Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
51/100 average clarity
33Strong · 80–100
316Adequate · 60–79
513Thin · 40–59
191Opaque · 0–39
33security candidates with opaque commit messaging
This commit fixes a mobile UI bug where pressing Cancel on a 'building transaction' dialog accidentally closed one too many screens. The fix moves the responsibility for closing the dialog into each screen's cancel handler, and prevents er…
No security-relevant signals in the diffUI-only navigation and error-dialog suppression changesNo cryptographic, authentication, authorization, or data-handling changes
This commit is a routine merge from the project's staging branch into a feature branch. The visible code changes fix small UI/UX bugs in Stack Wallet's send screens: clearing an internal address-validation cache when the form is reset, mak…
Clearing stale address-provider state on form reset reduces the risk of stale validation data influencing a subsequent transactionFee-form caching prevents repeated network calls and accidental fee UI flicker/state races on rebuildQR scan buttons are UX additions with no visible parser/validation logic changes
This commit fixes a desktop wallet bug where the send-fee form would repeatedly re-fetch fee estimates on every screen rebuild, wasting resources and possibly flickering. It now caches the fee estimate and only retries if the previous fetc…
No security-relevant signals present in diff or commit metadataChange is a UI/UX performance and reliability improvement
This commit merges a feature branch into another work-in-progress branch. It adds QR-code scanning buttons to two desktop token send screens and resets an internal address-validation state variable when the send form is cleared. There is n…
State reset added to clearForm() to avoid stale validation dataNew QR scan entry points in token send flows (UI feature, not a vulnerability signal)
This change fixes a UI state bug in the cryptocurrency wallet's send form. When a user clears the send form, the app now also resets whether the entered address is considered valid. Without this fix, the form could incorrectly keep showing…
UI state desynchronization between form field and validity indicatorPotential user confusion from stale valid-address stateNo input validation, cryptographic, or network-layer changes
This commit adds a QR code scanner button to two desktop cryptocurrency send forms. It is a straightforward user-interface feature addition with no apparent security relevance.
This commit adds a missing QR code scan button to two desktop token send screens in the Stack Wallet app. It is a straightforward user-interface fix that restores a feature already present on mobile and other send views; there is no indica…
This commit is purely a code-formatting cleanup. It changes line breaks and indentation in four user-interface files so the code is easier to read, but it does not change what the app actually does. There is no security relevance.
This commit fixes a UI bug in the desktop version of Stack Wallet where the send amount could be lost while the app was trying to estimate transaction fees. The fix keeps the amount 'alive' in memory so fee estimation does not accidentally…
State lifecycle issue in UI provider could lead to loss of user inputFix prevents fee estimation from silently resetting send amount to zeroNo cryptographic, authentication, or network security changes present
This commit updates the Stack Wallet app so that when a single payment is broken into multiple cryptocurrency transactions, the user sees a clear warning on the confirmation screen. It also changes the app's internal record-keeping to hand…
UI now warns users when a payment will be split into multiple on-chain transactionsInternal transaction model changed from single txid to list of txidsMultiple confirmation flows updated to iterate over all txids for notes and trade lookups
This commit fixes a performance bug in the desktop version of Stack Wallet where the app repeatedly re-fetched Bitcoin-style fee rates every time the on-screen fee form rebuilt. The change caches the fee result and only fetches again if th…
Unnecessary repeated network requests reducedFuture result cached to avoid re-execution on widget rebuildError path clears cache to allow retry
This commit fixes a UI state bug in Stack Wallet's send form. When a user clears the send form, the wallet now also resets whether the entered address is considered valid. Without this fix, the form could incorrectly keep showing an old ad…
Stale UI state after form resetAddress validity not synchronized with address field resetPotential UI confusion leading to incorrect send confirmation
This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…
Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …
New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …
This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…
Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…
Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…
New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…
New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…
Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
AI review queueddo not show anonymize all button in view only walletsby julian · 37293141 · Oct 10, 2025 · 1 fileMessage 50 · ThinLow 29Details
Commit message · julian
do not show anonymize all button in view only wallets
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100
This commit hides an 'anonymize all' button in cryptocurrency wallets that are in view-only mode. View-only wallets cannot spend or move funds, so the button was likely non-functional or confusing. The change is a UI cleanup rather than a fix for a vulnerability that could be directly exploited.
