SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1038 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

334security candidates400second-pass queue734AI analyses
66commits · 30 days
160commits · 60 days
606commits · 180 days
1009commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax339158241062
julian347112269044
Julian18939136042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 33 minutes ago

Low 35 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1450 from Ez3kiel-dev/fix/xelis-integration

This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…

Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
ad945d43by Julian+4298−162634 files
No security note in commit
Low 32 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/xelis-integration

This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …

New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
b0e5d35aby Julian+2678−330378 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateget full ticket probably doesn't return different responses for the same id. Assuming this, we can safely poll status and messages more frequentlyby julian · 92b4dac9 · Jul 9, 2026 · 2 filesMessage 50 · ThinInformational 18Details
Commit message · julian

get full ticket probably doesn't return different responses for the same id. Assuming this, we can safely poll status and messages more frequently

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit changes how often the app checks for updates on a support ticket and skips re-downloading the full ticket details when the app already has them. It is a routine performance and responsiveness improvement, not a security fix. There is no indication it addresses a vulnerability.

Security candidateSIB and GCs accessed from home screen on mobileby julian · f8dcdd8b · Jul 9, 2026 · 10 filesMessage 45 · ThinInformational 17Details
Commit message · julian

SIB and GCs accessed from home screen on mobile

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 17/100

This commit moves two existing app features—gift cards and concierge services—from a wallet-specific menu to the main home screen on mobile. It is a user-interface navigation change, not a security fix or vulnerability patch. There is no indication it fixes a bug that could be exploited.

Lower-priorityscrollable mobile main app menu barby julian · a9f50fc0 · Jul 9, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · julian

scrollable mobile main app menu bar

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidatehack in USDT TRX warningby julian · 4c173f6c · Jul 9, 2026 · 2 filesMessage 18 · OpaqueInformational 17Details
Commit message · julian

hack in USDT TRX warning

18/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body! Contains work-in-progress language! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 17/100

This commit adds on-screen warnings telling users to send only USDT (TRC20) to a displayed address and not to send plain TRX. It is a user-interface safety hint, not a code change that fixes a software vulnerability. There is no evidence in the commit of an exploit, bug, or security flaw being patched.

Security candidatestyle dialog for desktopby julian · 9ceeebbb · Jul 8, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · julian

style dialog for desktop

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a purely cosmetic UI change. It adjusts the width and button height of a confirmation dialog on desktop versions of the app. There is no security relevance.

Security candidatesplit full name into separate fields for first and last nameby julian · d94c789f · Jul 8, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · julian

split full name into separate fields for first and last name

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit simply changes the user interface for entering a billing/shipping name. Instead of one 'Full name' text box that the app later tried to split into first and last names, it now shows two separate boxes labeled 'First name' and 'Last name'. There is no security fix or vulnerability here; it is a routine UI and data-handling refactor.

Security candidatefix null errorby julian · 941a19e2 · Jul 8, 2026 · 1 fileMessage 28 · OpaqueInformational 21Details
Commit message · julian

fix null error

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 21/100

This commit fixes a programming crash in the Stack Wallet app's checkout screen. In some countries, the app was forcing a 'State' field to be shown even when no state was selected, which could cause the app to crash with a null error. The fix hides the state field when it isn't needed and only forces it when it is required.

Security candidateload offer before view/dialog opens so the accept button isn't disabled for a second or two without any info as to why displayedby julian · 5c94aa00 · Jul 8, 2026 · 2 filesMessage 62 · AdequateInformational 12Details
Commit message · julian

load offer before view/dialog opens so the accept button isn't disabled for a second or two without any info as to why displayed

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 12/100

This commit is a user-experience refactor, not a security fix. It moves the loading of a ShopInBit offer from inside the offer screen to the moment the user taps the 'Review offer' button, so the screen opens with data already loaded. The 'Accept offer' button no longer needs to be temporarily disabled while waiting. There is no indication this change addresses a security vulnerability.

Security candidateadjust button wording to reflect functionalityby julian · 323032c7 · Jul 8, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · julian

adjust button wording to reflect functionality

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit simply renames a button label from 'Decline' to 'Cancel' on a shopping offer screen so the text matches what the button actually does (close the screen). There is no security relevance.

