Skip to content

Releases: AdvancedBlockchainSecurity/SolidityDefend

Release v2.0.15

Choose a tag to compare

@github-actions github-actions released this 15 Jul 22:44
2eced80

Fixed

  • centralization-risk whole-file scoping (72 → 20 findings) — check_contract_centralization read the entire file instead of the contract under analysis. Because the detector registry runs once per contract, a single selfdestruct anywhere in a file invented a finding for every contract in it; 46 of the 72 were flagged on contracts containing no selfdestruct at all. The bug ran inverse too, letting a timelock keyword in a sibling contract suppress a genuinely vulnerable one. Findings are now scoped to the contract's own span. Pattern 1 additionally requires an owner gate — an ungated selfdestruct is callable by anyone, so "controllable by single address" was false; that case belongs to selfdestruct-abuse. The timelock heuristic is now case-insensitive (SELFDESTRUCT_DELAY was missed) and has_owner_gate recognizes manager gates. (ADV-231)
  • block-dependency over-reporting (21 → 5 findings) — is_deadline_comparison was only applied to if conditions, leaving it dead code for require(block.timestamp <= deadline), the dominant real-world idiom; it now covers require/assert arguments. A block value that is merely stored (lastUpdate = block.timestamp), placed in a struct field, or passed as a deadline argument is bookkeeping — it is now flagged only when it feeds a hash (randomness) or a modulo (selection). names_deadline matches timestamp, guarded so block.timestamp's own member cannot match and suppress every ordering comparison. (ADV-231)
  • gas-griefing false positives (13 → 4 findings) — the detector flagged any .call in a loop without a gas limit without asking who controls the batch. In the Multicall/ERC-7821 pattern the caller supplies the targets and pays the gas, so a callee burning gas only fails the submitter's own transaction. Caller-supplied batches are skipped; value-bearing distribution over a storage recipient list still fires. (ADV-231)
  • Contract-level findings reported at line 1 — centralization-risk, erc4337-entrypoint-trust, and hardware-wallet-delegation hardcoded line 1, so the CLI's (detector, file, line) deduplication collapsed genuinely distinct per-contract findings. They now report at the contract's declaration line. (ADV-230)

Changed

  • Ground-truth validation: false positives 170 → 93 (−45%), precision 46.7% → 61.6%, F1 0.637 → 0.762. Recall unchanged at 149/149 with 0 clean-contract false positives. Every change is a correctness fix verified against source; no known_false_positives suppression was used. (ADV-231)

Release v2.0.14

Choose a tag to compare

@github-actions github-actions released this 12 Jul 22:37
208ba66

Fixed

  • array-bounds-check recall regression from 2.0.13 — the Gate 1 tightening (require array params to be index-accessed) was too aggressive: it suppressed the classic parallel-array bug where a loop is bounded by one array's .length and indexes a different array (e.g. for (i < users.length) { … isActive[i] … }) because only one array used [i] syntax. Gate 1 now flags when ≥1 array param is index-accessed AND ≥2 params participate in the iteration (index access or a name.length loop bound). Thin forwarders (no index access) stay suppressed; OpenZeppelin false positives remain at 17. (ADV-214)

Release v2.0.12

Choose a tag to compare

@github-actions github-actions released this 20 Jun 17:38
85079b9

Release v2.0.12

Release v2.0.11

Choose a tag to compare

@dehvCurtis dehvCurtis released this 20 Jun 05:29
43fd9f9

Release v2.0.11

Release v2.0.10

Choose a tag to compare

@github-actions github-actions released this 23 May 22:29
d6383b6

Release v2.0.10

Release v2.0.9

Choose a tag to compare

@github-actions github-actions released this 01 Mar 06:58
5fcf30d

Changed

  • Rebranded from BlockSecOps to Apogee (0xApogee.com) across terminal output, JSON metadata, documentation, and config files
  • GitHub organization moved from BlockSecOps to AdvancedBlockchainSecurity
  • Docker Hub image renamed to apogee/soliditydefend
  • Homebrew tap updated to AdvancedBlockchainSecurity/tap
  • Repository cleanup: removed ~33MB of binary artifacts, internal task docs, legacy src/ directory, duplicate github/ directory, internal QA reports, old baselines, and misc artifacts

Release v2.0.8

Choose a tag to compare

@github-actions github-actions released this 16 Feb 23:01
1be8248

Release v2.0.8

Release v2.0.1

Choose a tag to compare

@github-actions github-actions released this 14 Feb 01:28
4f63022

Fixed

  • Re-enabled 3 disabled detectors — oracle-single-source, l2-block-number-assumption, and l2-push0-cross-deploy were disabled in v2.0.0 due to excessive false positives. Tightened detection logic to achieve 0 FPs while maintaining 100% recall.
    • oracle-single-source (145 FPs → 0): Added Chainlink infrastructure gate, safe patterns library integration (multi-oracle, TWAP, staleness), view/pure function filtering, expanded fallback recognition
    • l2-block-number-assumption (30 FPs → 0): Added L2 context gate requiring L2-specific interfaces/chain IDs, governance snapshot whitelist, simple assignment skip, defensive zero-check skip
    • l2-push0-cross-deploy (40 FPs → 0): Comment stripping for keyword matching, require block.chainid evidence, per-contract body extraction, removed overly broad keywords (blast, scroll, base chain)
  • Precision maintained at 18.4% — 77/77 TPs, 0 FPs on re-enabled detectors

Release v2.0.0

Choose a tag to compare

@github-actions github-actions released this 13 Feb 23:21
a274f87

Release v2.0.0

Release v1.10.24

Choose a tag to compare

@github-actions github-actions released this 13 Feb 21:04
c913eea

Fixed

  • Fixed 4 pre-existing unit test failures in defi-yield-farming-exploits and multisig-bypass detectors
  • All 367 workspace tests now pass with 0 failures