AI review queueddisplay salvium tx type in transaction detailsby julian · b173841a · Oct 9, 2025 · 5 filesMessage 45 · ThinInformational 15Details
Commit message · julian
display salvium tx type in transaction details
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a straightforward user-interface improvement: it adds a new 'Type' field to the transaction-details screen for Salvium cryptocurrency transactions. There is no evidence in the diff of any security bug, vulnerability, or behavior change that could put user funds or data at risk.
Security candidatesal testnet support using localhostby julian · cf74749b · Oct 9, 2025 · 5 filesMessage 45 · ThinInformational 18Details
Commit message · julian
sal testnet support using localhost
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 18/100
This commit adds testnet support for the Salvium cryptocurrency in Stack Wallet. It lets developers or users create and use Salvium wallets on a local test network (localhost) instead of the real main network. There is no obvious security bug in the change itself, but it does add a hardcoded localhost node and changes how wallet network types are selected. The commit does not describe any security issue, and no independent security report is supplied.
AI review queuedclean up sal relatedby julian · 9c43f13c · Oct 9, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · julian
clean up sal related
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is a small cleanup of a code template used for the Salvium cryptocurrency integration. It updates an error message, removes some unnecessary fallback values, and fixes how transaction 'type' data is passed by using the underlying value instead of an object. There is no clear security problem visible in the diff itself.
AI review queuedfix preview button label (refactor mwc tx type provider)by julian · 63e6fbf1 · Oct 9, 2025 · 4 filesMessage 50 · ThinInformational 18Details
Commit message · julian
fix preview button label (refactor mwc tx type provider)
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100
This commit is a code cleanup and UI consistency change for the Stack Wallet app. It replaces repeated checks of a global Mimblewimblecoin transaction method with a single wallet-scoped helper. The visible effect is making sure the preview/send button shows the correct label ("Create slatepack" vs "Preview") based on whether the current wallet is using slatepack transactions. There is no obvious security vulnerability in the diff itself.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100
This commit adds a new user interface screen for creating Salvium staking transactions in the Stack Wallet app. It is purely a UI feature: it adds a text box to enter an amount, a Preview button, and wiring to route the user to the existing transaction confirmation flow. There is no indication in the commit that it fixes a security bug or introduces a vulnerability.
AI review queuedfix xmr/wow interfacesby julian · 015ce8a4 · Oct 9, 2025 · 7 filesMessage 28 · OpaqueLow 32Details
Commit message · julian
fix xmr/wow interfaces
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 32/100
This commit refactors how the Monero and Wownero wallet code passes wallet objects around. Previously, many functions looked up a live wallet instance using only a wallet ID string, which could lead to the wrong wallet being used or a missing wallet being treated as present. The change makes wallet code explicitly carry and check a typed wallet object before calling sensitive operations such as viewing balances, creating transactions, and sending funds. It is a defensive fix that reduces the risk of accidental cross-wallet operations or crashes, but the commit message does not frame it as a security patch.
AI review queuedconst constructorsby julian · 7ca16980 · Oct 9, 2025 · 4 filesMessage 18 · OpaqueInformational 15Details
Commit message · julian
const constructors
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only adds Dart 'const' constructors to a few internal interface classes and changes their instantiation sites to use 'const'. It is a code-quality/performance micro-optimization with no visible security relevance.
