Skip to content

Remove the Slither and Snyk CI jobs - #3018

Merged
clement-ux merged 3 commits into
masterfrom
clement/remove-slither-snyk
Oct 8, 2026
Merged

clement-ux merged 3 commits into
masterfrom
clement/remove-slither-snyk

Conversation

@clement-ux

@clement-ux clement-ux commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Removes the Slither and Snyk jobs from CI. Both cost maintenance and block nothing.

Slither

  • It never blocks a merge: master has no required status checks.
  • It has passed on all of the last 17 PR runs.
  • New triage entries were added only 3 times in two years (Oct 2024, Apr 2025, Jun 2025).
  • The last two "fix Slither" PRs (Fix Slither CI #2870, Fix slither shadow var #2979) only added slither-disable comments to VaultAdmin and VaultStorage. The tool made us touch core contracts to silence it.
  • The install is fragile: it downloads solc 0.8.7, which nothing compiles with any more, and installs slither-analyzer unpinned.
  • slither.config.json excluded VaultInitializer and StableMath from analysis anyway.
  • The security review checklist does not require it. Audits, the solidity-auditor skill and Hypernative remain.

Snyk

  • continue-on-error: true, so it can never fail a PR. Its results only reach the Snyk dashboard.
  • npm supply-chain protection is already in pnpm-workspace.yaml (minimumReleaseAge: 10080, i.e. 7 days).

Code Change

  • .github/workflows/foundry.yml: drop the slither and snyk jobs. The 10 remaining jobs are unchanged.
  • Delete contracts/slither.config.json and contracts/slither.db.json (118 triage entries, 497 KB).
  • Remove the slither and slither:triage pnpm scripts.
  • Remove the Slither section from contracts/README.md and the CI row from scripts/deploy/ARCHITECTURE.md.
  • The 94 slither-disable comments in contracts/contracts/ are deliberately kept, so no contract source changes.

⚠️ Before merging

Snyk is currently the only dependency scanner on this repo. In this repo's settings, the Dependency graph is disabled and Dependabot alerts are inactive. The 53 "vulnerabilities" GitHub shows on push are frozen alerts on yarn.lock files that were deleted on 2026-09-08 (#2998).

An admin should enable, under Settings → Code security:

  1. Dependency graph
  2. Dependabot alerts

Both are free. Once they are on, the stale alerts should resolve against the current pnpm-lock.yaml files.

After merge, the SNYK_TOKEN repo secret and the Snyk project can be deleted.

Testing

  • The workflow YAML parses, and the 10 remaining jobs are listed.
  • No remaining references to slither/snyk outside the kept slither-disable comments and the embedded sources in deployments/*.json metadata.

🤖 Generated with Claude Code

Neither job ever blocks a merge: master has no required checks and Snyk
runs with continue-on-error. Slither has passed on every recent PR, its
last fixes only added slither-disable comments to core contracts, and its
install downloads an unused solc 0.8.7 plus an unpinned slither.

- drop both jobs from foundry.yml
- delete slither.config.json and slither.db.json and the pnpm scripts
- remove the Slither sections from the README and the deploy docs
- keep the slither-disable comments in contracts/ to leave them untouched
@clement-ux clement-ux self-assigned this Oct 8, 2026
@clement-ux
clement-ux merged commit 5b2c5d6 into master Oct 8, 2026
10 checks passed
@clement-ux
clement-ux deleted the clement/remove-slither-snyk branch October 8, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants