SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1038 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

334security candidates400second-pass queue734AI analyses
66commits · 30 days
160commits · 60 days
606commits · 180 days
1009commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax339158241062
julian347112269044
Julian18939136042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 14 minutes ago

Low 35 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1450 from Ez3kiel-dev/fix/xelis-integration

This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…

Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
ad945d43by Julian+4298−162634 files
No security note in commit
Low 32 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/xelis-integration

This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …

New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
b0e5d35aby Julian+2678−330378 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefix: empty string in response and more loggingby julian · 170cd9dd · Jun 1, 2026 · 2 filesMessage 57 · ThinInformational 20Details
Commit message · julian

fix: empty string in response and more logging

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 20/100

This commit fixes a minor app crash and adds better error logging. The app was failing when a backend response contained an empty VAT rate field, because the code expected a number and couldn't handle an empty string. The fix makes the VAT rate optional and safely parses it. The logging change helps developers see what went wrong during invoice loading.

Security candidatefix: log polling issue. Dialog isn't great here as its polling and... well...by julian · 44531dd8 · Jun 1, 2026 · 1 fileMessage 62 · AdequateInformational 16Details
Commit message · julian

fix: log polling issue. Dialog isn't great here as its polling and... well...

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

This is a small user-experience and diagnostics fix in a cryptocurrency wallet's car-research payment screen. It replaces a silent failure during a background polling loop with a logged error message, while keeping the existing on-screen error notification. There is no direct security vulnerability visible in the change.

Security candidateshopinbit refactor wipby julian · 1a804a50 · Jun 1, 2026 · 47 filesMessage 8 · OpaqueInformational 14Details
Commit message · julian

shopinbit refactor wip

8/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Contains work-in-progress language! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 14/100

This commit is a large work-in-progress refactor of the ShopinBit feature inside the Stack Wallet app. It restructures local database tables, generated code, and UI files to support a new customer-key-based account model and ticket storage. There is no direct evidence in the commit message or diff that this is a security fix, security patch, or response to a reported vulnerability. It appears to be ordinary feature/codebase maintenance.

AI review queuedre enable shopinbitby julian · 0042ca98 · May 31, 2026 · 2 filesMessage 28 · OpaqueInformational 17Details
Commit message · julian

re enable shopinbit

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit simply turns a feature flag back on for a third-party shopping integration called 'shopinBit' in two build configuration scripts. It adds one line to each script that includes the feature in the list of enabled app features. There is nothing in the commit that fixes, introduces, or describes a security vulnerability.

Security candidatepre loading example combined with required args in widget/viewby julian · cfb37fe1 · May 30, 2026 · 4 filesMessage 50 · ThinInformational 16Details
Commit message · julian

pre loading example combined with required args in widget/view

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

This commit refactors how a shopping feature in Stack Wallet loads country lists. Instead of fetching countries inside the shipping screen, it now fetches them earlier when the user accepts an offer, shows a loading spinner, validates the delivery country, and passes the list forward as a required argument. The change makes the shipping screen simpler and removes a fallback path where users could pick a different delivery country for restored orders. There is no obvious security bug in the diff, but the change removes some flexibility and error tolerance.

AI review queuedtemporarily disable shopinbit uiby julian · afb40b84 · May 30, 2026 · 2 filesMessage 35 · OpaqueInformational 17Details
Commit message · julian

temporarily disable shopinbit ui

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit removes a feature flag called 'shopinBit' from two build configuration scripts, effectively hiding that feature from two app variants (Stack Wallet and Stack Duo). There is no code change that fixes or changes any security behavior, cryptographic operation, network request, permission, or data handling. It is a straightforward feature-toggle removal with no apparent security relevance based on the diff alone.

AI review queuedfix: account for Firo OP_RETURN in fee previewsby Navid Rahimi · 706779c1 · May 30, 2026 · 6 filesMessage 57 · ThinLow 31Details
Commit message · Navid Rahimi

fix: account for Firo OP_RETURN in fee previews

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 31/100

This commit fixes a bug in Stack Wallet where transaction fee previews did not include the extra cost of adding an OP_RETURN data output for Firo public-balance sends. As a result, users could have been shown a lower fee than what the network would actually charge, or the wallet might have constructed an under-funded transaction. The patch adds the missing fee calculation, makes the OP_RETURN state provider auto-dispose to avoid stale data, and guards state updates with a 'mounted' check to prevent crashes after a screen is closed.

