
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@midcontract/protocol
Advanced tools
.env.example
file to .env
and fill in the variables.yarn install
. In case there is an error with the commands, run foundryup
and try them again.The default way to build the code is suboptimal but fast, you can run it via:
yarn build
In order to build a more optimized code (via IR), run:
yarn build:optimized
Unit tests should be isolated from any externalities, while Integration usually run in a fork of the blockchain. In this boilerplate you will find example of both.
In order to run both unit and integration tests, run:
yarn test
In order to just run unit tests, run:
yarn test:unit
In order to run unit tests and run way more fuzzing than usual (5x), run:
yarn test:unit:deep
In order to just run integration tests, run:
yarn test:integration
In order to check your current code coverage, run:
yarn coverage
Configure the .env
variables.
yarn deploy:sepolia
yarn deploy:blast
The deployments are stored in ./broadcast
See the Foundry Book for available options.
Export TypeScript interfaces from Solidity contracts and interfaces providing compatibility with TypeChain. Publish the exported packages to NPM.
To enable this feature, make sure you've set the NPM_TOKEN
on your org's secrets. Then set the job's conditional to true
:
jobs:
export:
name: Generate Interfaces And Contracts
# Remove the following line if you wish to export your Solidity contract and interface and publish them to NPM
if: true
...
Also, remember to update the package_name
param to your package name:
- name: Export Solidity - ${{ matrix.export_type }}
uses: defi-wonderland/evm-exporter-action@1dbf5371c260add4a354e7a8d3467e5d3b9580b8
with:
# Update package_name with your package name
package_name: "my-cool-project"
...
- name: Publish to NPM - ${{ matrix.export_type }}
# Update `my-cool-project` with your package name
run: cd export/my-cool-project-${{ matrix.export_type }} && npm publish --access public
...
You can take a look at our solidity-exporter-action repository for more information and usage examples.
The primary license for the boilerplate is MIT, see LICENSE
FAQs
Crypto payment protocol with escrow
We found that @midcontract/protocol demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.