What changed, and why it matters
This commit only updates the production-test firmware changelog. It deletes individual changelog fragment files and rolls their text into the main CHANGELOG.md file, adding release sections and pull-request links. No program code was changed.
No security action needed; this is a routine documentation-only changelog maintenance commit.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff is limited to Markdown changelog files under core/embed/projects/prodtest/.changelog.d/ and CHANGELOG.md. It removes 16 changelog fragments and appends release notes for versions 0.3.1–0.3.4 plus corresponding PR reference URLs. There are no source-code, build-system, or configuration modifications.
Changed components
core/embed/projects/prodtest/CHANGELOG.mdcore/embed/projects/prodtest/.changelog.d/*Inspect captured patch +54 / −16
diff --git a/core/embed/projects/prodtest/.changelog.d/+device_sn.changed b/core/embed/projects/prodtest/.changelog.d/+device_sn.changed
deleted file mode 100644
index 5380fb79f..000000000
--- a/core/embed/projects/prodtest/.changelog.d/+device_sn.changed
+++ /dev/null
@@ -1 +0,0 @@
-Rename otp-device-id-write to otp-device-sn-write.
diff --git a/core/embed/projects/prodtest/.changelog.d/5162.added b/core/embed/projects/prodtest/.changelog.d/5162.added
deleted file mode 100644
index 186869041..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5162.added
+++ /dev/null
@@ -1 +0,0 @@
-Added a check for the subject of the device certificate.
diff --git a/core/embed/projects/prodtest/.changelog.d/5281.added.1 b/core/embed/projects/prodtest/.changelog.d/5281.added.1
deleted file mode 100644
index 13fe6d144..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5281.added.1
+++ /dev/null
@@ -1 +0,0 @@
-Add the `secrets-init` command to generate and write secrets to flash.
diff --git a/core/embed/projects/prodtest/.changelog.d/5281.added.2 b/core/embed/projects/prodtest/.changelog.d/5281.added.2
deleted file mode 100644
index 3772e4825..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5281.added.2
+++ /dev/null
@@ -1 +0,0 @@
-Add the `optiga-pair` command to pair the Optiga with the MCU.
diff --git a/core/embed/projects/prodtest/.changelog.d/5525.added b/core/embed/projects/prodtest/.changelog.d/5525.added
deleted file mode 100644
index 3475cc931..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5525.added
+++ /dev/null
@@ -1 +0,0 @@
-Add Tropic provisioning commands.
diff --git a/core/embed/projects/prodtest/.changelog.d/5595.fixed b/core/embed/projects/prodtest/.changelog.d/5595.fixed
deleted file mode 100644
index 6c36cbba1..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5595.fixed
+++ /dev/null
@@ -1 +0,0 @@
-Removed the extra CRLF added to each response line in non-interactive mode.
diff --git a/core/embed/projects/prodtest/.changelog.d/5603.fixed b/core/embed/projects/prodtest/.changelog.d/5603.fixed
deleted file mode 100644
index cff26324c..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5603.fixed
+++ /dev/null
@@ -1 +0,0 @@
-Fixed wpc-info command - fixed hex formatting, args moved to OK.
diff --git a/core/embed/projects/prodtest/.changelog.d/5604.fixed b/core/embed/projects/prodtest/.changelog.d/5604.fixed
deleted file mode 100644
index 561a99c0a..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5604.fixed
+++ /dev/null
@@ -1 +0,0 @@
-Fixed arguments count check in the secrets-certdev-write command.
diff --git a/core/embed/projects/prodtest/.changelog.d/5657.added b/core/embed/projects/prodtest/.changelog.d/5657.added
deleted file mode 100644
index f45eca372..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5657.added
+++ /dev/null
@@ -1 +0,0 @@
-Add the `tropic-keyfido-read` command.
diff --git a/core/embed/projects/prodtest/.changelog.d/5697.added b/core/embed/projects/prodtest/.changelog.d/5697.added
deleted file mode 100644
index f99e8df3f..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5697.added
+++ /dev/null
@@ -1 +0,0 @@
-Add trusted anchors for device certificates.
diff --git a/core/embed/projects/prodtest/.changelog.d/5809.added b/core/embed/projects/prodtest/.changelog.d/5809.added
deleted file mode 100644
index bc8e70dd5..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5809.added
+++ /dev/null
@@ -1 +0,0 @@
-Allow rework of unit variant.
diff --git a/core/embed/projects/prodtest/.changelog.d/5845.changed b/core/embed/projects/prodtest/.changelog.d/5845.changed
deleted file mode 100644
index 27808fdbd..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5845.changed
+++ /dev/null
@@ -1 +0,0 @@
-Make `tropic-lock()` restrict access to 64 MAC-and-destroy slots.
