SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1038 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

334security candidates400second-pass queue734AI analyses
66commits · 30 days
160commits · 60 days
606commits · 180 days
1009commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax339158241062
julian347112269044
Julian18939136042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 13 minutes ago

Low 35 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1450 from Ez3kiel-dev/fix/xelis-integration

This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…

Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
ad945d43by Julian+4298−162634 files
No security note in commit
Low 32 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/xelis-integration

This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …

New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
b0e5d35aby Julian+2678−330378 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefeat(ui): extend AdaptiveTextField and migrate travel form to use themby sneurlax · 248c83cb · May 22, 2026 · 2 filesMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

feat(ui): extend AdaptiveTextField and migrate travel form to use them

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a routine user-interface refactor. It extends a shared text-field widget so it can replace a travel-form-specific text field, and updates the travel booking form to use the shared widget. There is no security-relevant change visible in the diff.

Security candidatefix(ui): adjust ShopinBit travel form on desktop and mobileby sneurlax · 23746e3d · May 22, 2026 · 2 filesMessage 62 · AdequateInformational 15Details
Commit message · sneurlax

fix(ui): adjust ShopinBit travel form on desktop and mobile

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a purely cosmetic user-interface tweak for a travel booking form inside the Stack Wallet app. It rounds the corners of text boxes, increases spacing between fields, and changes one placeholder label from an example to 'Destination city.' There is no security relevance.

AI review queuedhide/disable coin control view for salvium as the underlying library doesn't fully support itby julian · 75733fe4 · May 22, 2026 · 5 filesMessage 50 · ThinInformational 21Details
Commit message · julian

hide/disable coin control view for salvium as the underlying library doesn't fully support it

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit hides the 'coin control' feature for Salvium wallets in the Stack Wallet app. Coin control lets users manually choose which coins (transaction outputs) to spend. The change blocks Salvium wallets from using that feature because the underlying library doesn't fully support it. It is a compatibility/bug-avoidance change rather than a fix for an active security flaw, but disabling the unsupported path reduces the chance of users accidentally creating broken or mis-handled transactions.

Security candidatehandle here instead of https://github.com/cypherstack/stack_wallet/pull/1345 due to conflicts that I don't want to deal withby julian · 6e9c01ed · May 22, 2026 · 1 fileMessage 70 · AdequateInformational 0Details
Commit message · julian

handle here instead of https://github.com/cypherstack/stack_wallet/pull/1345 due to conflicts that I don't want to deal with

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 0/100

There is not enough information to evaluate this commit. The title and message only say it is handling another pull request's changes here due to merge conflicts. No actual code diff was provided, and no verified references describe what the change does or whether it has security relevance.

AI review queuedfix: dart formattingby Cyrix126 · 98633ecc · May 22, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · Cyrix126

fix: dart formatting

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only reformats Dart source code to match style rules. It changes whitespace, line breaks, and indentation but does not alter any program logic, behavior, or security controls.

AI review queuedflatpak: grant filesystem access to ~/.stackwalletby Dan Miller · f2c52c20 · May 22, 2026 · 1 fileMessage 50 · ThinLow 26Details
Commit message · Dan Miller

flatpak: grant filesystem access to ~/.stackwallet

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 26/100

This change updates the Flatpak packaging for Stack Wallet so the app can read and write files in a folder named .stackwallet inside the user's home directory. Flatpak apps normally run in a sandbox with limited access to the rest of the computer. The commit message only says this is being added to grant filesystem access to that folder; it does not say this fixes a security bug or that any vulnerability was reported.

AI review queuedAdd flatpak build job to CIby Dan Miller · c6af22c9 · May 22, 2026 · 5 filesMessage 45 · ThinInformational 16Details
Commit message · Dan Miller

Add flatpak build job to CI

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit adds a new automated build step that produces a Flatpak installer for the Linux version of Stack Wallet. It does not change the wallet's code, cryptography, or how user funds are handled. It is a packaging and release-pipeline change, not a security fix or vulnerability.

AI review queuedfix: bandaid fix for race condition when checkElectrumAdapter is called concurrently. The architecture of ElectrumXClient and ClientManager needs to be revisited and refactored in a safer wayby julian · 6182fbd7 · May 21, 2026 · 1 fileMessage 62 · AdequateLow 45Details
Commit message · julian

fix: bandaid fix for race condition when checkElectrumAdapter is called concurrently. The architecture of ElectrumXClient and ClientManager needs to be revisited and refactored in a safer way

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Low 45/100

This commit adds a temporary lock (mutex) around a function called checkElectrumAdapter in a cryptocurrency wallet app. The developer notes that without the lock, the function could be run by multiple parts of the app at the same time, causing a race condition. The race could potentially lead to duplicate or conflicting Electrum server connections, connection errors, or unexpected behavior when managing which server client is active. The fix is described as a 'bandaid,' meaning the underlying design still needs a safer rewrite.

AI review queuedadd pre build time features optionsby julian · 52350461 · May 21, 2026 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · julian

add pre build time features options

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply adds two new optional features, 'shopinBit' and 'cakePay', to the list of features that can be turned on or off at build time. It does not change any runtime behavior, security settings, or user data handling. There is no indication of a security issue.

Security candidatefix(ui): formattingby julian · 5de3119e · May 21, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · julian

fix(ui): formatting

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit only reformats a single Dart map literal from multi-line to single-line style. It changes whitespace and line breaks, not program logic, data handling, or security behavior. There is no security relevance.

Security candidaterefactor(ui): generalized external link launch request dialogby julian · e5d418f0 · May 21, 2026 · 5 filesMessage 62 · AdequateInformational 17Details
Commit message · julian

refactor(ui): generalized external link launch request dialog

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 17/100

This commit is a routine user-interface cleanup. It replaces several copies of the same 'Are you sure you want to open this external link?' warning dialog with one shared version. The behavior shown to the user—asking permission before opening a web link in the device's browser—does not change. There is no indication this fixes a security bug.

Security candidatefix(ui): clean up as much as possible without fully refactoringby julian · cbad601b · May 20, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · julian

fix(ui): clean up as much as possible without fully refactoring

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a purely cosmetic UI cleanup for a ticket detail screen in the Stack Wallet app. It swaps some text widgets for selectable text, adjusts padding and borders, and replaces a custom container with a reusable rounded container. There is no security-relevant change.

Security candidatefix(ui): provider access after widget disposedby julian · 73269aff · May 20, 2026 · 1 fileMessage 57 · ThinInformational 16Details
Commit message · julian

fix(ui): provider access after widget disposed

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

This is a small UI bug fix in a Flutter settings screen. It moves an asynchronous key-loading call so it only happens while the screen widget is still active, preventing a harmless 'provider accessed after widget disposed' warning. There is no direct evidence this is a security vulnerability.

Security candidatefix(ui): cakepay desktop navigation mostlyby julian · 2c81a674 · May 20, 2026 · 8 filesMessage 57 · ThinInformational 18Details
Commit message · julian

fix(ui): cakepay desktop navigation mostly

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100

This commit is a user-interface cleanup for the CakePay gift-card flow on desktop. It replaces separate mobile/desktop navigation paths with a single nested navigator inside a dialog, swaps some loading indicators, and changes how order details receive their data (passing the whole order object instead of just an order ID). There is no clear security bug being fixed, and nothing in the diff suggests attackers could exploit it.

Security candidatefix(ui): adjust button width to prevent overflow on min window widthby julian · beed5b62 · May 20, 2026 · 1 fileMessage 79 · AdequateInformational 15Details
Commit message · julian

fix(ui): adjust button width to prevent overflow on min window width

79/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Explains rationale or failure mode✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
memory safetyauthentication path
AI analysis · Informational 15/100

This commit is a purely cosmetic UI fix. It narrows three buttons on a desktop shopping page so they no longer overflow the window at the application's minimum width. There is no security relevance.

Security candidatefix(ui): don't display UTC timeby julian · 5fa4bcc1 · May 20, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · julian

fix(ui): don't display UTC time

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit changes a single screen in the Stack Wallet app so that timestamps are shown in the user's local time instead of UTC. It is a minor user-interface improvement with no security relevance.

Security candidatefix(ui): chat bubble colorsby julian · f1b14f11 · May 20, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · julian

fix(ui): chat bubble colors

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit only changes the colors used for chat message bubbles in a customer-support ticket screen. It swaps hard-coded or theme-mismatched colors for theme-consistent primary/secondary button colors so the chat looks correct in light and dark modes. There is no security relevance.

