This security audit aimed to verify the migration of various Solidity 0.5.x contracts to the 0.8.25 version. Special attention was given to potential storage collisions and to language-breaking changes. The performed audit did not identify any critical vulnerabilities. The code is well-written, and care has been taken to limit the audited [pull request](https://github.com/VenusProtocol/venus-protocol/pull/607/) (PR) to only Solidity version changes. However, we did note that the current test coverage is not in line with industry standards. It is currently at 59%; we expected it to be at least 90%. Improving coverage is key in identifying potential issues when migrating contracts and ensuring the implementation follows the expected protocol behaviour.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 2 | - | - | - | 2 |
Acknowledged | - | - | - | - | 0 |
Fixed | 1 | - | - | - | 1 |
| Total | 3 | 0 | 0 | 0 | 3 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |