Solc version used (known-bug versions flagged)
SUNSwap (sun.io)'s assessment for RD-F-170 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
V2/V3 use Solidity 0.7.6 (EOL/legacy; only Low-severity DirtyBytesArrayToStorage bug active). V4 uses 0.8.26 (current; one Low-severity bug). Vyper 0.2.8 and 0.3.10 — both outside July-2023 reentrancy range (0.2.15–0.3.0). Yellow due to EOL solc 0.7.x on V2/V3 operative surfaces.
Sources #
- URLVyper reentrancy vulnerability advisoryVyper July 2023 reentrancy advisory — affected range 0.2.15–0.3.0retrieved 2026-05-17
- Etherscan solc known bugsEtherscan solcbuginfo — solc 0.7.6 known bugs: DirtyBytesArrayToStorage (Low)retrieved 2026-05-17
- SUNSwap V3 hardhat configsunswap-v3-contracts hardhat.config.ts — solc 0.7.6 confirmed; Vyper 0.2.8 and 0.3.10retrieved 2026-05-17
Methodology #
Identify the Solidity compiler version used for deployed bytecode and flag if it appears on the known-bug list (solc bugs.json or Vyper 0.2.15–0.3.0 range).
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol sunswap factor RD-F-170 score yellow collected_at 2026-05-17 14:37:31