AI review queuedAdd OP_RETURN support required for rosen bridgeby Navid Rahimi · c9035e41 · May 30, 2026 · 6 filesMessage 45 · ThinLow 37Details
Commit message · Navid Rahimi

Add OP_RETURN support required for rosen bridge

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 37/100

This commit adds support for embedding small pieces of public metadata (called OP_RETURN data) into cryptocurrency transactions, specifically to enable a feature called Rosen Bridge. The code lets users paste a special payment link or scan a QR code that includes bridge instructions, shows a warning if the user tries to use a private balance, and only allows the metadata on public Firo transactions. It also enforces an 80-byte size limit and validates the data before adding it to the transaction.

Security candidaterefactor(shopinbit): resume car research with inline row spinnerby sneurlax · 28cc575c · May 30, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

refactor(shopinbit): resume car research with inline row spinner

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a user-interface refactor for the Stack Wallet app's 'ShopInBit' car-research ticket screen. It replaces a full-screen loading dialog with a small inline spinner while the app checks the server for an in-progress car-research invoice. There is no security-relevant change: no cryptography, authentication, network trust, permissions, or data handling logic is altered.

Security candidatefeat(shopinbit): resume car research from server-side current invoicesby sneurlax · 992d17e4 · May 29, 2026 · 1 fileMessage 62 · AdequateInformational 18Details
Commit message · sneurlax

feat(shopinbit): resume car research from server-side current invoices

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit changes how the Stack Wallet app resumes a 'car research' purchase when a user taps an in-progress ticket. Instead of relying only on invoice details saved on the phone, it now first asks the ShopInBit server for the current invoice list and uses that to decide whether to continue to payment or start over. The change appears to be a feature/robustness improvement, not a security fix, but it does introduce a new network call and slightly different logic for matching invoices.

Security candidaterefactor(shopinbit): finalize car research via backend failsafeby sneurlax · 8981054b · May 29, 2026 · 2 filesMessage 62 · AdequateInformational 23Details
Commit message · sneurlax

refactor(shopinbit): finalize car research via backend failsafe

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 23/100

This commit refactors how Stack Wallet finalizes a paid car-research request in its ShopInBit feature. It moves most of the post-payment work (creating the real support ticket) from the app to the backend, so the app now just logs the payment and then looks up the ticket the server created. It also makes number parsing safer when price data is missing. There is no direct evidence this fixes an active security bug, but it removes client-side logic that could previously leave orders in inconsistent states if the app crashed or retried at the wrong time.

Security candidaterefactor(shopinbit): retire manual car research request retryby sneurlax · 1c503d99 · May 29, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

refactor(shopinbit): retire manual car research request retry

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit removes a manual 'Complete Request' button from the car-research ticket screen and replaces it with a simple informational note telling the user that the request is being finalized automatically. The change is a user-experience refactor, not a security fix.

Security candidatefeat(shopinbit): cache car request payload when creating the fee invoiceby sneurlax · fb4952db · May 29, 2026 · 1 fileMessage 62 · AdequateInformational 11Details
Commit message · sneurlax

feat(shopinbit): cache car request payload when creating the fee invoice

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 11/100

This commit changes a car-research fee invoice screen so that, when requesting an invoice, the app now also sends the customer's car request details (a pseudonym, comment, and delivery country) to the backend. The stated goal is to let the backend create the real research ticket automatically once the fee is paid. There is no direct security bug visible in the diff, but it increases the amount of personal/order data transmitted and stored server-side, which could matter for privacy if the backend does not protect it properly.

Security candidatefeat(shopinbit): add car request payload and invoice recovery to clientby sneurlax · bdb6f7aa · May 29, 2026 · 2 filesMessage 62 · AdequateInformational 18Details
Commit message · sneurlax

feat(shopinbit): add car request payload and invoice recovery to client

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit adds two new features to the ShopInBit integration in Stack Wallet: it lets users attach a car-research request to a fee invoice, and it lets them retrieve any unpaid car-research invoices so they can finish paying. The code itself is a normal feature addition and does not appear to introduce an obvious security vulnerability. The main thing to watch is that the new API calls send personal/pseudonymous data and payment links over the network, so they rely on the existing HTTPS and authentication plumbing being correct.

Security candidatefix(shopinbit): require a live invoice before opening the payment viewby sneurlax · 9335dd5f · May 28, 2026 · 4 filesMessage 62 · AdequateLow 37Details
Commit message · sneurlax

fix(shopinbit): require a live invoice before opening the payment view

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 37/100

This commit hardens the checkout flow for a built-in shopping feature (ShopInBit). Previously, the payment screen could open even if no live invoice with payment addresses had been loaded, and it tried to recover or render empty payment links. Now the app refuses to open the payment screen unless a usable invoice is already in hand, and it disables the 'Pay Now' action when an address is missing. This reduces the chance a user accidentally sends money to an empty/invalid destination or gets stuck in a broken payment state.

