defirisk.co
rubric v1.7.0

Static-analyzer high-severity count

Curve Finance's assessment for RD-F-010 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Slither and Semgrep do not support Vyper. Mythril has partial Vyper support but no public run on Curve contracts found. No Vyper-native static analysis CI output is publicly available for Curve contracts. Factor cannot be assessed via standard tools for Vyper codebases. Needs Vyper-specific tool run.

Sources #

Methodology #

Count the number of unique high-severity detector findings from Slither + Mythril + Semgrep run against the deployed verified source (after deduplication across tools).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol curve-v2 factor RD-F-010 score gray collected_at 2026-04-28 19:48:40