Why this exists

Quiet fixes can create loud consequences.

Open source lets anyone inspect the code. In practice, very few people have the time, context, and incentive to read every commit that could change a security boundary.

The gap

A patch is not the same as disclosure.

Security-critical code changes every day. Some fixes receive a clear advisory, researcher credit, and actionable guidance. Others arrive under a generic commit title and disappear into the history.

That gap matters. Users cannot make informed decisions about old keys, persistent exposure, or vendor trust if they never learn what was fixed. Researchers may stop donating their time when careful work is neither acknowledged nor communicated. Vendors lose a feedback loop they need.

CommitWatch turns a repository’s permanent record into a public accountability layer.

Bitcoin first, then the wider open-source world.

Bitcoin wallets and infrastructure are the first focus because tiny mistakes can become irreversible losses. The same method applies anywhere public code protects people: cryptography, authentication, privacy tools, critical infrastructure, AI systems, and supply chains.

The long view

Keep independent eyes on the code.

CommitWatch is designed as durable public-interest infrastructure: open evidence, explicit uncertainty, and a record vendors cannot quietly rewrite.

See watched projects →