Security candidatedon't pass widget ref around outside buildby julian · 008481ab · Jul 8, 2026 · 1 fileMessage 45 · ThinInformational 16Details
Commit message · julian

don't pass widget ref around outside build

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

This is a small code-quality cleanup in a Flutter screen that shows ticket attachment details. It stops passing a UI framework reference (WidgetRef) into helper methods and instead passes the actual service object directly. There is no direct security vulnerability visible in the diff, but the change removes a pattern that can make code harder to reason about and could theoretically hide lifecycle bugs.

Security candidatefix provider read after disposeby julian · 0176be33 · Jul 8, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · julian

fix provider read after dispose

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This is a small bug-fix patch in a mobile wallet's shopping-support ticket screen. It stores a service reference when the screen first loads, then reuses that reference later, instead of asking the app's state-management system for the service again after the screen may have been destroyed. The change prevents a runtime crash ('provider read after dispose') but does not appear to be a security vulnerability.

Security candidatefix attachment link opening on desktopby julian · ea437941 · Jul 8, 2026 · 1 fileMessage 45 · ThinInformational 18Details
Commit message · julian

fix attachment link opening on desktop

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This is a one-line UI bug fix for opening attachment links on desktop versions of the Stack Wallet app. The change tells the app to use the root navigator on desktop when displaying an 'Opening attachment' progress indicator. There is no indication this fixes a security vulnerability; it appears to address a navigation/display issue specific to desktop layouts.

Security candidateclean up a VAT incl fixby julian · de05c79f · Jul 8, 2026 · 1 fileMessage 38 · OpaqueInformational 15Details
Commit message · julian

clean up a VAT incl fix

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a minor user-interface wording cleanup for a shopping feature. It changes two on-screen labels so that the heading now mentions VAT and the price line no longer repeats it. There is no security relevance in the code change itself.

Security candidateshorten and clarify concierge main request text fieldby julian · 90e9bb96 · Jul 8, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · julian

shorten and clarify concierge main request text field

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit only changes a user-visible label in a shopping concierge form from a longer description to a shorter one, and tweaks how a multi-line text field label is visually aligned. There is no security-relevant change.

Security candidateclearly show delivery country as requiredby julian · de3538d7 · Jul 8, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · julian

clearly show delivery country as required

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit simply changes a form field label from 'Delivery country' to 'Delivery country (Required)' in the app's shopping/payment flow. It is a user-interface wording change with no security relevance.

Security candidateadd incl VAT info where requestedby julian · e526fb0b · Jul 8, 2026 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · julian

add incl VAT info where requested

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit simply adds the text '(incl. VAT)' next to displayed prices in two shopping-related screens. It is a cosmetic/user-interface label change with no security relevance.

Security candidatevat rate can actually be a decimal which was not what the docs specifiedby julian · 3b500730 · Jul 8, 2026 · 2 filesMessage 50 · ThinInformational 19Details
Commit message · julian

vat rate can actually be a decimal which was not what the docs specified

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 19/100

This commit fixes a data-type mismatch in how the app reads VAT (sales tax) rates from a partner service. The code previously expected whole-number percentages like 19, but the service can actually send decimal values like 19.5. The change lets the app store and handle those decimal rates correctly. There is no direct evidence this is a security fix; it reads as a routine bug fix for incorrect parsing that could cause display or calculation errors.

Security candidatehack fix bad http urls from apiby julian · f8fa726a · Jul 8, 2026 · 1 fileMessage 25 · OpaqueLow 38Details
Commit message · julian

hack fix bad http urls from api

25/100 · OpaqueMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body! Contains work-in-progress language! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Low 38/100

This commit changes how the app handles package tracking links from a shopping partner API. Previously, the app took whatever text the API returned and treated it as a link. Now, if the text doesn't already start with 'http://' or 'https://', the app automatically adds 'https://' in front. This is a quick fix to prevent broken or unsafe links, but it doesn't fully validate that the resulting string is a real, safe URL.

