TZ
← All projectsTrezor

Trezor firmware

Firmware monorepo for Trezor One, Model T, and Safe devices.

BitcoinHardware walletsNormal
Repository coverage

3229 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

1125security candidates372second-pass queue2925AI analyses
292commits · 30 days
701commits · 60 days
1641commits · 180 days
2705commits · 365 days
Backfill bands
Aug 5 → Feb 61298 seen115 candidatesComplete
Feb 6 → Jun 6775 seen58 candidatesComplete
Jun 6 → Jul 6217 seen13 candidatesComplete
Jul 6 → Aug 5360 seen54 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

67/100 average clarity
635Strong · 80–100
1551Adequate · 60–79
1036Thin · 40–59
7Opaque · 0–39
1security candidate with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
tychovrahe343134322564
Roman Zeyde675214620372
obrusvit25395235364
PrisionMike10866106272
Andrew Kozlik833481268
Petr Susil202299
Jakub Janků591838180
Martin Pastyřík26823173
cepetr264106222059
M1nd3r24689227071
Ioan Bizău23076230059
Lukas Bielesch856784067
Analysis record

Published AI watches

Last scanned 21 minutes ago

Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): improvements to English copy

This commit is a routine text cleanup for the Trezor hardware wallet's on-screen English messages. It fixes punctuation, removes unnecessary line breaks, and makes small wording tweaks (for example, changing 'PIN will be required' to 'A PI…

1dbc2c3cby Michal Kazda+22−422 files
No security note in commit
Moderate 59 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core): app root packet downgrade protection

This commit adds downgrade protection for a new 'app root packet' system in Trezor firmware. Previously, the code had a TODO note saying downgrade protection needed to be considered. The change makes the device remember the timestamps of p…

Replaces a TODO comment ('!@# TODO: Consider downgrade protection') with concrete timestamp-based anti-downgrade checksAdds per-ring timestamp state to prevent rollback of root-of-trust packetsAdds chain_timestamp field and 90-day drift bound to root packet format
4a9cf168by cepetr+335−3112 files
No security note in commit
Moderate 67 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core/rust): discard low-order keys in THP handshake

This commit fixes a cryptographic edge case in Trezor's THP (Trezor Host Protocol) handshake. It now rejects Curve25519 public keys that are all zeros or that produce an all-zero shared secret. A zero public key can cause the Diffie-Hellma…

Curve25519 zero/low-order public key rejection added to DHZero shared-secret output rejected after scalar multiplicationHandshake state machine now transitions to Failed on initiation-response error
429a283dby M1nd3r+45−74 files
No security note in commit
Informational 11 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core): enable `ward` with `miniscript`

This commit changes one line in a build configuration file for the Trezor hardware wallet firmware. It adds the 'ward' feature to the existing 'miniscript' feature set. There is no direct evidence in the commit that this is a security fix;…

Single-line Cargo.toml feature flag changeNo code logic modificationNo changelog or security note in commit message
d434a636by Jakub Janků+1−11 file
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core): add `ward` feature flag

This commit adds a new disabled-by-default feature flag called 'ward' to the Trezor firmware build system. It does not change any production firmware behavior; it only wires up a placeholder MicroPython module and build options so that fut…

New feature flag is disabled by default and gated behind optional Cargo featuresCommit message explicitly states intent to exclude WARD from production firmware buildsNew MicroPython module is a stub with no exported functions beyond __name__
7b58e75aby Jakub Janků+55−018 files
No security note in commit
Low 27 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core): enable -Wsign-compare

This commit turns on a compiler warning (-Wsign-compare) that catches places where signed and unsigned numbers are compared, and fixes the resulting warnings across the Trezor firmware. Most changes are clean-up casts and loop-index type c…

Compiler warning -Wsign-compare enabled, indicating prior signed/unsigned comparison issuesI/O return-value checks hardened against negative ssize_t values being treated as successPython binding offset/length validation tightened in Monero crypto module
1cc940a4by cepetr+162−15247 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): merge passphrase__access_hidden_wallet into passphrase__access_wallet

This commit is a simple user-interface cleanup. It removes one duplicate translation label ('Access hidden wallet') and makes the device use a single, consistent label ('Access wallet') when asking the user to confirm opening a passphrase-…

65402aecby Michal Kazda+2−103 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): merge passphrase__hidden_wallet into passphrase__wallet

This commit is a simple user-interface cleanup. It merges two translation labels that both meant 'Passphrase wallet' into a single label, and updates the screens that used the old duplicate label. There is no security-relevant behavior cha…

