TZ
← All projectsTrezor

Trezor firmware

Firmware monorepo for Trezor One, Model T, and Safe devices.

BitcoinHardware walletsNormal
Repository coverage

2650 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

915security candidates307second-pass queue512AI analyses
338commits · 30 days
577commits · 60 days
1352commits · 180 days
2649commits · 365 days
Backfill bands
Aug 5 → Feb 61298 seen115 candidatesComplete
Feb 6 → Jun 6775 seen58 candidatesComplete
Jun 6 → Jul 6217 seen13 candidatesComplete
Jul 6 → Aug 5360 seen54 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

66/100 average clarity
470Strong · 80–100
1316Adequate · 60–79
859Thin · 40–59
5Opaque · 0–39
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Jakub Janků1998184
Martin Pastyřík2385173
Roman Zeyde56617695071
tychovrahe29210453061
cepetr1968228059
Ioan Bizău2307647059
obrusvit2137631064
M1nd3r2067139071
Lukas Bielesch846740067
PrisionMike945950073
Martin Milata1744625063
Ondřej Vejpustek953422060
Analysis record

Published AI watches

Last scanned 5 minutes ago

Informational 18 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): remove sha1 from regular FW

This commit removes the SHA-1 hashing function from the regular Trezor firmware. SHA-1 is an old, weak hash algorithm that is no longer considered secure for sensitive uses. The change deletes the code that exposes SHA-1 to apps running on…

Removal of a deprecated cryptographic primitive (SHA-1) from the firmware API surfaceReduction of attack surface and prevention of future misuse of a collision-vulnerable hashNo direct vulnerability patch or memory-safety bug is present in the diff
16d15774by M1nd3r+0−2006 files
No security note in commit
Low 27 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(crypto): pass static public key to `noise_xxpsk3_*_init()`

This commit changes how a cryptographic library sets up secure connections. Previously, the code automatically calculated the public key from the private key. Now, the caller must provide the public key directly. This is a code-quality ref…

Cryptographic key handling changed: public key is now supplied rather than derivedPotential reduction of key-mismatch risk if caller provides correct public keyNew null-pointer check added for static_public_key
1b3128a4by Ondřej Vejpustek+20−92 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(crypto): change order of parameters

This commit simply reorders the arguments of an internal function called dh() and updates every place that calls it. The actual math and security behavior are unchanged; it is a code cleanup with no security effect.

33a119eeby Ondřej Vejpustek+15−151 file
No security note in commit
Informational 15 AI analysisMessage 47 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(crypto): prefix enums

This commit simply renames two groups of internal status labels (called enums) in the Trezor firmware's cryptographic code. The old names like WAITING_FOR_REQUEST1 were shared between two different parts of the code, so the developer gave …

f1c74046by Ondřej Vejpustek+26−222 files
No security note in commit
Low 37 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(crypto): prevent calling `memzero(NULL, ...)`

This commit fixes three places in the Trezor firmware's cryptographic code where a memory-clearing function could be called with a NULL pointer. In practice, passing NULL to memzero is harmless on Trezor's platform (it does nothing), but i…

NULL pointer passed to memory-zeroing helper in cryptographic codeUndefined behavior in C standard library contractDefensive hardening in Noise protocol implementation
0394e934by Ondřej Vejpustek+11−51 file
No security note in commit
Informational 18 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(crypto): return remote static key from `noise_xxpsk3_*_handle_*()`

This commit is a code cleanup (refactor) for the cryptographic handshake code used in Trezor devices. It changes how the other party's long-term public key is returned to the caller: instead of storing it inside an internal state structure…

Removal of long-term public key storage from internal handshake stateCaller-supplied output buffer for remote static public key reduces internal secret retentionError-path memzero of returned key material on failure
3ead1aa6by Ondřej Vejpustek+79−423 files
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

test(ethereum): fix incorrect address checksum

This commit only updates test data. It corrects the capitalization (checksum) of Ethereum addresses used in automated tests and refreshes the expected screen-shot hashes those tests compare against. There are no changes to the actual Trezo…

2b1938ccby Tomas Martykan+52−523 files
No security note in commit
Low 33 AI analysisMessage 67 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(python/trezorlib): enable entropy check on T1 by default

This commit changes the Trezor Python library so that, when setting up a Trezor Model One (the original Trezor 1 device), it now performs an entropy check by default if the device runs firmware 1.13.1 or newer. Previously, the library only…

Enables a previously disabled security/validation feature (entropy check) for a specific device modelAdds version-gated behavior to avoid errors on older firmwareDefensive hardening of wallet setup randomness verification
a4af9107by Andrew Kozlik+10−42 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): remove scons related files

