# OpenZeppelin Contracts issues reported by Slither

**URL:** <https://forum.openzeppelin.com/t/openzeppelin-contracts-issues-reported-by-slither/5518>\
**Category:** Contracts\
**Tags:** erc20, audit, openzeppelin-contracts\
**Created:** [January 22, 2021, 5:49pm UTC](https://forum.openzeppelin.com/t/openzeppelin-contracts-issues-reported-by-slither/5518 "2021-01-22T17:49:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![abcoathup](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.openzeppelin.com/abcoathup/32/415_2.png) [@abcoathup](https://forum.openzeppelin.com/u/abcoathup)\
**Post date:** [January 25, 2021, 1:30am UTC](https://forum.openzeppelin.com/t/openzeppelin-contracts-issues-reported-by-slither/5518/2 "2021-01-25T01:30:05Z")

</div>

Hi @dmdv,

Slither is reporting that the reserved storage gap `__gap` shadows the other gaps in inherited contracts. For information on the gap please see the following: [https://docs.openzeppelin.com/contracts/3.x/upgradeable#storage\_gaps](https://docs.openzeppelin.com/contracts/3.x/upgradeable#storage_gaps)

As the storage gap is only used to reserve space I don't think shadowing is an issue.

> [@dmdv](#):
>
> And compilation warnings:

I assume you are compiling with Solidity 0.7.

In Solidity 0.7 visibility ( `public` / `external` ) is not needed for constructors anymore.  
See: [https://docs.soliditylang.org/en/v0.8.0/070-breaking-changes.html#functions-and-events](https://docs.soliditylang.org/en/v0.8.0/070-breaking-changes.html#functions-and-events)

> If you want to use Solidity 0.7, you may prefer to install `@openzeppelin/contracts@solc-0.7`  
> For the combination of upgradeable contracts and Solidity 0.7, use `@openzeppelin/contracts-upgradeable@solc-0.7`  
> From: [OpenZeppelin Contracts 3.3](https://forum.openzeppelin.com/t/openzeppelin-contracts-3-3/4804)

You appear to have a mix of upgradeable and non-upgradeable contracts. For upgradeable contracts you should use OpenZeppelin Contracts Upgradeable, see: [https://docs.openzeppelin.com/contracts/3.x/upgradeable](https://docs.openzeppelin.com/contracts/3.x/upgradeable)

> [@dmdv](#):
>
> Do I need to bother?

I would go through all of the reported issues/warnings and either resolve or decide why it doesn't need to be resolved. I would suggest documenting this for your community.

> [@dmdv](#):
>
> Is it audited at all?

Last full audit on v2.0.0, see: [https://github.com/OpenZeppelin/openzeppelin-contracts/tree/master/audit](https://github.com/OpenZeppelin/openzeppelin-contracts/tree/master/audit)

---

_[View the full topic](https://forum.openzeppelin.com/t/openzeppelin-contracts-issues-reported-by-slither/5518)._
