
Security News
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
@leap-network/v4-mainnet
Advanced tools
The PoolTogether V4 "mainnet" deployment scripts.
The deployment scripts are separated into versions.
Install direnv module.
We use direnv to manage environment variables. You'll likely need to install it.
cp .envrc.example .envrc
The RPC endpoints will need to be updated if you wish to deploy. The RPC endpoints will also need to point to archival nodes if you wish to run fork tests.
yarn
The deployment scripts can be tested in forked environments. The following commands will fork the network then run the deployment script against the fork.
Note: You must configure RPC endpoints for archival nodes in the .envrc.
yarn test:v1.x.x.mainnet
yarn test:v1.x.x.avalanche
yarn test:v1.x.x.polygon
yarn deploy:v1.x.x.mainnet
yarn deploy:v1.x.x.avalanche
yarn deploy:v1.x.x.polygon
This version was the original V4 launch across Ethereum and Polygon.
This version launched V4 on Avalanche, and included upgrades to Ethereum and Polygon. New contracts are being deployed across Avalanche, Ethereum and Polygon.
This version upgrades the existing configuration, so some changes need to be completed by the PoolTogether Executive Team once the contracts have been launched. Those post-deploy configuration changes are detailed below.
Deploy TWAB Rewards contract across Avalanche, Ethereum and Polygon.
Deploy TWAB Delegator contract across Avalanche, Ethereum and Polygon.
Deploy new BeaconTimelockTrigger, DrawCalculatorTimelock, PrizeDistributionFactory and PrizeTierHistory contracts on Ethereum.
Deploy new DrawCalculatorTimelock, PrizeDistributionFactory, PrizeTierHistory and ReceiverTimelockTrigger contracts on Avalanche and Polygon.
Deploy RNGChainlinkV2 on Ethereum.
Redeploy TWABRewards on Avalanche, Ethereum and Polygon.
Deploy USDC Prize Pool on Optimism.
Executive team needs to claim ownership of the following contracts:
Re-deploy USDC Prize Pool on Optimism.
Deploy RNGChainlinkV2 on Polygon and setup DrawBeacon to compute draw onchain.
Executive team needs to claim ownership of the following contracts:
Deploy RNGChainlinkV2 on Avalanche and setup DrawBeacon to compute draw onchain.
Executive team needs to claim ownership of the following contracts:
Deploy DPR upgrade to Avalanche, Ethereum, Polygon and Optimism.
Executive team needs to claim ownership of the following contracts:
FAQs
The PoolTogether V4 "mainnet" deployment scripts.
We found that @leap-network/v4-mainnet demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.

Research
/Security News
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.