This commit is a routine cleanup that removes the old SCons build system files from the Trezor Core firmware repository. It deletes Makefiles, SConscripts, and related Python helper scripts, but does not change any firmware source code, cr…

a4b25c31by cepetr+5−927554 files
No security note in commit
Informational 22 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): assorted micropython-1.28.0 fixes

This commit updates Trezor's embedded MicroPython interpreter from an older version to 1.28.0. It pulls in several upstream MicroPython bug fixes, including stricter buffer-size checks for converting integers to bytes, a new stack-safety A…

Synchronizes upstream MicroPython fixes that include buffer-size and stack-safety hardeningPrevents Ctrl+C interruption of frozen boot code, reducing denial-of-service/control-flow risk during bootFixes sys.stdout.buffer.write() return value, which could affect code relying on correct I/O semantics
7ba7879dby Martin Milata+36−4012 files
No security note in commit
Informational 15 AI analysisMessage 70 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): use mp_obj_new_str_from_cstr

This commit is a simple code cleanup that replaces a common MicroPython string-creation pattern with a new helper function. It does not change what the code does, only how it is written. There is no security issue visible in the change.

6a889e6aby Martin Milata+3−33 files
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): replace hexlify with bytes.hex()

This is a large but straightforward internal cleanup: the project switched from using the MicroPython `ubinascii` module's `hexlify`/`unhexlify` functions to the standard Python `bytes.hex()` and `bytes.fromhex()` methods. The change remov…

44aa469eby Martin Milata+1334−1383120 files
No security note in commit
Informational 18 AI analysisMessage 70 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): replace m_new_obj_with_finaliser

This commit is a routine code cleanup in the Trezor firmware's embedded MicroPython modules. It replaces an older, two-step object allocation pattern with a newer helper that allocates memory and sets the object type in one step. The chang…

No security-relevant logic changes observedNo input validation changesNo memory safety bug fixes (e.g., no overflow, use-after-free, or uninitialized memory fixes)
142794eaby Martin Milata+40−5619 files
No security note in commit
Informational 17 AI analysisMessage 70 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): use mp_obj_new_str_from_vstr

This is a code cleanup change in Trezor's firmware that swaps one MicroPython internal helper for another. It replaces calls that create byte or string objects from a vstr buffer with newer, purpose-built helpers. The commit message says t…

Refactor only: helper function renames with equivalent semanticsNew str helper adds UTF-8 validation; bytes helper does not validateNo input validation, length, or error-handling changes observed
7ea11191by Martin Milata+72−7433 files
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): switch to slots-based mp_obj_type_t

This commit is a routine internal cleanup that switches how Trezor's firmware defines built-in MicroPython object types. It replaces older, manually-written type structures with a newer macro provided by the upstream MicroPython project. T…

ab51798fby Martin Milata+163−16624 files
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): get rid of the STATIC macro

This commit is a large but purely mechanical code cleanup: it replaces the custom STATIC macro with the standard C keyword static across many MicroPython module files. There is no change to program logic, security boundaries, or behavior. …

053def4cby Martin Milata+789−79757 files
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): fix renamed micropython modules

This commit is a routine code cleanup that updates Trezor firmware to match a newer MicroPython version where built-in module names dropped the 'u' prefix (for example, 'uos' became 'os' and 'ustruct' became 'struct'). It renames imports, …

e1edbee0by Martin Milata+86−11727 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): bump version to 2.12.5

This commit only updates the firmware version number from 2.12.4 to 2.12.5 in the source code and translation files. It does not change any security-related logic, fix any bug, or alter any cryptographic behavior. It is a routine release b…

82c04645by Martin Milata+10−108 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): build trezor_lib with xbuild

This is a routine build-system cleanup for the Trezor firmware. It switches the internal 'trezor_lib' Rust crate to be built with the project's own 'xbuild' tool, removes transitional feature flags, and reorganizes Cargo.toml files. There …

9ba7ee1bby cepetr+597−86816 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(nordic): add nrf/ble functionality to T3T2

This commit adds Bluetooth Low Energy (BLE) support for the Trezor T3T2 hardware model. It introduces new board configuration files, pin mappings, build scripts, and firmware binaries for the Nordic nRF54LS05A BLE radio used in T3T2. There…

d8b4daa6by tychovrahe+526−922 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedrefactor(core/rust): update obj_type! for slots-based mp_obj_type_tby Martin Milata · aba19a5a · Aug 3, 2026 · 15 filesMessage 85 · StrongTriage 7Details
Commit message · Martin Milata

refactor(core/rust): update obj_type! for slots-based mp_obj_type_t

Relevant micropython commits:
3ac8b5851e5f4dade465d52b91ed2ccc17851263 py/obj: Add slot-index mp_obj_type_t representation.
cb0ffdd2bf25dcac3c230bdc1168d492aabaf573 py/obj: Remove basic mp_obj_type_t sparse representation.

[no changelog]

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI review queuedfix(nordic): select correct hash algorithm for fw validationby tychovrahe · 66205f1b · Jul 31, 2026 · 4 filesMessage 62 · AdequateTriage 12Details
Commit message · tychovrahe

fix(nordic): select correct hash algorithm for fw validation

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedfeat(core/sys): expose syslog as a Rust moduleby matejcik · bddf05ee · Jul 31, 2026 · 11 filesMessage 72 · AdequateTriage 0Details
Commit message · matejcik

feat(core/sys): expose syslog as a Rust module

and rewrite trezor_lib to use it as a dependency

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
second-pass: broader security terminology
AI review queuedchore(trezorlib): refactor device definition requests handlingby PrisionMike · 8a01a994 · Jul 29, 2026 · 6 filesMessage 62 · AdequateTriage 12Details
Commit message · PrisionMike

chore(trezorlib): refactor device definition requests handling

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedchore(translations): sync Crowdin translationsby Michal Kazda · c6040ab4 · Jul 28, 2026 · 6 filesMessage 57 · ThinTriage 0Details
Commit message · Michal Kazda

chore(translations): sync Crowdin translations

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathtranslation-only discountsecond-pass: security-sensitive path
AI review queuedchore: update fixturesby PrisionMike · 148d73ea · Jul 28, 2026 · 4 filesMessage 40 · ThinTriage 12Details
Commit message · PrisionMike

chore: update fixtures

[no changelog]

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedchore(translations): update Continue for csby Martin Milata · e1251b09 · Jul 28, 2026 · 2 filesMessage 57 · ThinTriage 0Details
Commit message · Martin Milata

chore(translations): update Continue for cs

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathtranslation-only discountsecond-pass: security-sensitive path
AI review queuedchore(core/ethereum): reject invalid initial chunkby Roman Zeyde · b5e27a2d · Jul 28, 2026 · 2 filesMessage 62 · AdequateTriage 20Details
Commit message · Roman Zeyde

chore(core/ethereum): reject invalid initial chunk

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI review queuedchore(core/stellar): make gen and fixturesby obrusvit · 94d39e3c · Jul 28, 2026 · 6 filesMessage 57 · ThinTriage 12Details
Commit message · obrusvit

chore(core/stellar): make gen and fixtures

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedrefactor(core): do not preallocate known addressesby obrusvit · 2e67a22f · Jul 27, 2026 · 4 filesMessage 77 · AdequateTriage 12Details
Commit message · obrusvit

refactor(core): do not preallocate known addresses

- use `mako` template to generate sc_constants
- de-duplicate WETH_DEPLOYMENTS

[no changelog]

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedfix(core/bitcoin): Fix external input misidentification.by Andrew Kozlik · 675fa659 · Jul 23, 2026 · 5 filesMessage 77 · AdequateTriage 12Details
Commit message · Andrew Kozlik

fix(core/bitcoin): Fix external input misidentification.

(cherry picked from commit 23bbf680071f7ede286dc3eda2f4baa7193288b2)

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedrefactor(core/bitcoin): Consolidate external input classification.by Andrew Kozlik · e70633ee · Jul 23, 2026 · 2 filesMessage 77 · AdequateTriage 12Details
Commit message · Andrew Kozlik

refactor(core/bitcoin): Consolidate external input classification.

(cherry picked from commit 2042aec0ba7316c268548b1297691e750ed2112c)

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedfix(core/bitcoin): Reject new external outputs in bitcoin replacement transactions.by Andrew Kozlik · 62891383 · Jul 23, 2026 · 3 filesMessage 77 · AdequateTriage 12Details
Commit message · Andrew Kozlik

fix(core/bitcoin): Reject new external outputs in bitcoin replacement transactions.

(cherry picked from commit a06d11ea82dcc796106a289084c958cbe76a5caf)

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedchore(core): simplify EIP-712 domain confirmation flowby Roman Zeyde · b408aa0a · Jul 23, 2026 · 3 filesMessage 85 · StrongTriage 12Details
Commit message · Roman Zeyde

chore(core): simplify EIP-712 domain confirmation flow

`EIP712Domain` contains up to 5 fields, so it would be much simpler to
always confirm all of them, instead of caching and re-streaming.

[no changelog]

(cherry picked from commit e9f5ebdd496098f07f8c62698b2ecf17615feccd)

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedfeat(core): group EIP-712 domain confirmationsby Roman Zeyde · 09e3f9cb · Jul 23, 2026 · 8 filesMessage 88 · StrongTriage 12Details
Commit message · Roman Zeyde

feat(core): group EIP-712 domain confirmations

It should require less confirmations on Bolt, Delizia and Eckhart,
since `EIP712Domain` doesn't contain nested members [1].

Also, show a warning if `EIP712Domain` is empty.

