defirisk.co
rubric v1.7.0

Shared-library version with known-vuln status

Sky Lending (formerly MakerDAO)'s assessment for RD-F-135 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

USDS uses OZ upgradeable contracts (Solidity 0.8.21 compatible version, likely v4.x or v5.x) — no known CVE/GHSA for the applicable version range. Core MCD contracts written from scratch without OZ libraries. DappSys libraries audited by Trail of Bits 2017-2018.

Sources #

  • URL
    https://github.com/sky-ecosystem/usds/blob/master/remappings.txtretrieved 2026-04-27
  • URL
    https://github.com/sky-ecosystem/audits/tree/master/dappsysretrieved 2026-04-27

Methodology #

Identify the version of key shared libraries (OZ, Solady, Solmate) used and check against CVE/GHSA databases for any active advisory.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sky-lending factor RD-F-135 score green collected_at 2026-04-28 00:43:18