<feed xmlns='http://www.w3.org/2005/Atom'>
<title>monzero-gui.git/src, branch main</title>
<subtitle>Monzero desktop wallet graphical interface.
</subtitle>
<id>https://code.monzero.org/monzero-gui.git/atom?h=main</id>
<link rel='self' href='https://code.monzero.org/monzero-gui.git/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/'/>
<updated>2026-08-15T20:26:40Z</updated>
<entry>
<title>Establish Monzero GUI Phase 0 baseline</title>
<updated>2026-08-15T20:26:40Z</updated>
<author>
<name>Monzero Build System</name>
<email>builds@monzero.org</email>
</author>
<published>2026-08-15T20:26:40Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=dceeb88444ce966caa1a133d2926d5f7213c87ff'/>
<id>urn:sha1:dceeb88444ce966caa1a133d2926d5f7213c87ff</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Set desktop file name for the application</title>
<updated>2026-07-02T06:31:19Z</updated>
<author>
<name>Balló György</name>
<email>ballogyor@gmail.com</email>
</author>
<published>2026-07-02T06:20:18Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=db73360ec68a615564a73fd1ee2e7bf7f3491494'/>
<id>urn:sha1:db73360ec68a615564a73fd1ee2e7bf7f3491494</id>
<content type='text'>
This ensures that the XDG toplevel app ID matches with the desktop file
name, so Wayland compositors could match the window with the application
and show the appropriate icon for them.
</content>
</entry>
<entry>
<title>p2pool v4.17.1</title>
<updated>2026-06-28T10:37:24Z</updated>
<author>
<name>SChernykh</name>
<email>15806605+SChernykh@users.noreply.github.com</email>
</author>
<published>2026-06-28T10:37:24Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=f4bfb444f26c51c5073e00329ee7529468ab0573'/>
<id>urn:sha1:f4bfb444f26c51c5073e00329ee7529468ab0573</id>
<content type='text'>
</content>
</entry>
<entry>
<title>wizard: check wallet file directory is writeable</title>
<updated>2026-06-25T16:03:55Z</updated>
<author>
<name>plowsof</name>
<email>plowsof@protonmail.com</email>
</author>
<published>2026-06-25T12:14:09Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=123433dd2caf7f5899c760e172dffb68df3375a7'/>
<id>urn:sha1:123433dd2caf7f5899c760e172dffb68df3375a7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>p2pool v4.17</title>
<updated>2026-06-21T17:36:21Z</updated>
<author>
<name>SChernykh</name>
<email>15806605+SChernykh@users.noreply.github.com</email>
</author>
<published>2026-06-21T17:36:21Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=b3e9423780b0fa648dd3d0f7cb4d97ff70a34376'/>
<id>urn:sha1:b3e9423780b0fa648dd3d0f7cb4d97ff70a34376</id>
<content type='text'>
</content>
</entry>
<entry>
<title>TransactionHistory: prevent CSV formula injection in writeCSV</title>
<updated>2026-06-18T14:29:34Z</updated>
<author>
<name>Thomas</name>
<email>thomas.giudici@proton.me</email>
</author>
<published>2026-06-18T10:17:18Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=0fbb1716fba3847a7d6f60287d20c1d9f03489cf'/>
<id>urn:sha1:0fbb1716fba3847a7d6f60287d20c1d9f03489cf</id>
<content type='text'>
writeCSV wrote the transaction note and subaddress label into the CSV
stripping only the quote character. A cell beginning with =, +, - or @
can be interpreted as a formula by spreadsheet software on open, which
CSV quoting does not prevent.

The transaction note can be attacker-controlled: a payment request's
tx_description is stored as the note when the payment is sent, so a
crafted note can run a spreadsheet formula when the user later exports
and opens their history, potentially enabling data exfiltration or
command execution.

Prefix affected fields with a single quote so they are treated as text;
fields beginning with whitespace or a control character are prefixed too.

Co-authored-by: selsta &lt;selsta@sent.at&gt;
</content>
</entry>
<entry>
<title>Merge pull request #4602</title>
<updated>2026-06-17T18:42:20Z</updated>
<author>
<name>tobtoht</name>
<email>tob@featherwallet.org</email>
</author>
<published>2026-06-17T18:42:20Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=a003cb75b6416488d0a448198e6de03211ae1a67'/>
<id>urn:sha1:a003cb75b6416488d0a448198e6de03211ae1a67</id>
<content type='text'>
1627661 libwalletqt: capture background sync password by value (selsta)

ACKs: plowsof
</content>
</entry>
<entry>
<title>Merge pull request #4603</title>
<updated>2026-06-17T18:41:38Z</updated>
<author>
<name>tobtoht</name>
<email>tob@featherwallet.org</email>
</author>
<published>2026-06-17T18:41:38Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=fdecbd3ec5e928143e5f61c141fbfadfa29dcb27'/>
<id>urn:sha1:fdecbd3ec5e928143e5f61c141fbfadfa29dcb27</id>
<content type='text'>
bfce02b libwalletqt: start wallet refresh worker lazily (selsta)

ACKs: plowsof
</content>
</entry>
<entry>
<title>Merge pull request #4596</title>
<updated>2026-06-15T17:39:40Z</updated>
<author>
<name>tobtoht</name>
<email>tob@featherwallet.org</email>
</author>
<published>2026-06-15T17:39:40Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=0a6ba55c69d4ba748865a530bcda5045d5599f24'/>
<id>urn:sha1:0a6ba55c69d4ba748865a530bcda5045d5599f24</id>
<content type='text'>
082cf9a network: require SSL for HTTPS requests (selsta)

ACKs: plowsof
</content>
</entry>
<entry>
<title>Merge pull request #4597</title>
<updated>2026-06-15T14:41:50Z</updated>
<author>
<name>tobtoht</name>
<email>tob@featherwallet.org</email>
</author>
<published>2026-06-15T14:41:50Z</published>
<link rel='alternate' type='text/html' href='https://code.monzero.org/monzero-gui.git/commit/?id=af56df631270447027b341698e4a3309d8ea2f4e'/>
<id>urn:sha1:af56df631270447027b341698e4a3309d8ea2f4e</id>
<content type='text'>
be9eade QR: skip QImage padding when filling quirc buffer (selsta)

ACKs: plowsof
</content>
</entry>
</feed>
