Shared-library version with known-vuln status
Sky Lending (formerly MakerDAO)'s assessment for RD-F-135 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
USDS uses OZ upgradeable contracts (Solidity 0.8.21 compatible version, likely v4.x or v5.x) — no known CVE/GHSA for the applicable version range. Core MCD contracts written from scratch without OZ libraries. DappSys libraries audited by Trail of Bits 2017-2018.
Sources #
- URLhttps://github.com/sky-ecosystem/usds/blob/master/remappings.txtretrieved 2026-04-27
- https://github.com/sky-ecosystem/audits/tree/master/dappsysretrieved 2026-04-27
Methodology #
Identify the version of key shared libraries (OZ, Solady, Solmate) used and check against CVE/GHSA databases for any active advisory.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol sky-lending factor RD-F-135 score green collected_at 2026-04-28 00:43:18