AI review queuedfix salvium interface and add salvium staking tx callby julian · 3375632a · Oct 9, 2025 · 6 filesMessage 50 · ThinLow 27Details
Commit message · julian
fix salvium interface and add salvium staking tx call
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 27/100
This commit updates the Salvium cryptocurrency wallet integration in Stack Wallet. It mainly changes how wallet objects are passed around internally (using a new WrappedWallet object instead of a wallet ID string) and adds support for creating Salvium staking transactions. There is no clear security fix or vulnerability being patched in the visible code changes.
Security candidateupdate frostdart with macos xcframeworkby Julian · 4bf95c62 · Oct 8, 2025 · 1 fileMessage 45 · ThinInformational 2Details
Commit message · Julian
update frostdart with macos xcframework
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 2/100
This commit appears to update a pre-built macOS framework file inside the frostdart crypto plugin. No source code diff is available, and the commit message gives no indication of a security fix or vulnerability. It looks like a routine build artifact update for macOS compatibility.
AI review queuedstupid hack. One day epic and mwc will be proper libraries...by julian · 34cb2b53 · Oct 8, 2025 · 7 filesMessage 30 · OpaqueInformational 18Details
Commit message · julian
stupid hack. One day epic and mwc will be proper libraries...
30/100 · OpaqueMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body! Contains work-in-progress language
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 18/100
This commit changes build scripts so that two cryptocurrency wallet libraries (Epic Cash and MWC) are only bundled into the main Stack Wallet app, not into the lighter Campfire and Stack Duo variants. It is a build-packaging tweak, not a fix for an active security flaw. There is no evidence it addresses a vulnerability.
AI review queuedclass name fixby Julian · da07f0de · Oct 7, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Julian
class name fix
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This is a simple code cleanup: a Dart template file had a class named after the wrong project ('MwebdServerInterfaceImpl' instead of 'LibXelisInterfaceImpl'), and the patch renames it to match the Xelis (XEL) wallet integration it actually implements. There is no security-relevant change.
AI review queuedupdate macos build filesby Julian · 41f94a1c · Oct 7, 2025 · 4 filesMessage 28 · OpaqueInformational 15Details
Commit message · Julian
update macos build files
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit updates macOS build configuration files for a Flutter wallet app. It removes an old dependency lock file, raises the minimum macOS version from 10.14 to 10.15, and cleans up references to several native libraries (such as frostdart, flutter_libepiccash, isar_flutter_libs, and wakelock_macos) from the Xcode project template. There is no code change that introduces a security vulnerability or fixes an obvious one. It appears to be routine build maintenance.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 4/100
This commit updates a sub-project dependency called flutter_libmwc to include a macOS build fix. The title mentions a 'macos xcfw fix' (likely a macOS XCFramework build issue). There is no diff available and no description suggesting a security problem. It appears to be a routine build/dependency maintenance change.
AI review queuedupdate gitignoreby Julian · a734654c · Oct 7, 2025 · 6 filesMessage 18 · OpaqueInformational 15Details
Commit message · Julian
update gitignore
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only updates the project's ignore rules and removes auto-generated Flutter plugin registration files from version control. It does not change any application code, cryptographic logic, or user-facing behavior. There is no security issue here.
AI review queuedupdate ios build filesby Julian · 9fd474dc · Oct 7, 2025 · 6 filesMessage 28 · OpaqueInformational 21Details
Commit message · Julian
update ios build files
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 21/100
This commit updates iOS build configuration files. The most notable change is the removal of debug code that called a function named `get_mnemonic()` and printed its output in the iOS app startup file. A mnemonic is the secret recovery phrase for a cryptocurrency wallet, so printing it could expose sensitive data during development or debugging. The commit also removes old references to an Epic Cash wallet library, deletes a generated Podfile.lock, and adjusts Xcode scheme settings. There is no evidence this was a remotely exploitable vulnerability, but it does remove a potentially unsafe debug practice.