[1] https://eips.ethereum.org/EIPS/eip-712#definition-of-domainseparator

[no changelog]

(cherry picked from commit b4af7c01db0b0352d81d4db47ec0ec767e559e8d)

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedfix(core): solana transfer showing LUT addressby obrusvit · 537b34f8 · Jul 23, 2026 · 4 filesMessage 72 · AdequateTriage 12Details
Commit message · obrusvit

fix(core): solana transfer showing LUT address

(cherry picked from commit e306dd41b41fea3cec3e3a75cedd501e8ad77a86)

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedchore(core): sign translationsby Martin Milata · 8b4afd25 · Jul 23, 2026 · 1 fileMessage 62 · AdequateTriage 0Details
Commit message · Martin Milata

chore(core): sign translations

[no changelog]

(cherry picked from commit b09832e821eac9ba247351037a2c8e2b585cad7c)

62/100 · AdequateMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathtranslation-only discountsecond-pass: security-sensitive path
AI review queuedfix(solana): check unique stake withdraw recipientby Jakub Janků · 31e05613 · Jul 23, 2026 · 2 filesMessage 85 · StrongTriage 12Details
Commit message · Jakub Janků

fix(solana): check unique stake withdraw recipient

Prior to this commit, trezor used special UI flow for solana
transactions that contained only stake withdraw instructions. The
problem was that only the total withdrawn amount was shown without the
per-recipient breakdown of the amount.

This change restricts the use of the special flow only to cases where
the recipient is the same across all withdraw instructions. This unifies
the behavior of the `try_confirm_token_transfer_transaction` and
`try_confirm_staking_transaction` functions. If the recipient differs
from the signer, a warning is shown.

NOTE: This change also fixes the issue that the special flow could be
aborted without user interaction --- this could happen when the
transaction contained one supported instruction (by the special flow)
with a recipient other than the wallet and one unsupported instruction.
First, the user would see the recipient warning (part of the special
flow), but then this flow would be aborted and the default per-
instruction confirmation flow would start.

(cherry picked from commit 6b84dcdd241410c90fce8dbd4d8f8a2454aceeaf)

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedfix(solana): show `source_account` when approving a delegateby Jakub Janků · 13abf4de · Jul 23, 2026 · 3 filesMessage 97 · StrongTriage 12Details
Commit message · Jakub Janků

fix(solana): show `source_account` when approving a delegate

The Solana Token programs provide two instructions for approving a
delegate for an account: `Approve` and `ApproveChecked`. The former
is shown on trezor as deprecated because it doesn't contain any
information about the token mint and decimals. However, it is still
important to show the source account for which we are approving the
delegate --- otherwise, if the user has multiple token accounts,
they may unknowingly approve the delegate for a different account
than they intended. Note that the `source_account` IS shown when
confirming the latter, checked, instructions.

[no changelog]

(cherry picked from commit c881bfedc5c556cce5884fd975b1b3993a34dbfe)

97/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queueddocs(core,prodtest): changelog update core v2.12.2 prodtest v0.3.8by PrisionMike · f7bd2917 · Jul 23, 2026 · 24 filesMessage 77 · AdequateTriage 0Details
Commit message · PrisionMike

docs(core,prodtest): changelog update core v2.12.2 prodtest v0.3.8

(cherry picked from commit 2549fb7f8ff7e758e63036a349284927bd55e4f2)

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
second-pass: unusually broad change
AI review queuedchore(python): make merkle tree balancedby M1nd3r · 6c40c944 · Jul 23, 2026 · 4 filesMessage 57 · ThinTriage 12Details
Commit message · M1nd3r

chore(python): make merkle tree balanced

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedtest(core): fix Stellar payment request tests.by Jun Luo · e9bd96f3 · Jul 22, 2026 · 2 filesMessage 67 · AdequateTriage 12Details
Commit message · Jun Luo

test(core): fix Stellar payment request tests.

[no changelog]

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedfix(l10n): updated generated files [no changelog]by Michal Kazda · 6ee734ad · Jul 21, 2026 · 5 filesMessage 72 · AdequateTriage 12Details
Commit message · Michal Kazda

fix(l10n): updated generated files
[no changelog]

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedchore(core): add ETH calldata digest translated stringby Roman Zeyde · a4097f69 · Jul 21, 2026 · 6 filesMessage 62 · AdequateTriage 12Details
Commit message · Roman Zeyde

chore(core): add ETH calldata digest translated string

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedrefactor(core/ethereum): make `ConfirmDataFn` a classby Roman Zeyde · f560b6f0 · Jul 21, 2026 · 2 filesMessage 85 · StrongTriage 12Details
Commit message · Roman Zeyde

refactor(core/ethereum): make `ConfirmDataFn` a class

It can be created inside `_confirm_data_chunks()`.
Also, make `get_progress_indicator` private and return a non-async callback.

[no changelog]

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path