What changed, and why it matters
This commit adds two digital signature files to the repository. They are third-party reproducible-build attestations (assertions) for the already-released BitBox02 firmware version 9.25.0. The commit does not change any firmware source code, build scripts, or device behavior. It is a routine release-verification step and does not introduce or fix any security vulnerability.
No action required. This is a normal, expected addition of reproducible-build attestation signatures. Reviewers may optionally verify the signatures against the published v9.25.0 firmware hashes if they participate in the reproducible-build verification process.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit b454a627fc80a781082d2e863e08755cd0db5e6d only creates two detached signature files under releases/firmware-v9.25.0/: assertion-bitbox02-btconly-yaziza.sig and assertion-bitbox02-multi-yaziza.sig. These are reproducible-build assertions signed by an independent builder (yaziza) attesting that the published v9.25.0 firmware binaries for the btc-only and multi-edition variants match the source code. No source code, build configuration, or firmware binary is modified. The diff is unavailable because the files are binary signatures.
Changed components
releases/firmware-v9.25.0/assertion-bitbox02-btconly-yaziza.sigreleases/firmware-v9.25.0/assertion-bitbox02-multi-yaziza.sigInspect captured patch +0 / −0
### releases/firmware-v9.25.0/assertion-bitbox02-btconly-yaziza.sig
[binary or diff unavailable]
### releases/firmware-v9.25.0/assertion-bitbox02-multi-yaziza.sig
[binary or diff unavailable]Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.