defirisk.co
rubric v1.7.0

Dependency manifest uses unpinned versions

Raydium's assessment for RD-F-133 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

CLMM: anchor-lang =0.32.1, anchor-spl =0.32.1, bytemuck 1.19.0 — all exact pinning. Exception: uint is a git dep from raydium-io/parity-common (Raydium-controlled org, no external supply-chain risk). CPMM: anchor-lang 0.32.1, anchor-spl 0.32.1 — exact. Standard AMM: solana-program =2.1.0, spl-token =7.0.0 — exact. Dev deps (test-only) use ranges. All production security-critical dependencies are exactly pinned.

Sources #

Methodology #

Determine whether `package.json`, `Cargo.toml`, or `foundry.toml` uses `^` or `~` version ranges for security-critical libraries (OpenZeppelin, Solady, etc.).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol raydium factor RD-F-133 score green collected_at 2026-04-29 12:31:55