Dependency had malicious-release incident (last 90d)
Falcon Finance's assessment for RD-F-134 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No dependency manifest accessible (private/no repo). No GHSA advisory for OZ upgradeable or Solidity stdlib in last 90 days identified. Cannot fully assess due to closed source.
Detail #
No npm/foundry lockfile available. Identifiable dependencies: OZ contracts-upgradeable (version unknown) and Solidity standard library. No GHSA advisory affecting OZ contracts-upgradeable in last 90 days found as of 2026-05-12. Cannot confirm dependency tree completeness without a public manifest.
Sources #
- URLGitHub Security AdvisoriesGitHub Security Advisories — no OZ upgradeable advisory in last 90 daysretrieved 2026-05-12
Methodology #
Determine whether any npm/PyPI/crates.io dependency of this protocol had a flagged malicious release in the trailing 90 days.
See the full factor methodology and distribution across all protocols →