SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1038 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

334security candidates400second-pass queue734AI analyses
66commits · 30 days
160commits · 60 days
606commits · 180 days
1009commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax339158241062
julian347112269044
Julian18939136042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 14 minutes ago

Low 35 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1450 from Ez3kiel-dev/fix/xelis-integration

This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…

Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
ad945d43by Julian+4298−162634 files
No security note in commit
Low 32 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/xelis-integration

This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …

New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
b0e5d35aby Julian+2678−330378 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityfix: always show/log error in orders view and ensure its propagated from refreshAllby julian · 496d998e · Jun 11, 2026 · 2 filesMessage 62 · AdequateTriage 0Details
Commit message · julian

fix: always show/log error in orders view and ensure its propagated from refreshAll

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-priorityfix(cakepay): show a flushbar when pull-to-refresh failsby sneurlax · a201981f · Jun 11, 2026 · 2 filesMessage 62 · AdequateTriage 0Details
Commit message · sneurlax

fix(cakepay): show a flushbar when pull-to-refresh fails

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-priorityfix(cakepay): log refreshAll errors without propagating themby sneurlax · 65542e9e · Jun 11, 2026 · 2 filesMessage 62 · AdequateTriage 0Details
Commit message · sneurlax

fix(cakepay): log refreshAll errors without propagating them

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-prioritydocs(cakepay): drop misleading comment on refreshAll ignoreby sneurlax · adc937fb · Jun 11, 2026 · 1 fileMessage 62 · AdequateTriage 0Details
Commit message · sneurlax

docs(cakepay): drop misleading comment on refreshAll ignore

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Security candidatefix(shopinbit): only mark car research complete once the ticket existsby sneurlax · 6b7d9bcb · Jun 11, 2026 · 1 fileMessage 62 · AdequateInformational 16Details
Commit message · sneurlax

fix(shopinbit): only mark car research complete once the ticket exists

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

This commit fixes a UI timing bug in a cryptocurrency wallet's car-research payment flow. Previously, the app could mark the payment as 'complete' and try to open the order details before the backend ticket actually existed, which could briefly show the wrong screen or a fallback. Now it waits until the real ticket ID is available before marking the flow complete. There is no direct evidence this is a security vulnerability.

AI review queuedfix(firo): clear stale op return send stateby Navid Rahimi · 7cc95b07 · Jun 11, 2026 · 3 filesMessage 57 · ThinLow 49Details
Commit message · Navid Rahimi

fix(firo): clear stale op return send state

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 49/100

This commit fixes a UI state bug in the Stack Wallet app where leftover 'OP_RETURN' data (extra information sometimes attached to a cryptocurrency transaction) could stick around when a user changed the recipient address or scanned a new QR code. The leftover data could then incorrectly block or alter sending for coins that don't support it. The patch clears that stale state in more places and disables the preview-transaction button when OP_RETURN data is present for any coin other than Firo.

Security candidatefix(shopinbit): handle no_payment_required as fully coveredby sneurlax · 0119c48f · Jun 11, 2026 · 2 filesMessage 62 · AdequateInformational 21Details
Commit message · sneurlax

fix(shopinbit): handle no_payment_required as fully covered

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 21/100

This commit fixes a UI/workflow bug in Stack Wallet's ShopInBit integration. When an order is fully covered by a voucher or store credit, the payment status becomes 'no_payment_required' and the invoice has no payment addresses. Previously the app treated this as a failed payment load and blocked the user; now it shows a 'fully covered' screen and lets the user continue. It is a functional bug fix rather than a security vulnerability.

Security candidatechore(shopinbit): address review on car-research finalizeby sneurlax · e61d8400 · Jun 11, 2026 · 2 filesMessage 62 · AdequateInformational 23Details
Commit message · sneurlax

chore(shopinbit): address review on car-research finalize

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 23/100

This commit makes two small code cleanups in a car-research payment flow. One change removes a manual timer cancellation and relies on the caller to cancel it, which could in theory lead to a timer continuing to run briefly if the caller doesn't always do so. The other change replaces a safe integer parser (which throws a clear error on bad input) with a stricter parser that throws a less informative error. Neither change is obviously a security fix, and the commit message frames them as routine review follow-up rather than a security issue.

Security candidatefix(shopinbit): surface parse errors for required ticket fieldsby sneurlax · 860bd1ab · Jun 11, 2026 · 2 filesMessage 62 · AdequateLow 29Details
Commit message · sneurlax

fix(shopinbit): surface parse errors for required ticket fields


and cleaning

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 29/100

This commit changes how the Stack Wallet app parses data from its ShopInBit partner service. Previously, missing or malformed fields were silently replaced with empty strings, zero, or the current date/time. Now the app throws visible errors instead. That is generally a good defensive change, but it removes some safety comments and fallback behavior for unknown ticket states, and it makes parsing stricter. The patch is small and appears aimed at surfacing bugs rather than introducing a vulnerability, but it is only a partial hardening of the parsing layer.