AI review queuedfix missed xelis importby julian · 661e3f86 · Oct 7, 2025 · 3 filesMessage 28 · OpaqueInformational 19Details
Commit message · julian
fix missed xelis import
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 19/100
This commit is a routine code cleanup for the Xelis cryptocurrency support. It moves the logic that checks whether a Xelis network node is reachable out of a general test file and into a generated interface file, while also fixing a missing import. There is no indication this change fixes a security vulnerability or introduces one; it appears to be a normal refactoring/bug-fix for build or import correctness.
AI review queuedremove unused codeby julian · cef53858 · Oct 7, 2025 · 4 filesMessage 28 · OpaqueInformational 15Details
Commit message · julian
remove unused code
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit simply deletes four unused files that handled Tezos cryptocurrency data fetching and account/transaction model classes. There is no indication this fixes or introduces a security problem; it is routine code cleanup.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 35/100
This commit makes the Tor privacy feature optional and configurable across the Stack Wallet app. It adds feature-gating so that Tor-related code, UI elements, and network routing are only active when the app configuration explicitly enables Tor. Most of the visible changes are formatting and minor refactorings; the substantive change is architectural, not a direct security fix.
AI review queuedadd tor optino to app configby julian · ce22845a · Oct 7, 2025 · 4 filesMessage 45 · ThinInformational 15Details
Commit message · julian
add tor optino to app config
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit adds a new 'tor' option to the app's feature configuration. It is a straightforward feature-flag change that enables Tor support in three app variants (Campfire, Stack Duo, Stack Wallet). There is no indication of a security vulnerability or bug fix.
AI review queuedfix xmr rpc importby julian · b127e8e7 · Oct 7, 2025 · 1 fileMessage 28 · OpaqueInformational 17Details
Commit message · julian
fix xmr rpc import
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100
This commit moves a Monero cryptocurrency library dependency (monero_rpc) from an optional, commented-out XMR-only block to the always-included dependencies section of a Flutter package configuration template. On its own, this is a build/template fix rather than a direct security vulnerability. It could slightly widen the software's attack surface by ensuring the Monero RPC code is always compiled in, but there is no evidence in the commit of an exploitable flaw.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 28/100
This commit refactors how the Stack Wallet app talks to the Xelis cryptocurrency library. Instead of importing the Xelis package directly throughout the app, it introduces a new internal interface layer (`libXelis`) that wraps the Xelis package. The main visible change is making this Xelis support optional at build time, controlled by a code-generation template. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be an architectural/build change.
AI review queuedimplement optional import of flutter_libsparkmobileby julian · 5f12db24 · Oct 6, 2025 · 9 filesMessage 50 · ThinLow 27Details
Commit message · julian
implement optional import of flutter_libsparkmobile
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 27/100
This commit refactors how the Stack Wallet app uses the Firo Spark cryptography library. Instead of directly importing flutter_libsparkmobile everywhere, it introduces a generated interface wrapper so the library can be optionally included or excluded at build time. Most of the diff is code reformatting and replacing direct library calls with calls through the new wrapper. There is no obvious security bug in the diff itself, but the change touches sensitive wallet code (address generation, transaction signing, coin identification, fee estimation) and the generated template has placeholder error paths when Firo is not enabled.
AI review queuedimplement optional import of frostdartby julian · 69d143c2 · Oct 6, 2025 · 22 filesMessage 45 · ThinLow 34Details
Commit message · julian
implement optional import of frostdart
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 34/100
This commit refactors how the Stack Wallet app talks to its FROST (multisignature) cryptography library. It replaces direct calls to a concrete 'Frost' service with calls through a new 'frostInterface' abstraction, and makes the underlying frostdart package import optional. The change is mostly architectural: it enables building the app without the FROST library present, and centralizes the interface. There is no direct evidence in the diff of a security vulnerability being fixed; it is a code-organization and build-flexibility change.
AI review queuedfix package importby julian · c51e7842 · Oct 6, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · julian
fix package import
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit only changes how one file imports another file inside the same project. It replaces a package-style import with a relative-path import and reformats the code. There is no security-relevant change.