7ce6887fby Michal Kazda+5−184 files
No security note in commit
Low 45 AI analysisMessage 85 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core/bootloader): keep the full block length for block-0 retries

This commit fixes a bug in the Trezor bootloader's firmware-update code. When updating firmware, the first block of data is fetched in two pieces: a small initial 'header prefetch,' then the rest. If a communication error happened and the …

Firmware update reliability bug in bootloaderBlock-0 retry path truncated data before hash verificationHash mismatch caused by buffer offset/size mismatch, not by attacker
dc937ba2by tychovrahe+81−711 file
No security note in commit
Informational 12 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core/bootloader): separate image upload and image checks

This commit is a code cleanup in the Trezor bootloader. It moves the generic, image-type-agnostic parts of firmware upload (chunk receiving, retry logic, flash erasing/writing, timeouts) into a new reusable module called wf_image_upload.c,…

Refactor only: logic moved, not changed in security-relevant waysSame signature/version/model/downgrade checks remain in firmware-specific handlerSame flash erase/write sequence preserved in generic engine
caab7d9eby tychovrahe+772−4834 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): remove unused trezor_lib/ui feature

This commit removes an unused Rust Cargo feature flag called 'ui' from the Trezor firmware build configuration. It is a cleanup change: the feature was always enabled in practice, so the code now compiles unconditionally. There is no secur…

1436fbc6by cepetr+2−158 files
No security note in commit
Low 27 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core/caesar): change confirm middle button

This commit changes how users confirm an Ethereum authorization screen on Trezor's 'Caesar' layout. Previously, the user had to hold down a button to approve; now a simple tap is enough. The change only affects the user-interface interacti…

UI confirmation gesture changed from hold-to-confirm to tap-to-confirmOnly affects EIP-7702 authorization flow on Caesar (T3B1) layoutTest fixture hashes updated for all supported languages
e231cc94by obrusvit+50−502 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): merge firmware and unix cargo packages

This commit is a routine internal cleanup that merges two separate build packages (one for real hardware firmware and one for the desktop emulator) into a single package. It moves source files into subdirectories and updates build scripts …

6be32440by cepetr+48−32025 files
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core): test aes gcm only if enabled

This commit is a minor build/test maintenance change. It adds a feature flag (USE_AES_GCM) so that AES-GCM tests are only run when the feature is actually enabled in a particular firmware build. There is no security fix or vulnerability be…

890aca93by cepetr+13−14 files
No security note in commit
Informational 15 AI analysisMessage 95 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(python, tests): add and update GNU licence headers

This commit only adds or updates copyright and GNU license header comments in Python test and tooling files. It makes no changes to executable code, so it cannot introduce a security vulnerability or fix one.

6dc781c2by M1nd3r+1202−203250 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): move the multisig XPUB title into a translation template

This commit is a straightforward code cleanup: it moves the on-screen title for multisig XPUB screens from hard-coded English text into the device's translation system. The visible text remains essentially the same, and there is no securit…

6d69df16by Michal Kazda+20279−2023911 files
No security note in commit
Informational 15 AI analysisMessage 77 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

refactor(core): render translated strings verbatim in layouts

This is a cosmetic code cleanup. It moves punctuation and capitalization out of the Python code and into the translation files so translated strings are shown exactly as written. There is no security-relevant change.

162ed3a2by Michal Kazda+12−125 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(core/bolt): remove unneeded `use` statements

This commit simply removes two unused Rust import statements (called `use` statements). It does not change any actual code behavior, logic, or security properties of the Trezor firmware.

a56f8c3dby Roman Zeyde+0−22 files
No security note in commit
Informational 18 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core): add missing colon in Tron

This commit fixes a UI formatting bug in the Tron cryptocurrency flow on Trezor hardware wallets. A missing colon was added to account information labels shown on the device screen. The change is cosmetic and does not appear to affect cryp…

UI label formatting fix onlyNo changes to signature verification, key handling, or transaction authorizationNo buffer size, memory allocation, or input validation changes observed
739c2968by Michal Kazda+19332−193364 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core): combine path/account with labels

This commit is a straightforward user-interface refactoring. It bundles an account/path label together with its corresponding value into a single tuple, instead of passing them as four separate arguments. There is no security-relevant chan…

c66f6f4dby Michal Kazda+51−7413 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedfix(python): skip stale protocol v1 responsesby Roman Zeyde · 1edb54ac · Jun 12, 2026 · 4 filesMessage 57 · ThinLow 47Details
Commit message · Roman Zeyde

fix(python): skip stale protocol v1 responses

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Low 47/100

This update fixes a bug in the Trezor Python library where reconnecting to a Trezor device could fail if an old, unread response was still waiting in the communication channel. The fix makes the library clear out up to 10 stale responses before it checks whether the device speaks the older protocol v1. A new test simulates a host disconnect mid-operation and verifies that a new client can reconnect successfully.

AI review queuedchore(tron): boilerplate support for (un)delegate resource instructions.by PrisionMike · ef510943 · Jun 12, 2026 · 23 filesMessage 77 · AdequateInformational 15Details
Commit message · PrisionMike

chore(tron): boilerplate support for (un)delegate resource instructions.

- Benign string refactorings with eos.
[no changelog]

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds the data structures and translations needed to support two new Tron blockchain operations—delegating and undelegating staked resources—but does not include the actual code that would handle or sign those operations. It also moves a few shared user-interface labels from the EOS section to a common 'words' section. There is no security issue visible in this patch.

AI review queuedchore(rust): remove unneeded `script_type` from Trezor::get_public_key()by Roman Zeyde · a87197ed · Jun 8, 2026 · 4 filesMessage 62 · AdequateInformational 18Details
Commit message · Roman Zeyde

chore(rust): remove unneeded `script_type` from Trezor::get_public_key()

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This is a small cleanup change in the Rust Trezor client library. It removes an unused `script_type` parameter from the `get_public_key()` function and its callers. The parameter was being set in the request to the Trezor device, but the device does not actually need or use it for this operation. There is no security vulnerability here—just code simplification.

AI review queuedrefactor(core/build): stop treating emulator as a separate HW board, instead use it to emulate the selected boardby tychovrahe · 566dc7db · Jun 8, 2026 · 22 filesMessage 62 · AdequateInformational 15Details
Commit message · tychovrahe

refactor(core/build): stop treating emulator as a separate HW board, instead use it to emulate the selected board

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit is a build-system cleanup. It removes separate 'emulator board' configuration files and instead makes the emulator reuse the real hardware board's settings, only swapping in a special emulator header and the Unix display/touch drivers. There is no user-facing change or security fix visible in the diff.

AI review queuedfeat(core/build): add board and target configuration filesby tychovrahe · 9bf8a898 · Jun 8, 2026 · 23 filesMessage 62 · AdequateInformational 15Details
Commit message · tychovrahe

feat(core/build): add board and target configuration files

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit adds new configuration files describing Trezor hardware models and build targets. It is a build-system feature with no user-facing behavior change and no apparent security relevance.

AI review queuedfix(core/cardano): don't access TR in global ctxby copilot-swe-agent[bot] · 9365fb01 · Jun 3, 2026 · 6 filesMessage 57 · ThinInformational 20Details
Commit message · copilot-swe-agent[bot]

fix(core/cardano): don't access TR in global ctx

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit is a code-quality fix in the Cardano app of the Trezor firmware. It removes direct access to the global translation object (TR) at the time the Python module is first loaded, and instead reads the translated strings only when they are actually needed. This avoids a potential startup-time crash or import-order problem if the translation system is not fully initialized when the module is imported. There is no direct evidence in the commit that this is an exploitable security vulnerability.

AI review queueddocs(core): document why `_waiting_screen` doesn't send ButtonRequestsby Roman Zeyde · 4fa4371a · Jun 3, 2026 · 1 fileMessage 74 · AdequateInformational 15Details
Commit message · Roman Zeyde

docs(core): document why `_waiting_screen` doesn't send ButtonRequests

[no changelog]

74/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Explains rationale or failure mode! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds comments explaining existing behavior in a Trezor firmware source file. No code logic was changed, no bugs were fixed, and no security vulnerability is present in the diff.

AI review queuedfix(core): avoid failing ButtonRequest handling at `ContinueOnErrors`by Roman Zeyde · f12deee6 · Jun 3, 2026 · 3 filesMessage 85 · StrongLow 44Details
Commit message · Roman Zeyde

fix(core): avoid failing ButtonRequest handling at `ContinueOnErrors`

No more button requests / errors will be sent later during
the backup workflow after an I/O-related error/timeout.

Host will be ignored until the backup workflow is over -
sending the final "Success" response may fail.

Other workflows can be aborted after user cancellation via `_waiting_screen()`.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Low 44/100

This update fixes a bug in how the Trezor device handles on-screen button prompts when communication with the host computer hits errors or timeouts. Previously, an input/output problem during a backup could cause the device to send extra button requests or errors after the workflow should have ended, and the final 'Success' message could fail to send. The fix makes the device ignore further host messages until the backup workflow finishes, and lets users cancel other workflows through a new waiting screen. It is a reliability and defensive fix rather than a clear-cut remote exploit.

AI review queuedchore(core): update communication-related stringsby Roman Zeyde · ef194b4a · Jun 2, 2026 · 7 filesMessage 57 · ThinInformational 15Details
Commit message · Roman Zeyde

chore(core): update communication-related strings

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes user-facing text strings and their generated lookup tables in the Trezor firmware. It rewords a message about communication problems and adds a second, milder version of the message. There are no code behavior changes, no fixes to logic bugs, and no security-relevant functionality altered.

AI review queuedchore(deps): bump urllib3 in /tools/automatic_battery_testerby dependabot[bot] · 2bda8865 · May 29, 2026 · 1 fileMessage 93 · StrongInformational 15Details
Commit message · dependabot[bot]

chore(deps): bump urllib3 in /tools/automatic_battery_tester

Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.3 to 2.7.0.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0)

---
updated-dependencies:
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
documentation-only discountautomated dependency-update discountsecond-pass: broader security terminology
AI analysis · Informational 15/100

This is a routine automated dependency update by Dependabot that bumps the urllib3 library from version 2.6.3 to 2.7.0 inside a small internal testing tool (automatic_battery_tester). The change is a single line in a requirements file. There is no indication in the commit that this fixes a security issue, and the tool is not part of the Trezor firmware that runs on user devices.

AI review queuedfix(core): skip bitcoin.signtx_decred test on BTC_ONLYby M1nd3r · 80c9f204 · May 29, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · M1nd3r

fix(core): skip bitcoin.signtx_decred test on BTC_ONLY

[no changelog]

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes a test file so that a Decred signing test is skipped when the firmware is built in Bitcoin-only mode. It does not modify any production firmware code, wallet behavior, or cryptographic logic. There is no security issue here.

AI review queuedtest(solana): sign message with many cosignersby Jakub Janků · e0b2dea3 · May 29, 2026 · 2 filesMessage 67 · AdequateInformational 15Details
Commit message · Jakub Janků

test(solana): sign message with many cosigners

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds a new test case for Solana message signing with 64 cosigners and updates the expected screen snapshots used by automated testing. It does not change any firmware code that runs on the Trezor device, so it cannot introduce a security vulnerability or fix one.

AI review queuedchore(ci): skip `auto-assign` job for botsby M1nd3r · c784179b · May 29, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · M1nd3r

chore(ci): skip `auto-assign` job for bots

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathdocumentation-only discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a minor GitHub workflow change that stops an automatic pull-request assignment job from running when the pull request is opened by a bot account (whose username ends with '[bot]'). It has no security relevance to the Trezor firmware itself or to user funds.

AI review queuedfix(core): fix device_menu crash on devices without a serial numberby cepetr · 51790381 · May 29, 2026 · 1 fileMessage 62 · AdequateInformational 20Details
Commit message · cepetr

fix(core): fix device_menu crash on devices without a serial number

[no changelog]

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 20/100

This commit fixes a crash in the Trezor device's on-screen 'About device' menu when the device lacks a serial number. It wraps the serial-number lookup in a try/except block and displays 'N/A' instead of crashing. There is no indication this can be exploited by an attacker; it is a robustness fix for a user-interface screen.

AI review queuedchore(core): adjust json vendorheadersby M1nd3r · 82f1c71b · May 27, 2026 · 14 filesMessage 57 · ThinInformational 15Details
Commit message · M1nd3r

chore(core): adjust json vendorheaders

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only renames a single JSON key from '_reserved' to 'reserved' across 14 vendor header configuration files. No security settings, permissions, or values are changed. It appears to be a routine cleanup to match a naming convention elsewhere in the build tooling.

AI review queuedrefactor(core): move is_printable_ascii to commonby Jakub Janků · e07fff7d · May 26, 2026 · 3 filesMessage 80 · StrongInformational 15Details
Commit message · Jakub Janků

refactor(core): move is_printable_ascii to common

This is a preparatory commit. The utility will be used in solana
off-chain message parsing, so we move it from cardano/helpers/utils
to common/signverify.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply moves a small helper function that checks whether a string contains only normal printable characters from one file to another shared location. No behavior changes, no bug fixes, and no security implications are visible in the code change itself.

AI review queuedtest(solana): sign and verify off-chain messagesby Jakub Janků · 2124b6b3 · May 26, 2026 · 4 filesMessage 67 · AdequateInformational 15Details
Commit message · Jakub Janků

test(solana): sign and verify off-chain messages

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds new automated tests for a Solana feature that signs and verifies off-chain messages. It does not change the actual wallet firmware code that users rely on, so it cannot by itself introduce a security vulnerability or fix one. The tests exercise parsing, signing, and verification logic and include checks for invalid inputs.