Security candidatefix(shopinbit): require remaining required fields across modelsby sneurlax · 8e33585b · Jun 11, 2026 · 5 filesMessage 62 · AdequateLow 26Details
Commit message · sneurlax

fix(shopinbit): require remaining required fields across models

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 26/100

This commit tightens how the Stack Wallet app reads data from its ShopInBit partner service. Previously, several fields were treated as optional and replaced with safe defaults (empty strings, false, current time) when missing. Now the code requires those fields to be present and correctly typed. This is a defensive correctness fix: it makes the app fail earlier and more visibly if the server sends unexpected or malformed data, rather than silently continuing with placeholder values. There is no direct evidence this fixes an active security vulnerability, but it reduces the risk of logic errors or misleading UI state caused by missing fields.

Security candidatefix(shopinbit): keep car-research expiresAt null on parse failureby sneurlax · 1e820fd7 · Jun 10, 2026 · 1 fileMessage 62 · AdequateLow 35Details
Commit message · sneurlax

fix(shopinbit): keep car-research expiresAt null on parse failure

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 35/100

This commit fixes a bug in the Stack Wallet app's integration with ShopinBit's car-research service. Previously, if the invoice expiration date was missing or unreadable, the app would silently replace it with the current time, making a brand-new invoice look like it had already expired. Now the app keeps the expiration date as 'unknown' instead of guessing. This is a correctness and user-experience fix, not a remote code execution or theft vulnerability.

Security candidatefix(shopinbit): treat an empty 2xx body as an errorby sneurlax · 0d54cd92 · Jun 10, 2026 · 1 fileMessage 62 · AdequateLow 44Details
Commit message · sneurlax

fix(shopinbit): treat an empty 2xx body as an error

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 44/100

This commit fixes a bug in the Stack Wallet app's integration with ShopInBit. Previously, if the server returned a successful HTTP response with an empty body, the app would pretend it received valid data and create fake placeholder objects (for example, a support ticket with ID 0). Now the app correctly treats an empty successful response as an error instead. This is a defensive fix that prevents the app from acting on fabricated data, which could confuse users or lead to incorrect app behavior.

Security candidatefix(shopinbit): recover car-research invoices within the +24h graceby sneurlax · c5f20015 · Jun 10, 2026 · 1 fileMessage 62 · AdequateInformational 18Details
Commit message · sneurlax

fix(shopinbit): recover car-research invoices within the +24h grace

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit fixes a business-logic bug in Stack Wallet's ShopinBit ticket screen. Previously, car-research invoices that had expired but were still within a 24-hour grace period were incorrectly treated as unpayable, so users could not resume or recover them. The change extends the payable check from the original expiration time to 24 hours after expiration, matching the documented spec. There is no direct security signal in the diff itself.

Security candidatefix(shopinbit): re-authenticate once on HTTP 401by sneurlax · 85e8b394 · Jun 10, 2026 · 1 fileMessage 57 · ThinInformational 22Details
Commit message · sneurlax

fix(shopinbit): re-authenticate once on HTTP 401

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 22/100

This commit fixes a bug in the Stack Wallet app's integration with ShopInBit. Previously, if the app's login token expired while making a request, the app would simply fail. Now, when it receives an HTTP 401 'unauthorized' error, it automatically refreshes the token once and retries the request. This is a routine reliability fix rather than a security vulnerability patch.

Security candidatefix(shopinbit): regenerate expired invoice via PUT ?retry=trueby sneurlax · d1457a08 · Jun 10, 2026 · 2 filesMessage 62 · AdequateInformational 18Details
Commit message · sneurlax

fix(shopinbit): regenerate expired invoice via PUT ?retry=true

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit fixes a small integration bug in the Stack Wallet app's ShopInBit payment feature. Previously, when a user tried to refresh an expired invoice, the app called the server without the required retry=true flag. The fix adds that flag so the server regenerates the invoice instead of returning an error. There is no direct evidence this is a security vulnerability; it appears to be a normal bug fix for a broken user flow.

Security candidatechore(shopinbit): clean up merge lintsby sneurlax · 716c6e33 · Jun 10, 2026 · 2 filesMessage 57 · ThinInformational 15Details
Commit message · sneurlax

chore(shopinbit): clean up merge lints

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This is a routine code cleanup commit. It removes one unused import and fixes a Dart lint warning by replacing an unnecessary null-assertion operator with a direct property access. There is no security-relevant change.

Security candidatefix: race condition when refreshing all shopinbit tickets when not all tickets use the same customer key. Probably introduces bugs elsewhere now though...by julian · b9b104fd · Jun 10, 2026 · 12 filesMessage 62 · AdequateLow 35Details
Commit message · julian

fix: race condition when refreshing all shopinbit tickets when not all tickets use the same customer key. Probably introduces bugs elsewhere now though...

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 35/100

This commit fixes a race condition in the Stack Wallet app's ShopinBit feature. Previously, the app stored one shared 'customer key' on the API client object. When refreshing multiple tickets that belonged to different customer keys, one ticket's key could overwrite another's mid-refresh, causing requests to be sent with the wrong key. The fix passes the correct customer key alongside each individual request instead of relying on shared state. The commit message notes the fix may introduce other bugs elsewhere.

Security candidaterefactor(shopinbit): drop the single-flight ticket/invoice fetch wrappersby sneurlax · f01dc8c3 · Jun 10, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

refactor(shopinbit): drop the single-flight ticket/invoice fetch wrappers

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit removes a small performance optimization in the Stack Wallet app's ShopInBit service. Previously, if multiple parts of the app tried to fetch the same ticket list or car-research invoice list at the same time, they would share one network request. After this change, each call goes straight to the API independently. There is no security fix or vulnerability here—it's a straightforward code simplification that may slightly increase API traffic.

Security candidatefix(shopinbit): drop the by-customer car ticket fallbackby sneurlax · 77461f13 · Jun 10, 2026 · 3 filesMessage 62 · AdequateInformational 22Details
Commit message · sneurlax

fix(shopinbit): drop the by-customer car ticket fallback

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 22/100

This commit removes a fallback mechanism in Stack Wallet's ShopInBit car-research payment flow. Previously, if the server didn't immediately provide the real customer-support ticket ID, the app would try to guess it by listing all tickets associated with the customer and picking the newest one that wasn't already known. That fallback is now deleted; the app simply waits for the server to supply the real ticket ID directly. The change is described as a functional fix, not a security fix, but removing a heuristic that touches other customer tickets reduces the risk of accidentally opening or acting on the wrong ticket.

Security candidaterefactor(shopinbit): consolidate poll backoff into the clientby sneurlax · 090ab331 · Jun 10, 2026 · 4 filesMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

refactor(shopinbit): consolidate poll backoff into the client

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a simple code cleanup: it moves the same retry-backoff calculation used by three different screens into one shared helper inside the ShopInBit client. There is no change in behavior, no bug fix, and no security improvement or regression.

Security candidatefix(shopinbit): migrate car research flow to API v1.0.6by sneurlax · fb6ea0c2 · Jun 10, 2026 · 5 filesMessage 77 · AdequateInformational 16Details
Commit message · sneurlax

fix(shopinbit): migrate car research flow to API v1.0.6

docs(shopinbit): tighten car research v1.0.6 comments

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

This commit updates the Stack Wallet app's 'ShopinBit car research' feature to work with a newer version of the partner API (v1.0.6). It mainly changes how the app checks whether a customer has paid the car-research fee and how it finds the resulting support ticket. The old code relied on a separate 'log payment' API call that is being removed; the new code reads the payment/ticket status directly from a status endpoint. There is no obvious security bug being fixed, but the change removes a workaround where payment confirmation was partly driven by the client calling a logging endpoint.

AI review queued- Restore BuildingTransactionDialog in SendView on desktop (revert showLoading) - Replace AlertDialog with SDialog for collateral address picker - Revert custom CreateMasternodeView close button and cancel/pop behavior - Extract masternode collateral send notes to MasternodeCollateralNotesby levoncrypto · 1928d37f · Jun 10, 2026 · 6 filesMessage 73 · AdequateInformational 11Details
Commit message · levoncrypto

- Restore BuildingTransactionDialog in SendView on desktop (revert showLoading)
- Replace AlertDialog with SDialog for collateral address picker
- Revert custom CreateMasternodeView close button and cancel/pop behavior
- Extract masternode collateral send notes to MasternodeCollateralNotes

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 11/100

This commit is a small UI cleanup in a cryptocurrency wallet app. It restores a 'building transaction' loading dialog on desktop, swaps one style of address picker dialog for another, and moves two hard-coded note strings into a shared constants file. There is no obvious security fix or vulnerability being introduced; it looks like ordinary bug-fix/refactoring work.

Lower-priorityAdd build disclaimer to workflow run summaryby Dan Miller · 7f3c3f62 · Jun 6, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Dan Miller

Add build disclaimer to workflow run summary

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
Security candidatefeat(shopinbit): after payment, nav back to specific request if knownby sneurlax · 25541dd3 · Jun 4, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

feat(shopinbit): after payment, nav back to specific request if known

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit changes the post-payment navigation in the ShopInBit feature of Stack Wallet. After a user pays, the app now tries to return them to the specific purchase request they came from, instead of always sending them to the general requests list. There is no security issue visible in this change.

Security candidatefix(shopinbit): combine by-customer and car-invoice fetchesby sneurlax · 60559c42 · Jun 4, 2026 · 2 filesMessage 85 · StrongInformational 19Details
Commit message · sneurlax

fix(shopinbit): combine by-customer and car-invoice fetches

getTicketsByCustomer and getCurrentCarResearchInvoices were the two read paths left outside the completer-based dedup that already guards _refreshRef, so overlapping refreshes (tickets view racing a post-action refresh, or refreshAll racing adoptRealCarTicket) each fired their own
request. Wrap both in the same in-flight combined pattern and route callers through it.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
authentication path
AI analysis · Informational 19/100

This change is a performance fix, not a security fix. It prevents the wallet's ShopInBit ticket screen from making duplicate API calls when several refreshes happen at the same time. The code now shares one in-flight request among callers instead of firing multiple identical requests. There is no evidence in the commit of a vulnerability being patched.