feat(upgrade): add Soroban contract upgrade safety analyzer - #61
Merged
Nanle-code merged 1 commit intoJul 29, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
starforge upgrade analyze, a static safety analyzer that compares the current and candidate Soroban contract WASM files before an upgrade.The analyzer detects potentially breaking interface and storage-layout changes, produces human-readable or JSON reports, and returns a non-zero exit code when breaking findings are present.
Changes
Added the new command:
Added confirmed interface diffing for:
Added best-effort storage-key analysis for conventional
DataKeyandStorageKeycontract types.Clearly distinguishes evidence confidence:
confirmedfor contract-spec interface metadataheuristicfor inferred storage findingsAdded
breaking,warning, andinforisk classifications.Added JSON output and report persistence:
Added a versioned JSON schema for downstream CI validation.
Suppressed decorative output automatically when JSON format is selected.
Added CI documentation and a recommended GitHub Actions upgrade gate.
Exit Behavior
Storage Analysis Limitations
Standard Soroban contract metadata does not expose storage durability or stored value types. Storage findings are therefore explicitly marked as heuristic and recommend manual verification.
Testing
cargo check --all-targetspasses.Closes #60.