diff --git a/core/embed/projects/prodtest/.changelog.d/5897.fixed b/core/embed/projects/prodtest/.changelog.d/5897.fixed
deleted file mode 100644
index f7fe6d34c..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5897.fixed
+++ /dev/null
@@ -1 +0,0 @@
-Exit pairing screen when already paired host connects.
diff --git a/core/embed/projects/prodtest/.changelog.d/5900.fixed b/core/embed/projects/prodtest/.changelog.d/5900.fixed
deleted file mode 100644
index 95b0e4eec..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5900.fixed
+++ /dev/null
@@ -1 +0,0 @@
-Switched Tropic revision to ACAB.
diff --git a/core/embed/projects/prodtest/.changelog.d/5940.added b/core/embed/projects/prodtest/.changelog.d/5940.added
deleted file mode 100644
index e13e29412..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5940.added
+++ /dev/null
@@ -1 +0,0 @@
-Added an argument to the ping command.
diff --git a/core/embed/projects/prodtest/.changelog.d/5940.fixed b/core/embed/projects/prodtest/.changelog.d/5940.fixed
deleted file mode 100644
index fb4bfdb81..000000000
--- a/core/embed/projects/prodtest/.changelog.d/5940.fixed
+++ /dev/null
@@ -1 +0,0 @@
-Fixed issues with USB VCP stability.
diff --git a/core/embed/projects/prodtest/CHANGELOG.md b/core/embed/projects/prodtest/CHANGELOG.md
index ede1eb923..c5ea8be28 100644
--- a/core/embed/projects/prodtest/CHANGELOG.md
+++ b/core/embed/projects/prodtest/CHANGELOG.md
@@ -1,4 +1,45 @@
+## 0.3.4 [21st October 2025]
+
+### Added
+- Allow rework of unit variant. [#5809]
+- Added an argument to the ping command. [#5940]
+
+### Fixed
+- Exit pairing screen when already paired host connects. [#5897]
+- Switched Tropic revision to ACAB. [#5900]
+- Fixed issues with USB VCP stability. [#5940]
+
+## 0.3.3 [(internal release)]
+
+### Added
+- Add trusted anchors for device certificates. [#5697]
+
+### Changed
+- Make `tropic-lock()` restrict access to 64 MAC-and-destroy slots. [#5845]
+
+## 0.3.2 [(internal release)]
+
+### Changed
+- Minor fixes and changes.
+
+## 0.3.1 [(internal release)]
+
+### Added
+- Added a check for the subject of the device certificate. [#5162]
+- Add the `secrets-init` command to generate and write secrets to flash. [#5281]
+- Add the `optiga-pair` command to pair the Optiga with the MCU. [#5281]
+- Add Tropic provisioning commands. [#5525]
+- Add the `tropic-keyfido-read` command. [#5657]
+
+### Changed
+- Rename otp-device-id-write to otp-device-sn-write.
+
+### Fixed
+- Removed the extra CRLF added to each response line in non-interactive mode. [#5595]
+- Fixed wpc-info command - fixed hex formatting, args moved to OK. [#5603]
+- Fixed arguments count check in the secrets-certdev-write command. [#5604]
+
## 0.3.0 [16th July 2025]
### Added
@@ -124,4 +165,17 @@
[#4682]: https://github.com/trezor/trezor-firmware/pull/4682
[#4735]: https://github.com/trezor/trezor-firmware/pull/4735
[#5050]: https://github.com/trezor/trezor-firmware/pull/5050
+[#5162]: https://github.com/trezor/trezor-firmware/pull/5162
[#5227]: https://github.com/trezor/trezor-firmware/pull/5227
+[#5281]: https://github.com/trezor/trezor-firmware/pull/5281
+[#5525]: https://github.com/trezor/trezor-firmware/pull/5525
+[#5595]: https://github.com/trezor/trezor-firmware/pull/5595
+[#5603]: https://github.com/trezor/trezor-firmware/pull/5603
+[#5604]: https://github.com/trezor/trezor-firmware/pull/5604
+[#5657]: https://github.com/trezor/trezor-firmware/pull/5657
+[#5697]: https://github.com/trezor/trezor-firmware/pull/5697
+[#5809]: https://github.com/trezor/trezor-firmware/pull/5809
+[#5845]: https://github.com/trezor/trezor-firmware/pull/5845
+[#5897]: https://github.com/trezor/trezor-firmware/pull/5897
+[#5900]: https://github.com/trezor/trezor-firmware/pull/5900
+[#5940]: https://github.com/trezor/trezor-firmware/pull/5940
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.