
Product
Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.
@leap-network/v4-core
Advanced tools
Have questions or want the latest news?
Join the PoolTogether Discord or follow us on Twitter:
Documentation
https://v4.docs.pooltogether.com
Deployments
Periphery and supporting contracts:
The project is made available as a NPM package.
yarn add @leap-network/pooltogether-contracts
The repo can be cloned from Github for contributions.
git clone https://github.com/pooltogether/v4-core
yarn
We use direnv to manage environment variables. You'll likely need to install it.
cp .envrc.example .envrc
To run fork scripts, deploy or perform any operation with a mainnet/testnet node you will need an Infura API key.
We use Hardhat and hardhat-deploy
To run unit & integration tests:
yarn test
To run coverage:
yarn coverage
Deployment is maintained in a different repo.
Deployment is maintained in a different repo.
FAQs
PoolTogether V4 Core Smart Contracts
We found that @leap-network/v4-core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.

Research
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infostealer during installation.

Research
/Security News
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.