GitHub malicious-dependency incident touching protocol deps
Spiko's assessment for RD-F-160 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
OZ v5.4.0 is the current stable EVM dependency; no GHSA advisory flags it as malicious. Starknet uses Cairo/Scarb ecosystem with no flagged malicious release in the trailing 90-day window. Stellar uses Rust/Cargo dependencies from Halborn-audited stellar-contracts repo (audited 2025-09). Last EVM GitHub commit 2026-03-03 with no supply-chain incident in surrounding timeframe. No malicious dependency release identified.
Sources #
- GitHubSpiko EVM contracts repo — dependency setspiko-tech/contracts OZ v5.4.0; spiko-tech/stellar-contracts Halborn-audited Sep 2025; no GHSA advisory for these dependency versionsretrieved 2026-05-16
- Spiko data cache — GitHub OZ version00-data-cache.json github.oz_contracts_version 5.4.0; last_commit_date 2026-03-03retrieved 2026-05-16
Methodology #
Determine whether a security advisory flags a malicious release in a dependency consumed by this protocol.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol spiko factor RD-F-160 score green collected_at 2026-05-15 22:52:13