defirisk.co
rubric v1.7.0

Deployed bytecode reproducibility

SUNSwap (sun.io)'s assessment for RD-F-145 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Source code publicly available on GitHub (sun-protocol org). V3 uses Hardhat+Solidity (OZ 3.4.1-solc-0.7-2); V4 uses Hardhat+Foundry with Solidity 0.8.26. No CI/CD build artifacts or deterministic build verification confirmed. TRON-substrate bytecode verification is less standardized than EVM. Theoretically reproducible but not confirmed in practice.

Sources #

  • Internal
    SUNSwap data cache — build tooling00-data-cache.json github.oz_contracts_version: 3.4.1-solc-0.7-2, hardhat_config_present: trueretrieved 2026-05-17
  • GitHub
    sun-protocol GitHub org — public sourcegithub.com/sun-protocol: public repos with source code; 00-data-cache.json oz_contracts_version: 3.4.1-solc-0.7-2retrieved 2026-05-17

Methodology #

Determine whether anyone can independently reproduce the deployed bytecode from the repo and declared build toolchain.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sunswap factor RD-F-145 score yellow collected_at 2026-05-17 14:37:31