.xyz icon appear correctly on dark backgrounds. There is no security relevance.

AI review queuedadd block.xyz augur fee estimatorby Liz Lightning · 6452bf81 · Nov 25, 2025 · 3 filesMessage 45 · ThinInformational 19Details
Commit message · Liz Lightning

add block.xyz augur fee estimator

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit adds a new optional Bitcoin transaction fee estimator source called block.xyz (using Block's 'Augur' fee estimation service) to the Sparrow Wallet desktop app. It lets users choose this service when estimating how much fee to pay for Bitcoin transactions. There is no obvious security bug in the code, but adding any new external data source creates a small expansion of the app's 'attack surface' and trust assumptions.

AI review queuedalways show display address for watch-only walletsby Craig Raw · 71cb5852 · Nov 25, 2025 · 1 fileMessage 50 · ThinLow 26Details
Commit message · Craig Raw

always show display address for watch-only wallets

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 26/100

This small change makes the 'Display Address' button always appear for watch-only wallets in Sparrow Wallet. Watch-only wallets cannot spend funds, so this is mainly a usability improvement to help users verify receiving addresses. It does not appear to fix a vulnerability that lets someone steal bitcoins, but it may reduce the chance a user sends funds to a wrong or attacker-controlled address.