Slither

Import Slither reports in JSON format. Slither is a static analyser for Solidity smart contracts.

Generate a report with:

slither . --json slither.json

Slither needs a matching solc on the path, which solc-select can manage.

Severity Mapping

Slither reports two independent axes per detector result: impact, which is the severity axis, and confidence, which describes how sure Slither is that the result is real. DefectDojo maps impact and records confidence in the description rather than blending them:

Slither impactDefectDojo severity
HighHigh
MediumMedium
LowLow
InformationalInfo
OptimizationInfo

Slither’s id is a stable hash of the result’s content and is stored as unique_id_from_tool, so a result tracks across re-imports even when line numbers move.

Sample Scan Data

Sample Slither scans can be found here.

Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these hashcode fields:

  • vuln_id_from_tool
  • file_path
  • line