Repository navigation
Releases: AdvancedBlockchainSecurity/SolidityDefend
Releases · AdvancedBlockchainSecurity/SolidityDefend
Release list
Release v2.0.15
Fixed
centralization-riskwhole-file scoping (72 → 20 findings) —check_contract_centralizationread the entire file instead of the contract under analysis. Because the detector registry runs once per contract, a singleselfdestructanywhere in a file invented a finding for every contract in it; 46 of the 72 were flagged on contracts containing noselfdestructat all. The bug ran inverse too, letting atimelockkeyword in a sibling contract suppress a genuinely vulnerable one. Findings are now scoped to the contract's own span. Pattern 1 additionally requires an owner gate — an ungatedselfdestructis callable by anyone, so "controllable by single address" was false; that case belongs toselfdestruct-abuse. The timelock heuristic is now case-insensitive (SELFDESTRUCT_DELAYwas missed) andhas_owner_gaterecognizesmanagergates. (ADV-231)block-dependencyover-reporting (21 → 5 findings) —is_deadline_comparisonwas only applied toifconditions, leaving it dead code forrequire(block.timestamp <= deadline), the dominant real-world idiom; it now coversrequire/assertarguments. A block value that is merely stored (lastUpdate = block.timestamp), placed in a struct field, or passed as a deadline argument is bookkeeping — it is now flagged only when it feeds a hash (randomness) or a modulo (selection).names_deadlinematchestimestamp, guarded soblock.timestamp's own member cannot match and suppress every ordering comparison. (ADV-231)gas-griefingfalse positives (13 → 4 findings) — the detector flagged any.callin a loop without a gas limit without asking who controls the batch. In the Multicall/ERC-7821 pattern the caller supplies the targets and pays the gas, so a callee burning gas only fails the submitter's own transaction. Caller-supplied batches are skipped; value-bearing distribution over a storage recipient list still fires. (ADV-231)- Contract-level findings reported at line 1 —
centralization-risk,erc4337-entrypoint-trust, andhardware-wallet-delegationhardcoded line 1, so the CLI's(detector, file, line)deduplication collapsed genuinely distinct per-contract findings. They now report at the contract's declaration line. (ADV-230)
Changed
- Ground-truth validation: false positives 170 → 93 (−45%), precision 46.7% → 61.6%, F1 0.637 → 0.762. Recall unchanged at 149/149 with 0 clean-contract false positives. Every change is a correctness fix verified against source; no
known_false_positivessuppression was used. (ADV-231)
Release v2.0.14
Fixed
array-bounds-checkrecall regression from 2.0.13 — the Gate 1 tightening (require array params to be index-accessed) was too aggressive: it suppressed the classic parallel-array bug where a loop is bounded by one array's.lengthand indexes a different array (e.g.for (i < users.length) { … isActive[i] … }) because only one array used[i]syntax. Gate 1 now flags when ≥1 array param is index-accessed AND ≥2 params participate in the iteration (index access or aname.lengthloop bound). Thin forwarders (no index access) stay suppressed; OpenZeppelin false positives remain at 17. (ADV-214)
Release v2.0.12
Release v2.0.11
Release v2.0.10
Release v2.0.9
Changed
- Rebranded from BlockSecOps to Apogee (0xApogee.com) across terminal output, JSON metadata, documentation, and config files
- GitHub organization moved from
BlockSecOpstoAdvancedBlockchainSecurity - Docker Hub image renamed to
apogee/soliditydefend - Homebrew tap updated to
AdvancedBlockchainSecurity/tap - Repository cleanup: removed ~33MB of binary artifacts, internal task docs, legacy
src/directory, duplicategithub/directory, internal QA reports, old baselines, and misc artifacts
Release v2.0.8
Release v2.0.1
Fixed
- Re-enabled 3 disabled detectors —
oracle-single-source,l2-block-number-assumption, andl2-push0-cross-deploywere disabled in v2.0.0 due to excessive false positives. Tightened detection logic to achieve 0 FPs while maintaining 100% recall.oracle-single-source(145 FPs → 0): Added Chainlink infrastructure gate, safe patterns library integration (multi-oracle, TWAP, staleness), view/pure function filtering, expanded fallback recognitionl2-block-number-assumption(30 FPs → 0): Added L2 context gate requiring L2-specific interfaces/chain IDs, governance snapshot whitelist, simple assignment skip, defensive zero-check skipl2-push0-cross-deploy(40 FPs → 0): Comment stripping for keyword matching, requireblock.chainidevidence, per-contract body extraction, removed overly broad keywords (blast, scroll, base chain)
- Precision maintained at 18.4% — 77/77 TPs, 0 FPs on re-enabled detectors
Release v2.0.0
Release v1.10.24
Fixed
- Fixed 4 pre-existing unit test failures in
defi-yield-farming-exploitsandmultisig-bypassdetectors - All 367 workspace tests now pass with 0 failures