Security candidatechore(shopinbit): drop unused show_flush_bar import from car fee viewby sneurlax · 13144c21 · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

chore(shopinbit): drop unused show_flush_bar import from car fee view

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit simply removes an unused import statement from a single Dart file in the Stack Wallet app. It does not change any app behavior, fix a bug, or alter security in any way. It is a routine code cleanup.

Security candidatefix(shopinbit): show step 4 submit errors as a dialogby sneurlax · c15dae48 · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

fix(shopinbit): show step 4 submit errors as a dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit changes how error messages are shown to users when a ShopinBit order submission fails. Previously, a small temporary notification banner (a 'flush bar') appeared at the bottom of the screen. Now, a centered popup dialog appears instead. There is no security change here—only a user-interface improvement to make errors more noticeable.

Security candidatefix(shopinbit): show ticket retry request errors as a dialogby sneurlax · 05d6f824 · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

fix(shopinbit): show ticket retry request errors as a dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit changes how error messages are shown to the user when a ticket retry request fails in the ShopInBit feature. Previously, a brief floating notification (a 'flush bar') appeared; now, a modal dialog box appears instead. There is no security issue here—this is purely a user-interface improvement.

Security candidatefix(shopinbit): show manual customer key set errors as a dialogby sneurlax · bc567af6 · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 16Details
Commit message · sneurlax

fix(shopinbit): show manual customer key set errors as a dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

This commit changes how an error message is shown to the user when saving a customer key in the ShopInBit settings. Instead of a temporary warning banner, it now shows a proper dialog box. It also adds a safety check to avoid a crash if the user navigates away while the dialog is open. There is no direct security vulnerability being fixed here; it is a UI/UX robustness improvement.

Security candidatefix(shopinbit): show customer key generation errors as a dialogby sneurlax · c3e5340c · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 18Details
Commit message · sneurlax

fix(shopinbit): show customer key generation errors as a dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit changes how an error message is shown to the user when key generation fails in a shopping-related settings screen. Instead of a temporary warning banner, it now shows a popup dialog. It also adds a safety check to avoid updating the screen after the user has navigated away. This is a minor UI/UX fix with no clear security impact.

Security candidatefix(shopinbit): show car research invoice errors as a dialogby sneurlax · 08683135 · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 17Details
Commit message · sneurlax

fix(shopinbit): show car research invoice errors as a dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 17/100

This commit changes how invoice creation errors are shown to users in a car-research shopping feature. Instead of a brief floating warning bar, the app now displays a proper dialog box with the error message. This is a user-experience improvement, not a security fix, and it does not change how errors are handled or logged.

Security candidatefix(shopinbit): show car research request retry errors as a dialogby sneurlax · d1e0a72a · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

fix(shopinbit): show car research request retry errors as a dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit changes how an error message is shown to the user when a car research payment retry fails. It swaps a temporary floating notification bar for a popup dialog. There is no security issue here—this is purely a user-interface improvement.

Security candidatefix(shopinbit): show car research payment processing errors as a dialogby sneurlax · e691f22b · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

fix(shopinbit): show car research payment processing errors as a dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit changes how error messages are shown to users when a car-research payment fails in the Stack Wallet app. It replaces small floating notification banners with larger popup dialogs so users are more likely to notice the problem. There is no security fix here—only a user-interface improvement.

Security candidatefix(shopinbit): show payment-check API errors as a blocking dialogby sneurlax · cf0b4437 · May 28, 2026 · 1 fileMessage 62 · AdequateInformational 21Details
Commit message · sneurlax

fix(shopinbit): show payment-check API errors as a blocking dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 21/100

This commit changes how payment-check errors are shown to the user in the ShopInBit feature. Previously, a brief warning banner (a 'flush bar') appeared. Now, a blocking dialog box appears that the user must acknowledge before continuing. This is a user-experience and reliability improvement, not a fix for a code vulnerability. It makes it harder for a user to miss an important payment failure message, but it does not change how payments are processed or how errors are generated.

Security candidatefix(shopinbit): render locked country as disabled text fieldby sneurlax · 1659182d · May 27, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

fix(shopinbit): render locked country as disabled text field

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a straightforward user-interface cleanup. It replaces a custom read-only 'Country' field in the ShopInBit shipping screen with a shared 'DetailItem' widget so the locked country is rendered as a disabled text field. There is no security change: the country was already locked and uneditable before, and it remains locked and uneditable after.