Dependency had malicious-release incident (last 90d)
Orca's assessment for RD-F-134 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No GHSA/crates.io advisories found for the Rust crates used (anchor-lang 0.32.1, solana-program 2.2.1, pinocchio, borsh, bytemuck, arrayvec, etc.) involving malicious releases in the trailing 90 days (2026-02-16 to 2026-05-16). The two active Anchor GHSA advisories (GHSA-429q, GHSA-c6rc, published 2026-05-07/08) are design vulnerability disclosures affecting anchor-lang 1.0.0+ only, not malicious supply-chain releases, and Orca uses 0.32.1. The solana-web3.js malicious release (Dec 2024, GHSA-jcxm-7wvp-g6p5) affected JavaScript tooling only, not the on-chain Rust program.
Sources #
- URLAnchor framework security advisories (both 2026-05-07/08, affect 1.0.0+ not 0.32.1)https://github.com/coral-xyz/anchor/security/advisoriesretrieved 2026-05-16
- programs/whirlpool/Cargo.toml (all deps use = pinning)https://github.com/orca-so/whirlpools/blob/main/programs/whirlpool/Cargo.tomlretrieved 2026-05-16
Methodology #
Determine whether any npm/PyPI/crates.io dependency of this protocol had a flagged malicious release in the trailing 90 days.
See the full factor methodology and distribution across all protocols →