Dependency had malicious-release incident (last 90d)
Jupiter Perpetual Exchange's assessment for RD-F-134 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
The Anchor framework and Solana program crates (the most likely core dependencies) have no malicious-release advisories in the trailing 90 days per GHSA search. No specific dependency manifest is accessible (closed-source), but the core Solana/Anchor ecosystem has not had a supply-chain malicious release incident in this window. Low confidence green due to inability to verify exact dependency list.
Sources #
- URLGitHub Security Advisories — Solana/Anchor ecosystemGitHub Security Advisories (GHSA) — no malicious-release advisory for Anchor framework or Solana program crates in trailing 90 daysretrieved 2026-05-16
Methodology #
Determine whether any npm/PyPI/crates.io dependency of this protocol had a flagged malicious release in the trailing 90 days.
See the full factor methodology and distribution across all protocols →