Security candidaterefactor(ui): keep functionality the same as much as possible but refactor widget tree clean up and styling fixesby julian · 0f0d582f · May 20, 2026 · 4 filesMessage 62 · AdequateInformational 15Details
Commit message · julian

refactor(ui): keep functionality the same as much as possible but refactor widget tree clean up and styling fixes

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a user-interface cleanup for the ShopInBit ticket and request screens. It swaps some dialog and container widgets, extracts repeated list-row code into helper widgets, and changes how a loading spinner is shown during ticket sync. There is no indication of a security fix or vulnerability being addressed.

Security candidaterefactor(db): use drift/sqlite instead of isarby julian · f357b4a7 · May 20, 2026 · 28 filesMessage 57 · ThinInformational 11Details
Commit message · julian

refactor(db): use drift/sqlite instead of isar

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 11/100

This commit is a routine internal refactor that moves the app's shared database code from one location to another and switches some ShopInBit ticket data from the Isar database to a Drift/SQLite database. It is not described as a security fix, and the visible changes do not introduce obvious ways for an attacker to steal funds or data. The main risk is that any database migration could accidentally lose or corrupt user data, but nothing in the supplied diff proves that happened.

Security candidatefix(ui): check correct contextby julian · fd53f9fe · May 19, 2026 · 1 fileMessage 57 · ThinInformational 16Details
Commit message · julian

fix(ui): check correct context

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100

A one-line UI fix changes a safety check from 'if the widget is still in the tree' to 'if the Flutter BuildContext is still valid' before showing a temporary info banner. This is a routine Flutter correctness fix that prevents a possible crash when a screen is closed while the banner is being prepared. There is no direct evidence in the commit that this is a security issue.

Security candidatefix(ui): button spacingby julian · 9dad75d7 · May 19, 2026 · 1 fileMessage 40 · ThinInformational 15Details
Commit message · julian

fix(ui): button spacing

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit only adjusts the spacing between buttons on a settings screen, making gaps slightly wider on desktop and in a couple of places on mobile. It is a visual user-interface tweak with no security relevance.

Security candidatefix(ui): clean up flow logic and state issuesby julian · 1c6ffa9a · May 19, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · julian

fix(ui): clean up flow logic and state issues

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a routine UI cleanup in the Stack Wallet app's ShopInBit settings screen. It removes an extra 'verify your key' dialog that was managed inside the same screen and turns it into a separate, self-contained dialog widget. The visible behavior—asking the user to re-enter their saved customer key before continuing—appears unchanged. There is no clear security fix or vulnerability here; it looks like a code-quality refactor.

Security candidatechore: add some toString()sby julian · 8ed3d339 · May 19, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · julian

chore: add some toString()s

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit adds human-readable toString() methods and helper toMap() methods to three data classes that describe shopping tickets. It only changes how objects look when printed or logged; it does not alter how data is stored, transmitted, validated, or protected. There is no security issue visible in the change.

Security candidaterefactor(shopinbit): Store shop in bit settings using Drift, use providers for drift shared db and shopinbit service, and some general clean up and tweaksby julian · fa5fa812 · May 19, 2026 · 29 filesMessage 62 · AdequateInformational 19Details
Commit message · julian

refactor(shopinbit): Store shop in bit settings using Drift, use providers for drift shared db and shopinbit service, and some general clean up and tweaks

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 19/100

This commit is a routine refactor of the ShopinBit feature in Stack Wallet. It moves settings like whether the user accepted guidelines, completed setup, and their display name from the previous storage mechanism into a Drift/SQLite database, and switches UI code to use Riverpod providers for that database and the ShopInBit service. The diff shows no obvious malicious intent, no new network calls, no weakening of encryption, and no exposed secrets. It is primarily a code-quality and architecture change.

Security candidateFix Android APK signing (keystore format) in CI build jobby Dan Miller · ec2cabc3 · May 19, 2026 · 1 fileMessage 50 · ThinInformational 18Details
Commit message · Dan Miller

Fix Android APK signing (keystore format) in CI build job

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarydocumentation-only discount
AI analysis · Informational 18/100

This commit fixes a small but real bug in the automated build pipeline for Android. Previously, the build script used `echo` to write the signing keystore from a base64-encoded secret. If the secret was empty or missing, `echo` would still create an empty file and the build would continue, potentially producing an unsigned or broken APK. The fix uses `printf '%s'` to avoid adding a trailing newline, and adds a check that aborts the build if the keystore secret is empty. This is a reliability and correctness improvement rather than a direct security vulnerability in the app itself.