Merge commit 'refs/pull/2061/head' of https://github.com/BitBoxSwiss/bitbox02-firmware
What changed, and why it matters
This commit only adds two digital signature files for an already-released firmware version (v9.26.5). These signatures are used by users to independently verify that the published firmware binary matches what a specific signer reviewed. No code, no firmware binary, and no behavior of the device or software is changed. There is no security vulnerability here.
No action required. This is a routine release-attestation signature addition. Reviewers may optionally verify the signature against the signer's known public key and the published firmware hash if they participate in the reproducible-build attestation process.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit merges PR #2061, which adds two assertion signature files under releases/firmware-v9.26.5/: assertion-bitbox02-btconly-sutterseba.sig and assertion-bitbox02-multi-sutterseba.sig. These are detached signatures over an existing firmware release, produced by an independent builder/reviewer (‘sutterseba’). They do not modify source code, compiled firmware, build scripts, or any runtime component. The diff is binary-only and unavailable, but the file paths and naming convention unambiguously identify them as release assertion signatures.
Changed components
Inspect captured patch +0 / −0
### releases/firmware-v9.26.5/assertion-bitbox02-btconly-sutterseba.sig
[binary or diff unavailable]
### releases/firmware-v9.26.5/assertion-bitbox02-multi-sutterseba.sig
[binary or diff unavailable]Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.