Audit with Radar
Overview
bake audit
bake audit runs Radar โ Auditware's static analyzer for Anchor/Rust contracts. This is the tool the Solana docs recommend.
Info: bake implements no security heuristics of its own. All findings are Radar's, labelled "powered by Radar."
Requirements
- Radar installed (
curl -L https://raw.githubusercontent.com/auditware/radar/main/install-radar.sh | bash) - Docker running (Radar is a 5-container compose stack)
If Radar is missing, bake prints the install command and exits.
Usage
bake audit
Exit codes
| Code | Meaning |
|---|---|
| 0 | No critical/high findings |
| 1 | At least one critical/high finding |
| 2 | Operational error (Radar missing, Docker unavailable) |
Deploy gating
bake deploy --require-audit
Refuses to deploy when any critical/high finding exists. There is deliberately no --ignore-audit override โ the honest framing is "opt into the gate," not "opt into ignoring your own gate."
Output format
bake audit
Running Radar analysis...
found 2 issues:
HIGH: Unchecked arithmetic in transfer.rs:42
HIGH: Missing signer check in initialize.rs:18
Exit code: 1 (critical/high findings present)CI integration
bake audit --ci && echo "Audit passed" || echo "Audit failed"
Use exit code 1 as a CI gate to block deploys with critical/high findings.
How Radar works
Radar is a static analyzer that:
- Parses Rust/Anchor source code
- Applies a rule set for known vulnerability patterns
- Reports findings with severity levels
bake's role is to make Radar convenient, scriptable, and deploy-gated โ not to replace or extend its analysis.