Case study

Soroban Upgrades

Soroban Upgrades checks compiled Soroban contract upgrades before signer approval. It produces stable reports and deterministic review evidence.

Eloiz open-source project
Ecosystem
Stellar / Soroban
Category
Release verification
Status
Stable open-source release
Record year
2026
Project factsStable open-source release

Stable release v1.0.7

80% minimum core line coverage

Scheduled parser and generated-WASM fuzzing

5 attested platform archives

Problem

Why this project exists

Soroban replaces contract WASM while it keeps the contract address and ledger state. A source diff cannot prove that the compiled artifact is safe. Teams must review interfaces, stored data, upgrade paths, and protocol capabilities.

Approach

System design

The CLI treats WASM and JSON as untrusted input. It compares exact compiled artifacts, checks public interfaces, storage evidence, contract versions, upgrade reachability, and protocol compatibility. Each finding labels its evidence as fact, inference, or unknown.

Result

Current release

Version 1.0.7 is the stable release. CI enforces core coverage, dependency policy, cross-platform tests, parser fuzzing, and generated-WASM fuzzing. The release provides stable reports, crates.io packages, and attested binaries. The checker never holds keys, signs data, uploads WASM, deploys contracts, or submits transactions. It is not a contract audit.

Install v1.0.7

Start with a pinned release.

Use a release installer for a prebuilt binary. Rust users can compile the same pinned release from source.

macOS and Linux

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/bielcarpi/soroban-upgrades/releases/download/v1.0.7/soroban-upgrades-cli-installer.sh | sh

Windows PowerShell

powershell -ExecutionPolicy Bypass -c "irm https://github.com/bielcarpi/soroban-upgrades/releases/download/v1.0.7/soroban-upgrades-cli-installer.ps1 | iex"

Cargo

cargo install soroban-upgrades-cli --version 1.0.7 --locked

The Cargo command downloads the pinned release from crates.io and compiles it with Rust 1.93 or later.

For controlled environments, download the platform archive and verify its GitHub attestation before extraction.

Technical details

Stack and source

  • Rust
  • Soroban SDK
  • WASM
  • Stellar CLI
  • Contract Spec XDR
  • libFuzzer

Have a project in mind?

Tell us what you're building.

Tell us what you are building, where the system stands, and what needs to happen next. A founder will reply directly.