Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…
Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …
New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …
This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…
Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…
Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…
New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…
New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…
Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…
New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…
Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…
No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …
No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…
Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…
Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…
Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…
No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…
Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…
Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…
Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…
Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Moderate 61/100
This commit rewrites how the Stack Wallet app handles typed-in money amounts. It makes the rules for what counts as a valid amount much stricter: only digits and the user's locale-specific decimal separator are allowed, grouping characters (like commas in 1,000) are rejected, and the code now keeps a separate 'canonical' parser for trusted sources like QR codes. The change also adds recovery logic for on-screen keyboards that compose characters in unusual ways, so the app doesn't get stuck with an unparseable amount. The main risk is that a user could previously enter an amount that the app misread by a factor of 1,000 (for example, treating '1.000' as one thousand instead of one), which could lead to sending far more cryptocurrency than intended.
Lower-priorityTrim pasted text and pass it through the field's input formatters so paste works the same as typed input.by Julian · 3621c59d · Aug 26, 2026 · 2 filesMessage 65 · AdequateTriage 0Details
Commit message · Julian
Trim pasted text and pass it through the field's input formatters so paste works the same as typed input.
65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Lower-priorityupdate devicelocale package with linux fix merged upstreamby Julian · da38ddce · Aug 26, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Julian
update devicelocale package with linux fix merged upstream
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedupdate NSPhotoLibraryUsageDescription stringby Julian · 0f6c54fa · Aug 24, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Julian
update NSPhotoLibraryUsageDescription string
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only rewords the iOS permission message shown to users when the app requests access to the photo library. It changes a generic 'Photo Library Access Warning' into a clearer explanation that the app only reads images the user selects (for example, a QR code photo) and does not access the library automatically. There is no code change that alters what the app actually does or fixes a security flaw.
AI review queuedupdate NSPhotoLibraryUsageDescription stringby Julian · f920c360 · Aug 24, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Julian
update NSPhotoLibraryUsageDescription string
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only rewords the iOS permission message shown to users when the app wants to access photos. It changes a generic 'Photo Library Access Warning' to a clearer explanation that the app only reads images the user selects (for example, a QR code photo) and will not access the photo library automatically. There is no code change that alters what the app actually does or fixes a security flaw.
AI review queuedreplace deprecated share callby Julian · dafffe88 · Aug 22, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Julian
replace deprecated share call
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit simply swaps an old, deprecated 'Share' button function for the newer 'SharePlus' package equivalent in the PayNym screen. It is a routine maintenance/dependency update with no visible security change.
Lower-priorityanother set of dep upgrades for SPM as well as android/gradle stuffby Julian · 000c3fe6 · Aug 19, 2026 · 13 filesMessage 50 · ThinTriage 0Details
Commit message · Julian
another set of dep upgrades for SPM as well as android/gradle stuff
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
This commit updates several third-party software libraries (dependencies) and adjusts the code that shares QR-code images so it uses the newer library's API. It is a routine maintenance/cleanup change. There is no direct evidence in the commit that it fixes a security vulnerability, but keeping dependencies up to date can remove known bugs in older library versions.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 37/100
This commit fixes a wallet bug where Litecoin MWEB peg-out transactions could be spent before they were actually valid on the network. MWEB peg-outs require six confirmations to mature, but Stack Wallet was treating them like normal transactions that only need one confirmation. The patch detects these special outputs and enforces the six-block wait, preventing users from accidentally creating invalid or rejected transactions.
AI review queuedrefactor electrumx based coin transaction building and fee calculationby Julian · d00afa71 · Aug 19, 2026 · 5 filesMessage 50 · ThinLow 33Details
Commit message · Julian
refactor electrumx based coin transaction building and fee calculation
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 33/100
This commit refactors how Stack Wallet builds Bitcoin-like transactions and calculates fees. It introduces a new fee planner that handles three modes: normal fixed-amount sends, 'subtract fee from amount' (the recipient gets slightly less so the sender doesn't need extra funds for the fee), and sweep/all sends. The change consolidates previously scattered fee logic into one place and adds unit tests. It is a code-quality and feature refactor; there is no direct evidence in the commit that it fixes a known security vulnerability, but any change to transaction-fee logic can affect whether users accidentally overpay, underpay, or create invalid transactions.
AI review queuedfix custom fee ui state drift on mobileby Julian · a8ca183a · Aug 18, 2026 · 9 filesMessage 45 · ThinLow 30Details
Commit message · Julian
fix custom fee ui state drift on mobile
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 30/100
This commit fixes a UI bug in Stack Wallet where the custom/preset fee selection could get out of sync between the fee picker and the actual transaction being built. Previously, whether a custom fee was active was tracked in a separate local variable that could drift from the shared state provider. The patch makes the send flow read the fee mode directly from the shared state provider at the moment the transaction is prepared, and adds a helper that only supplies a custom fee value when custom mode is actually selected. The risk is that a user might have a preset fee selected while the app still uses an old custom fee value, or vice versa, leading to an unexpected transaction fee.
AI review queuedmemo/extraid swap supportby Julian · 09ac90fe · Aug 18, 2026 · 16 filesMessage 35 · OpaqueLow 34Details
Commit message · Julian
memo/extraid swap support
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 34/100
This commit adds support for 'memos' or 'destination tags' when swapping cryptocurrencies through third-party exchange providers. Some coins (like XRP, XLM, ATOM, etc.) require these extra identifiers so the receiving platform knows which customer account should get the funds. Previously, the wallet always sent these fields as empty/null, which could cause swapped funds to be lost or misattributed when sent to an exchange or custodial address that requires a memo. The change also parses memos from scanned QR payment URIs and shows input fields only when the chosen currency commonly needs one.
Lower-priorityfix payment uri amount parsingby Julian · c31d8288 · Aug 17, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Julian
fix payment uri amount parsing
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-prioritytighten localized number string parsingby Julian · 9bb5acac · Aug 17, 2026 · 3 filesMessage 45 · ThinTriage 0Details
Commit message · Julian
tighten localized number string parsing
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedformattingby Julian · f2325147 · Aug 17, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Julian
formatting
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is purely a code-formatting cleanup in a single Dart file that builds the QR-code generation screen. It rewraps long lines, adjusts indentation, and replaces a deprecated SVG color property with a newer colorFilter property. No security-sensitive logic, permissions, or data handling changed.
Lower-priorityhandle edgecase where estimate could be stale in the 1.5s windowby Julian · 78eced11 · Aug 17, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Julian
handle edgecase where estimate could be stale in the 1.5s window
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedtighten up DPS persistenceby Julian · 898c56d2 · Aug 16, 2026 · 2 filesMessage 35 · OpaqueModerate 57Details
Commit message · Julian
tighten up DPS persistence
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Moderate 57/100
This commit hardens how Stack Wallet stores the desktop password 'key blob' on disk. It prevents creating a new password blob when one already exists, verifies writes actually landed, makes password changes more atomic, and lets the app recover when the stored version number doesn't match the blob. The changes reduce the risk of ending up with a corrupt or mismatched password state that could lock a user out or leave an old password usable unexpectedly.
AI review queuedfix autobackup locationby Julian · 6541cdcc · Aug 16, 2026 · 1 fileMessage 28 · OpaqueInformational 19Details
Commit message · Julian
fix autobackup location
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 19/100
This is a one-line bug fix in a mobile/desktop cryptocurrency wallet's auto-backup screen. The developer changed which folder path is recorded as the backup destination: previously the code saved the user's original picked path, and now it saves a computed 'pathToSave' variable. Without more context we cannot tell whether this fixes a security problem or merely a functional/UI bug, but it could affect where sensitive backup files are written.
Lower-priorityadd extra check to handle amount formatter invalid selectionby Julian · 0144f910 · Aug 16, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Julian
add extra check to handle amount formatter invalid selection
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedadd extra check to nano interface account info parsingby Julian · 0fde946a · Aug 16, 2026 · 2 filesMessage 50 · ThinLow 45Details
Commit message · Julian
add extra check to nano interface account info parsing
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 45/100
This commit tightens how Stack Wallet parses account information for Nano cryptocurrency sends. Previously, if the Nano node returned an error or a malformed balance, the code could crash or behave unpredictably. Now it explicitly checks for error responses and invalid balance values before continuing. This is a defensive hardening fix that prevents bad node responses from causing app crashes or incorrect send calculations.
Lower-priorityadd extra check to swap pay in amount parsingby Julian · 6876df3f · Aug 16, 2026 · 4 filesMessage 45 · ThinTriage 0Details
Commit message · Julian
add extra check to swap pay in amount parsing
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedfix nanswap networksby Julian · 24d58009 · Aug 16, 2026 · 3 filesMessage 28 · OpaqueLow 33Details
Commit message · Julian
fix nanswap networks
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 33/100
This commit fixes a network-labeling bug in the Nanswap cryptocurrency exchange integration. Before the fix, the code sometimes mixed up the currency/network a user was supposed to send in with the one they would receive out. That could mislead users into depositing funds on the wrong blockchain or network, which in the worst case could mean lost or stuck funds. The patch adds helper getters so the correct network is always chosen, and adds a unit test to confirm the behavior.
Lower-priorityclean up node uri handlingby Julian · d84aba48 · Aug 16, 2026 · 3 filesMessage 45 · ThinTriage 0Details
Commit message · Julian
clean up node uri handling
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedensure frost wallet data is fully deleted on wallet deleteby Julian · 1c85b97a · Aug 16, 2026 · 2 filesMessage 50 · ThinModerate 59Details
Commit message · Julian
ensure frost wallet data is fully deleted on wallet delete
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 59/100
This commit fixes a cleanup bug in Stack Wallet: when a user deleted a FROST (multi-signature) Bitcoin wallet, the app was leaving behind sensitive key material and configuration data in secure storage and the local database. The patch now explicitly deletes those leftover FROST records during wallet deletion, reducing the risk that a deleted wallet's secrets could be recovered or reused later.