Security candidateflagby julian · 976bd6be · Jul 8, 2026 · 1 fileMessage 0 · OpaqueLow 44Details
Commit message · julian

flag

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Low 44/100

A single-line change flips a third-party shopping integration from sandbox/test mode to live/production mode. This is a configuration change rather than a traditional code vulnerability, but it moves real user transactions and partner secrets from a safe test environment to the live service. If the rest of the app is not ready for production, this could expose real payment or order data, charge real money, or leak the partner secret through production traffic.

AI review queuedFix Spark Name registration formatby Reuben Yap · ca52f39c · Jul 3, 2026 · 3 filesMessage 45 · ThinLow 31Details
Commit message · Reuben Yap

Fix Spark Name registration format

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 31/100

This commit fixes the way Spark Name registration data is embedded in blockchain transactions. Spark Names are human-readable aliases (like a username) tied to a privacy address. The previous code likely sent the registration fee to a plain address without attaching the required extra metadata, which could cause the name registration to fail or be recorded incorrectly. The patch adds the proper script format, including the name and Spark address, so the Firo network can recognize and process the registration. It also switches the underlying Spark mobile library from Cypher Stack's fork to the official Firoorg repository.

Lower-priorityfix: use correct familiarity flagby julian · 4bb226b0 · Jul 1, 2026 · 3 filesMessage 57 · ThinTriage 0Details
Commit message · julian

fix: use correct familiarity flag

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Security candidateshow request shipping tracking links if availableby julian · 70981e89 · Jun 26, 2026 · 3 filesMessage 45 · ThinInformational 21Details
Commit message · julian

show request shipping tracking links if available

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 21/100

This commit adds a feature that displays shipping tracking links on a purchase ticket detail page. When a user taps a link, the app tries to open it in an external browser. The change is mostly a normal UI feature, but it does accept tracking-link strings from ticket data and pass them directly to the phone's URL opener. That creates a small risk if a malicious or compromised server sends a harmful link, because the app will try to open whatever it receives without visible filtering.

Security candidatefeat(shopinbit): split tracking linksby sneurlax · 1b9d2818 · Jun 26, 2026 · 1 fileMessage 57 · ThinInformational 18Details
Commit message · sneurlax

feat(shopinbit): split tracking links

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit is a routine feature improvement for the ShopinBit integration in Stack Wallet. It changes how package tracking links are handled: instead of storing one raw string that may contain several URLs crammed together with commas, pipes, or semicolons, the code now splits that string into a clean list of individual tracking URLs. It also turns empty strings from the server into null values so the rest of the app doesn't treat an empty value as a real link. There is no security fix here and nothing that looks like a vulnerability.

Security candidaterefactor(shopinbit): parse ticket messages with the html packageby sneurlax · ad6cde62 · Jun 26, 2026 · 3 filesMessage 62 · AdequateLow 37Details
Commit message · sneurlax

refactor(shopinbit): parse ticket messages with the html package

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 37/100

This commit replaces a custom-built HTML parser in Stack Wallet's ShopinBit ticket-message feature with the well-known 'html' package. The old code parsed HTML by hand using string scanning and regular expressions, which is a common source of security bugs (for example, tricking the parser into treating malicious code as harmless text or vice versa). The new code uses a dedicated HTML parser that is more robust against malformed or adversarial input. The change is a defensive refactor; there is no direct evidence in the commit that an actual attack was found or exploited.

Security candidatefix(shopinbit): handle ticket message mediaby sneurlax · 71d8a86f · Jun 26, 2026 · 4 filesMessage 57 · ThinLow 37Details
Commit message · sneurlax

fix(shopinbit): handle ticket message media

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 37/100

This update improves how Stack Wallet's ShopInBit support-chat feature handles images and file attachments. It replaces an older inline-base64-only image renderer with a safer parser that also supports server-hosted attachments, adds request timeouts so background polling can't get stuck forever, and skips malformed messages instead of crashing the whole chat. The code also adds path-traversal checks on attachment URLs so a malicious link can't trick the app into requesting unintended server paths using the user's own login token.