AI review queuedchore(translations): minor string update [no changelog]by Michal Kazda · b2d0adf4 · May 26, 2026 · 2 filesMessage 77 · AdequateInformational 15Details
Commit message · Michal Kazda

chore(translations): minor string update
[no changelog]

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathtranslation-only discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit changes one German translation string to add the word 'ist' (is) for consistency, and updates the corresponding translation signature metadata. There is no code or security change.

AI review queuedchore(translations): sync Crowdin translations [no changelog]by Michal Kazda · c565e45c · May 26, 2026 · 6 filesMessage 77 · AdequateInformational 15Details
Commit message · Michal Kazda

chore(translations): sync Crowdin translations
[no changelog]

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathtranslation-only discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only updates translated text strings in Czech, German, Spanish, French, and Portuguese for the Trezor hardware wallet firmware. It changes wording for things like Ethereum transaction prompts, Bluetooth device labels, backup/recovery instructions, and passphrase prompts. There are no code logic changes, no new features, and no security fixes.

AI review queuedchore(core/eckhart): update About screenby obrusvit · 41ff96ea · May 26, 2026 · 10 filesMessage 57 · ThinInformational 15Details
Commit message · obrusvit

chore(core/eckhart): update About screen

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine user-interface update for the Trezor hardware wallet's 'About' screen. It adds a 'Made in Ostrava, Czechia' label and, on devices that use serial numbers, displays the serial number. There is no security-relevant change.

AI review queuedchore(tests,ethereum): tests from Suiteby Ioan Bizău · fc87316d · May 26, 2026 · 1 fileMessage 67 · AdequateInformational 15Details
Commit message · Ioan Bizău

chore(tests,ethereum): tests from Suite

[no changelog]

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds new test cases for Ethereum transaction signing. It does not change any production code, so it cannot introduce a security vulnerability by itself. The test data includes sample transactions and their expected signatures, used to verify the device signs complex DeFi transactions correctly.

AI review queuedchore(ethereum): preload 6kb of databy Ioan Bizău · a36d79b7 · May 26, 2026 · 2 filesMessage 57 · ThinInformational 18Details
Commit message · Ioan Bizău

chore(ethereum): preload 6kb of data

[no changelog]

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This is a small internal tuning change for Trezor's Ethereum app. It increases the amount of transaction data the device preloads from 4 KB to 6 KB before asking the user to confirm. The only visible effect is fewer back-and-forth data requests for Ethereum transactions with large data payloads. There is no direct security fix or vulnerability being patched.

AI review queuedchore(python): re-add `pytest-retry` dependency for `pytest.mark.flaky`by Roman Zeyde · c081328b · May 23, 2026 · 2 filesMessage 77 · AdequateInformational 15Details
Commit message · Roman Zeyde

chore(python): re-add `pytest-retry` dependency for `pytest.mark.flaky`

It was removed in 108c87a776 by mistake.

[no changelog]

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 15/100

This commit simply restores a missing Python test dependency called pytest-retry. It only affects the project's testing environment and does not change any code that runs on the Trezor device or any production software. There is no security issue here.

AI review queuedchore(translations): sync Crowdin translations [no changelog]by Michal Kazda · 1ffba715 · May 22, 2026 · 6 filesMessage 77 · AdequateInformational 15Details
Commit message · Michal Kazda

chore(translations): sync Crowdin translations
[no changelog]

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathtranslation-only discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine synchronization of translated user-interface text for the Trezor hardware wallet. It updates wording, adds missing translations, and removes obsolete translation keys across several language files. There are no code changes that affect security, cryptography, transaction signing, or device behavior.

AI review queuedfix(solana): ALT recipients shown correctly in system transfer.by PrisionMike · 2b4cbcc9 · May 22, 2026 · 6 filesMessage 77 · AdequateModerate 58Details
Commit message · PrisionMike

fix(solana): ALT recipients shown correctly in system transfer.

(cherry picked from commit 257af9891d24b7f9d0379729177a23d8cd7de7c8)

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 58/100

This update fixes how Trezor displays Solana transactions that use Address Lookup Tables (ALTs). Previously, the device could misidentify or fail to show the real recipient when an ALT was involved, which might let an attacker trick a user into approving a transfer to an unexpected address. The patch also blocks ALT references in payment requests and some staking flows where the device cannot safely verify the destination.