SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1038 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

334security candidates400second-pass queue734AI analyses
66commits · 30 days
160commits · 60 days
606commits · 180 days
1009commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax339158241062
julian347112269044
Julian18939136042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 59 minutes ago

Low 35 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1450 from Ez3kiel-dev/fix/xelis-integration

This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…

Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
ad945d43by Julian+4298−162634 files
No security note in commit
Low 32 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/xelis-integration

This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …

New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
b0e5d35aby Julian+2678−330378 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefix(shopinbit): keep delivery country consistent in shipping viewby sneurlax · 9f558ea2 · May 27, 2026 · 1 fileMessage 62 · AdequateInformational 18Details
Commit message · sneurlax

fix(shopinbit): keep delivery country consistent in shipping view

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit is a UI/UX fix for the Stack Wallet app's ShopinBit integration. It makes sure the delivery country shown during shipping matches the country that was used to price the order. It does not appear to be a security fix and does not introduce obvious security risks.

Security candidatefix(shopinbit): don't pop the whole nav stack when PAY NOW has no addressby sneurlax · b4cb8949 · May 27, 2026 · 1 fileMessage 77 · AdequateInformational 22Details
Commit message · sneurlax

fix(shopinbit): don't pop the whole nav stack when PAY NOW has no address

Auto stash before rebase of "josh/fixes"

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
authentication path
AI analysis · Informational 22/100

This commit fixes a bug in Stack Wallet's ShopInBit payment screen. Previously, if the user tapped 'PAY NOW' before the payment address had loaded, the app would abruptly close the entire navigation stack (effectively kicking the user out of the checkout). Now it shows a warning message, attempts to recover the missing payment details from the server, and continues polling instead of popping screens.

Security candidatefix(ui): pre-load ShopInBit payment info instead of in-page spinner overlayby sneurlax · fc57247d · May 27, 2026 · 6 filesMessage 62 · AdequateInformational 17Details
Commit message · sneurlax

fix(ui): pre-load ShopInBit payment info instead of in-page spinner overlay

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 17/100

This commit is a user-interface refactor for the ShopInBit checkout flow. It moves the loading of payment information earlier in the process so the payment screen appears already filled in, rather than showing a spinner after the page opens. There is no direct security fix here, but the change touches code that handles invoice creation, polling, and route arguments for a third-party payment integration.

Security candidaterefactor(shopinbit): await send-from navigation before returning trueby sneurlax · 574392ab · May 27, 2026 · 3 filesMessage 62 · AdequateLow 26Details
Commit message · sneurlax

refactor(shopinbit): await send-from navigation before returning true

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 26/100

This commit fixes a timing bug in the Stack Wallet app's ShopInBit payment flow. Previously, the code that launches the in-wallet send screen was called without waiting for it to finish, and the app could continue running logic on a screen that had already been closed. The change makes the navigation awaitable and adds a check to stop further work if the widget is no longer visible. This is a correctness and stability fix that could prevent UI glitches or inconsistent order state, but it is not a clear-cut security vulnerability.

Security candidatefix: use more SW-standard iconsby sneurlax · cd2a1b88 · May 27, 2026 · 5 filesMessage 57 · ThinInformational 15Details
Commit message · sneurlax

fix: use more SW-standard icons

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit only swaps out some on-screen icons in the Stack Wallet app. It replaces standard Flutter icons with custom SVG-based icons in a few payment and order history screens. There is no security change here—just a visual consistency update.

Security candidatefix: guard against non-ETH TRON addressesby sneurlax · c2bd5708 · May 27, 2026 · 3 filesMessage 57 · ThinLow 44Details
Commit message · sneurlax

fix: guard against non-ETH TRON addresses

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 44/100

This commit fixes a bug in Stack Wallet's ShopInBit payment feature. Previously, when a user chose to pay with USDT, the app assumed every USDT payment address was on the Ethereum network. If the merchant actually provided a Tron (TRC-20) USDT address, the app could still try to route the payment through an Ethereum wallet, which would send funds to the wrong kind of address and likely cause the user to lose money. The fix checks whether the payment URI is genuinely Ethereum-based before allowing an in-app Ethereum/USDT wallet payment; otherwise it forces the user to pay externally.

Security candidatefix: use CopyIconby sneurlax · 738dc1e4 · May 27, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · sneurlax

fix: use CopyIcon

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit simply swaps a generic copy icon for a custom project-specific copy icon widget in one screen of the Stack Wallet app. There is no visible security change.

Security candidaterefactor: extract shared payment flowby sneurlax · adcbf651 · May 27, 2026 · 4 filesMessage 57 · ThinInformational 15Details
Commit message · sneurlax

refactor: extract shared payment flow

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a routine code cleanup: it moves duplicated payment-handling logic from two ShopInBit screens into a single shared helper file. There is no security-relevant change visible in the diff—no new permissions, no altered validation, no changed cryptography, and no new network behavior. The shipping screen also gets a small UI tweak to allow country selection only when the order did not already arrive with a country.

Security candidateuse portable sed -i.bak in configure and version scripts from @parasewby Dan Miller · 0d3742df · May 27, 2026 · 4 filesMessage 50 · ThinInformational 15Details
Commit message · Dan Miller

use portable sed -i.bak in configure and version scripts from @parasew

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathboot or update path
AI analysis · Informational 15/100

This commit is a build-script portability cleanup. It replaces macOS-specific and Linux-specific ways of running the `sed` text-editing tool with a single cross-platform approach that works on both systems. There is no security-relevant change here.

Security candidatebump frostdart, parameterize download_all.shby Dan Miller · 744485c8 · May 27, 2026 · 7 filesMessage 45 · ThinInformational 15Details
Commit message · Dan Miller

bump frostdart, parameterize download_all.sh

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit is a build-script cleanup. It makes the pre-built crypto plugin download scripts aware of which app is being built (stack_wallet, stack_duo, or campfire) so that only the plugins needed for that app are downloaded. It also updates the frostdart plugin submodule to a newer version. There is no user-facing app change and no obvious security vulnerability introduced by the diff itself.

Security candidatefix(ui): shopinbit ticket detail review offer options stylingby julian · 4c5680f7 · May 27, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · julian

fix(ui): shopinbit ticket detail review offer options styling

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a purely cosmetic user-interface tweak. It changes how a 'Review offer' button and product text are arranged on the screen depending on whether the app is running on desktop or mobile. There is no security relevance.

Security candidatefix(ui): more navigation and layout/styling cleanupby julian · e915b025 · May 27, 2026 · 5 filesMessage 62 · AdequateInformational 15Details
Commit message · julian

fix(ui): more navigation and layout/styling cleanup

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a routine user-interface cleanup for a shopping feature inside the Stack Wallet app. It swaps some dialog widgets, adjusts button layouts, and makes desktop and mobile navigation behave the same way. There is no indication it fixes a security problem.

Security candidatefix(ui): fix keyboard covering textfield/dialog on mobileby julian · 726c21df · May 27, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · julian

fix(ui): fix keyboard covering textfield/dialog on mobile

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit fixes a minor user-interface bug in a mobile dialog. When a user opens a text field inside a dialog on a phone, the on-screen keyboard can slide up and cover the field. The change adds padding equal to the keyboard's height so the dialog shifts out of the way. There is no security relevance in the diff itself.

Security candidatefix(ui): mobile button height/sizeby julian · 571fc325 · May 27, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · julian

fix(ui): mobile button height/size

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit adjusts the height of two buttons (Cancel and Confirm) in a settings dialog so that on mobile devices the buttons use a default height instead of a fixed large height. It is purely a user-interface layout fix with no security relevance.

Security candidatechore: Log errorsby julian · 48bfd1af · May 27, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · julian

chore: Log errors

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit only adds error logging to a car-fee invoice creation screen. It does not change how user data is handled, how money moves, or how the app protects itself. It simply records more details when something goes wrong, so developers can diagnose issues later. There is no security problem here.

Security candidatefeat(shopinbit): migrate to PUT /payment for 1.0.4by sneurlax · e2306338 · May 26, 2026 · 3 filesMessage 62 · AdequateInformational 12Details
Commit message · sneurlax

feat(shopinbit): migrate to PUT /payment for 1.0.4

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 12/100

This commit updates the Stack Wallet app's integration with the ShopinBit service. It changes how a payment invoice is created: previously the app used a GET request (which could accidentally create invoices), and now it uses a PUT request after the user clicks 'PAY NOW'. This is a normal API migration to match a new ShopinBit specification version 1.0.4. There is no direct evidence in the commit of a security vulnerability being fixed or introduced.

Security candidatefix(shopinbit): GET payment first, PUT only if no live invoiceby sneurlax · 0f51d51c · May 26, 2026 · 1 fileMessage 62 · AdequateLow 32Details
Commit message · sneurlax

fix(shopinbit): GET payment first, PUT only if no live invoice

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 32/100

This commit changes how Stack Wallet's ShopInBit payment screen fetches an invoice. Previously it always created or regenerated a payment invoice with a PUT request. Now it first checks with a GET request and only creates a new invoice if no live one exists. This is a defensive fix to avoid overwriting or regenerating an existing valid invoice, which could disrupt a payment in progress or cause funds to be sent to a stale address.

Security candidatefix(shopinbit): escape non-ASCII in request bodiesby sneurlax · 48517de0 · May 26, 2026 · 1 fileMessage 62 · AdequateLow 37Details
Commit message · sneurlax

fix(shopinbit): escape non-ASCII in request bodies

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 37/100

This commit fixes a bug in the Stack Wallet app's integration with ShopInBit, a third-party shopping service. When users sent text containing non-English characters (like ± or emoji), the app encoded them incorrectly before sending over the internet. This could corrupt order details, shipping names, or item descriptions, potentially causing orders to fail or be processed with wrong information. The fix forces all special characters to be sent as safe ASCII escape sequences.

AI review queuedRevert incorrect conflict resolution.by Dan Miller · 8208fe7e · May 26, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Dan Miller

Revert incorrect conflict resolution.

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply removes a GitHub Actions workflow job that automatically packaged and published release files when a new version tag was created. It is a routine revert of a previous merge-conflict resolution and does not change any wallet code, cryptography, or user-facing security behavior.

Security candidateRevert "feat(shopinbit): backfill remote tickets into the local db on refresh"by julian · 33571449 · May 26, 2026 · 1 fileMessage 65 · AdequateLow 26Details
Commit message · julian

Revert "feat(shopinbit): backfill remote tickets into the local db on refresh"

This reverts commit 91dc8229c456aeed2795b23e51e788963241778e.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
authentication path
AI analysis · Low 26/100

This commit undoes a recent feature that copied remote customer support tickets into the app's local database during refresh. The revert removes the backfill step, so tickets created on another device or the web dashboard will no longer automatically appear in the local database. The change is described as a routine revert, not a security fix, and no public references explain why it was reverted.

Security candidatefix(ui): nav bugby julian · d0a3ee9c · May 26, 2026 · 1 fileMessage 40 · ThinInformational 11Details
Commit message · julian

fix(ui): nav bug

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 11/100

This is a small user-interface navigation fix. The developer removed an unused wrapper widget and now directly calls the close action when a desktop user clicks a button. There is no indication this change affects security, user data, or wallet funds.

Security candidatefeat(shopinbit): recover requestDescription and detect travel on restoreby sneurlax · ab93fe03 · May 26, 2026 · 1 fileMessage 62 · AdequateInformational 18Details
Commit message · sneurlax

feat(shopinbit): recover requestDescription and detect travel on restore

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit fixes a small data-recovery bug in Stack Wallet's integration with the ShopInBit shopping service. When a user restored their wallet or reopened an existing support ticket, the app had been storing an empty description and could not tell whether the ticket was for travel or the general concierge service. The patch recovers the original request text from the first message and uses a simple text pattern to detect travel bookings. There is no sign this exposes user funds, private keys, or allows remote attacks; it is a correctness improvement for how existing ticket data is displayed and categorized.

Security candidatefeat(shopinbit): backfill remote tickets into the local db on refreshby sneurlax · 91dc8229 · May 26, 2026 · 1 fileMessage 62 · AdequateInformational 12Details
Commit message · sneurlax

feat(shopinbit): backfill remote tickets into the local db on refresh

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 12/100

This commit adds a feature that downloads a user's complete order/ticket list from a remote service and saves any missing entries into the local database when the app refreshes. It is a routine data-synchronization improvement, not a security fix.

Security candidatefeat(shopinbit): implement fetchAllForCustomerKeyby sneurlax · e7073cb1 · May 26, 2026 · 1 fileMessage 47 · ThinInformational 15Details
Commit message · sneurlax

feat(shopinbit): implement fetchAllForCustomerKey

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit finishes a previously stubbed-out feature that downloads a customer's support/order tickets from an external service (ShopinBit) and stores them locally in the wallet's database. It is a normal feature implementation. There is no direct evidence in the commit that it fixes a security vulnerability, but it touches sensitive data (customer key, ticket messages) and makes network calls, so a defensive review checks for obvious safety issues.

Security candidateadd shopinbit fetch all from remote function stubby julian · 59a2eeaf · May 26, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · julian

add shopinbit fetch all from remote function stub

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit adds a placeholder (stub) function for a future feature. It does not contain any working code, does not change how the app currently behaves, and introduces no security issue. The new function immediately throws an error if called, which is normal for unfinished development.