Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
90 commits
Select commit Hold shift + click to select a range
6b04006
Merge pull request #421 from keepkey/release/7.14.0
pastaghost Apr 5, 2026
b0abf99
release: harden 7.14.2 signing and display paths
BitHighlander Aug 26, 2026
2d2153b
fix: close 7.14.2 security boundaries
BitHighlander Aug 26, 2026
251f7a3
fix: close 7.14.2 presign audit findings
BitHighlander Aug 26, 2026
7f6fded
fix(ethereum): preserve full chain IDs in token lookup
BitHighlander Aug 27, 2026
0a5c217
fix(ethereum): scope native pseudo-token metadata
BitHighlander Aug 27, 2026
39fdc88
fix(authenticator): clear seed string after processing
Copilot Aug 27, 2026
ef1bd8c
fix(signing): reject empty message sessions
BitHighlander Aug 27, 2026
0565b3c
Merge pull request #470 from keepkey/fix/7142-presign-state-secret-cl…
BitHighlander Aug 27, 2026
57d6024
fix(tendermint): bind signed text and fees to review
BitHighlander Aug 27, 2026
2a430da
fix(ethereum): require AdvancedMode for transformERC20
BitHighlander Aug 27, 2026
7be96a7
fix(security): consolidate 7.14.2 audit remediation
BitHighlander Aug 27, 2026
d91aa93
test: pin MakerDAO advanced-mode integration coverage
BitHighlander Aug 27, 2026
bcee122
Merge pull request #473 from keepkey/fix/7142-consolidated-audit-reme…
BitHighlander Aug 27, 2026
3df4038
Merge branch 'master' into release/7.14.2-rc31
pastaghost Aug 27, 2026
abe29d1
release: prepare 7.14.3 bitcoin-only candidate
BitHighlander Aug 28, 2026
32a445b
fix(storage): stage unsigned decoder replay for 7.14.3
BitHighlander Sep 8, 2026
cc38154
fix: enforce decoder bounds and terminal rejection for Bitcoin-only r…
BitHighlander Sep 8, 2026
21ceae2
fix(storage): carry complete buffer capacities into Bitcoin-only product
BitHighlander Sep 8, 2026
7923904
style: trim storage regression trailing blank line
BitHighlander Sep 8, 2026
d333c9d
fix(storage): invalidate cached wallet on passphrase setting changes
BitHighlander Sep 8, 2026
e513ce4
fix(storage): complete cipher scratch cleanup in release product
BitHighlander Sep 8, 2026
5ea5174
fix(eos): preserve authorization hash and disclosure agreement
BitHighlander Sep 8, 2026
8f37a67
fix(storage): revoke workflows at low-level authorization boundaries
BitHighlander Sep 8, 2026
86e81d9
build: declare generated token definition byproducts
BitHighlander Sep 8, 2026
b51024d
docs(release): assemble 7.14.3 candidate with explicit acceptance con…
BitHighlander Sep 8, 2026
de0251b
docs(release): accept combined 7.14.3 with both variant receipts
BitHighlander Sep 8, 2026
747e800
fix(release): route audited ARM artifacts by build variant
BitHighlander Sep 8, 2026
1d439b9
fix(release): package firmware variants with accurate hash filenames
BitHighlander Sep 8, 2026
2678b07
docs(release): distinguish presign hashes from signed variant images
BitHighlander Sep 8, 2026
a67b7f7
fix(report): require complete native evidence inputs
BitHighlander Sep 8, 2026
0f5283d
fix(rehearsal): keep bitcoin-only unit image identity separate
BitHighlander Sep 8, 2026
97f9701
fix(transport): wipe tiny-message credential copies
BitHighlander Sep 8, 2026
47eae60
fix(transport): wipe consumed receive packet storage
BitHighlander Sep 8, 2026
1ce4d39
fix(ripple): preserve displayed address across debug requests
BitHighlander Sep 9, 2026
0292e7f
test(ripple): pin displayed-address response regression
BitHighlander Sep 9, 2026
06d84f5
fix(ripple): reject unsupported memo on 7.14.3
BitHighlander Sep 9, 2026
89c03a5
test(ripple): pin unsupported memo rejection regression
BitHighlander Sep 9, 2026
9d66360
fix(confirm): consume each debug backup page acknowledgement
BitHighlander Sep 9, 2026
8624927
fix(ping): initialize response after protected confirmation
BitHighlander Sep 9, 2026
c23460b
refactor(fsm): remove duplicate setup ceremony guard definition
BitHighlander Sep 9, 2026
e298e08
fix(setup): require live ceremony authorization before commit
BitHighlander Sep 9, 2026
27865aa
test(reset): pin dice backup subpage collector correction
BitHighlander Sep 9, 2026
7eea5be
fix(storage): bound and terminate loaded public strings
BitHighlander Sep 9, 2026
8d08a88
fix(emulator): erase flash sectors during storage rotation
BitHighlander Sep 9, 2026
374efb1
fix(pin): scrub verification and wipe-code buffers on every return
BitHighlander Sep 9, 2026
1f97ea5
test(setup): verify staging isolation and foreign commit revocation
BitHighlander Sep 9, 2026
f342d5a
fix(transport): unwind tiny receive failures without duplicate replies
BitHighlander Sep 9, 2026
9af75ac
style: format terminal tiny receive rejection calls
BitHighlander Sep 9, 2026
8ef50c1
test(storage): pass the transition flag separately during reset valid…
BitHighlander Sep 9, 2026
e25201c
fix(storage): port V17 durable commits and hardware-compatible emulat…
BitHighlander Sep 9, 2026
1083292
fix(storage): recover pending replacement over torn legacy record
BitHighlander Sep 9, 2026
450851b
test(storage): pin CRC-aware migration fixtures
BitHighlander Sep 9, 2026
3dd0d76
fix(signing): bound input-history hash to transaction ID bytes
BitHighlander Sep 9, 2026
c8f47fc
fix(signing): retain input history throughout the output phase
BitHighlander Sep 9, 2026
44d0c60
fix(signing): preserve extended wallet prefix for mixed-mode change
BitHighlander Sep 9, 2026
3305563
test(storage): export commit snapshots for released bootloader replay
BitHighlander Sep 9, 2026
684a277
fix(signing): preserve accepted history when duplicate output is refused
BitHighlander Sep 9, 2026
0f64f80
fix: preserve incompatible pending storage before recovery writes
BitHighlander Sep 9, 2026
0fe01bc
fix(scope): remove bootloader-coupled storage durability batch
BitHighlander Sep 9, 2026
b30cd6e
deps: pin python-keepkey to the consolidated canonical head
BitHighlander Sep 10, 2026
cdd9c42
deps: advance python-keepkey to the corrected canonical head
BitHighlander Sep 10, 2026
f8f384f
deps: advance python-keepkey to the corrected canonical head
BitHighlander Sep 10, 2026
4c7615c
fix(reset): ignore display_random, matching 7.14.2 and 7.15
BitHighlander Sep 10, 2026
238c3a9
deps: advance python-keepkey to the corrected canonical head
BitHighlander Sep 10, 2026
f34f1a3
docs(dice): add the ColdCard comparison and name the gap
BitHighlander Sep 10, 2026
277f4f7
ci: stop serializing the graph behind cppcheck; cache the base image …
BitHighlander Sep 11, 2026
3e6899c
fix: seven defects found auditing this release's own diff
BitHighlander Sep 12, 2026
9cb0a8e
fix(eth): pin the THORChain deposit decoder to its router, and show m…
BitHighlander Sep 12, 2026
10c600b
fix(recovery): refuse a cipher ceremony that produced no words
BitHighlander Sep 12, 2026
b0bb109
refactor(mayachain): one place decides a denom's exponent
BitHighlander Sep 12, 2026
a29186a
fix(eth): pin the Maya router too, not just THORChain's
BitHighlander Sep 12, 2026
f690fdd
fix: five defects on the bitcoin-only line
BitHighlander Sep 12, 2026
8631d48
build: gate this line on the same 16 KiB runtime-SRAM reserve as the …
BitHighlander Sep 12, 2026
36ea6cf
fix(eth): the router label is a string literal, so hold it in a const…
BitHighlander Sep 12, 2026
c91090d
docs(release): make the 7.14.3 receipt describe this tree
BitHighlander Sep 12, 2026
7deb95a
docs(dice): describe the ceremony that ships, and fix the repro command
BitHighlander Sep 12, 2026
852ad7a
docs(release): certify the audited head
BitHighlander Sep 12, 2026
cf17dc5
fix(eth): scrub the derived node on the transfer path's error exits
BitHighlander Sep 12, 2026
fc53946
fix(signing): size the sighash scratch from the field it copies
BitHighlander Sep 12, 2026
1d885c3
fix(eth): name the asset from the transaction being confirmed
BitHighlander Sep 12, 2026
f6c8ead
fix(rand): re-read the hardware fault latch after the draw, not only …
BitHighlander Sep 12, 2026
611a407
fix(tiny-json): stop defining a global named errno
BitHighlander Sep 12, 2026
f19b9d3
fix(deps): point each submodule branch key at a branch holding the pin
BitHighlander Sep 12, 2026
18606c1
docs(release): certify the audited head
BitHighlander Sep 12, 2026
bca1db3
feat(dice): two opt-in verifiable modes, host-selected with on-device…
BitHighlander Sep 11, 2026
5565929
fix(dice): review fixes -- SRAM, consent text, no_backup, capability bit
BitHighlander Sep 11, 2026
601981f
deps: advance python-keepkey (native dice tests catalogued)
BitHighlander Sep 11, 2026
2e1aaf5
fix(deps): point each submodule branch key at a branch holding the pin
BitHighlander Sep 12, 2026
f23557f
fix(dice): stop the verifier accusing the device over a missing flag
BitHighlander Sep 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 47 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# Copilot code review instructions

