chore: add code complexity checks to CI - #711
Merged
Merged
Conversation
This reverts commit a964902.
Compares every proxied mainnet implementation against the layout recorded in its deployment artifact, read from the PR base branch so a deploy PR cannot pass by overwriting its own reference. vTokens and Diamond facets are covered explicitly.
|
An entry now excuses only a target whose artifact records no layout to compare against; one that compares badly fails whether or not it is listed. Also corrects the header claim that renaming a variable shifts every slot after it -- it does not.
|
fred-venus
reviewed
Sep 17, 2026
Debugger022
reviewed
Sep 17, 2026
fred-venus
approved these changes
Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two CI gates, both enforced through existing scripts. No contract code changes.
Code complexity
ESLint now caps per-function complexity at 15 for TypeScript:
complexity: ["error", 15]— cyclomaticsonarjs/cognitive-complexity: ["error", 15]— cognitive, viaeslint-plugin-sonarjs@^1.0.4Solhint's
code-complexitywas already at["error", 14]and is untouched. 15 is aceiling, not a target, so a threshold that is already stricter stays where it is.
These run inside
yarn lint, which CI already blocks on, so no workflow change was needed.What the gate found
Four functions were over the limit. One is fixed, three carry an inline
eslint-disable-next-linewith a reason:generateCutParamsscript/deploy/comptroller/facet-cut-params-generator.tsatomicLiquidatescripts/bstock/atomic-liquidate.tsbuildSafeFallbackBatchscripts/bstock/safe-fallback.tssweepOnetests/hardhat/Fork/BStockLiquidatorFork.tsgenerateCutParamswas split into named pipeline stages —resolveNewFacetAddresses,resolveNewSelectors,identifyOldFacets,buildCutEntries,collectRemovals. Purerefactor: every statement is unchanged and runs in the same order.
The two bStock scripts are liquidation tooling and too important to reshape alongside a
lint rollout. They are suppressed here and get their own PR.
The fork test is low priority and does not need fixing.
Storage layout and upgrade safety
New
Upgrade safetyworkflow, pull requests only, running two checks:moved to : #712
Slither: tried and reverted
Added in a964902, reverted in e242e08, kept in history so the next person does not repeat it.
It works, but the signal is not there. 382 findings out of the box. Filtering the vendored
0x fixed-point math library, the legacy contract directories and the known false-positive
detectors got it to 192 — still ~190 unreviewed items, and the high-impact ones were
dominated by patterns that are the architecture rather than bugs: every
controlled-delegatecallhit is a proxy doing delegatecall.A Security tab nobody opens is worse than no Security tab. With AI-assisted development and
review in the loop, generic pattern matching of this kind adds little.
Follow-ups
atomicLiquidateandbuildSafeFallbackBatchin their own PR.review access to Trump, rather than another generic static analyser:
solidity-auditor(AI security audit),x-ray(pre-audit scan: threat model, invariants, entry points) and
fizz(Echidna/Medusafuzz suite generation). https://github.com/pashov/skills
https://solodit.cyfrin.io
https://www.openzeppelin.com/news/introducing-openzeppelin-skills
and more.