How reviews on this repository should be conducted. These govern the review
process itself, not what counts as good code.

## Report everything in one pass

Report every finding you have in a single review. Do not hold findings back for a
later round.

- Review the complete diff — every changed file, every changed hunk. Do not stop
partway through.
- Finding several problems early is not a reason to end the review. It is a reason
to keep going.
- Do not sample. If a file has twelve problems, report twelve.
- Comment on every instance of a repeated problem, not just the first. If the same
mistake appears in six places, mark all six — the author fixes what is marked, so
"and similar issues elsewhere" leaves five defects in the branch.

## Include minor and uncertain findings

Do not filter down to only the findings you are most confident about.

- Report low-severity and minor issues alongside significant ones.
- Report a finding you are less than certain about, and say plainly what you are
unsure of. A finding the author dismisses in ten seconds costs far less than an
entire extra review cycle.
- Label each finding's severity so the author can triage quickly instead of having
to weigh every comment equally.

## Converge in as few rounds as possible

Every additional review round costs the author a full cycle. Target:

- **One round** — ideal. Everything surfaced on the first review.
- **Two or three rounds** — acceptable.
- **Five rounds** — the absolute ceiling.

A later round should raise only problems introduced by the previous round's fixes.
A problem that was present in the original diff and went unmentioned until round
three is a review failure, not a thorough review.

## Do not trade thoroughness for brevity

None of the above is a reason to scrutinize less carefully. The goal is more
findings per review, not faster reviews. Depth of analysis stays the same; what
changes is that all of it arrives at once.
Loading
Loading