
Research
/Security News
Shai Hulud Strikes Again (v2)
Another wave of Shai-Hulud campaign has hit npm with more than 500 packages and 700+ versions affected.
@oakxswap/v3-core
Advanced tools
This repository contains the core smart contracts for the oakx V3 Protocol. For higher level contracts, see the oakx-v3-periphery repository.
This repository is subject to the oakx V3 bug bounty program, per the terms defined here.
In order to deploy this code to a local testnet, you should install the npm package
@oakx/v3-core
and import the factory bytecode located at
@oakx/v3-core/artifacts/contracts/OakxSwapV3Factory.sol/OakxSwapV3Factory.json.
For example:
import {
abi as FACTORY_ABI,
bytecode as FACTORY_BYTECODE,
} from '@oakx/v3-core/artifacts/contracts/OakxSwapV3Factory.sol/OakxSwapV3Factory.json'
// deploy the bytecode
This will ensure that you are testing against the same bytecode that is deployed to mainnet and public testnets, and all oakx code will correctly interoperate with your local deployment.
The oakx v3 interfaces are available for import into solidity smart contracts
via the npm artifact @oakx/v3-core, e.g.:
import '@oakx/v3-core/contracts/interfaces/IOakxSwapV3Pool.sol';
contract MyContract {
IOakxSwapV3Pool pool;
function doSomethingWithPool() {
// pool.swap(...);
}
}
The primary license for oakx V3 Core is the Business Source License 1.1 (BUSL-1.1), see LICENSE. However, some files are dual licensed under GPL-2.0-or-later:
contracts/interfaces/ may also be licensed under GPL-2.0-or-later (as indicated in their SPDX headers), see contracts/interfaces/LICENSEcontracts/libraries/ may also be licensed under GPL-2.0-or-later (as indicated in their SPDX headers), see contracts/libraries/LICENSEcontracts/libraries/FullMath.sol is licensed under MIT (as indicated in its SPDX header), see contracts/libraries/LICENSE_MITcontracts/test remain unlicensed (as indicated in their SPDX headers).FAQs
🦄 Core smart contracts of oakx V3
We found that @oakxswap/v3-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Another wave of Shai-Hulud campaign has hit npm with more than 500 packages and 700+ versions affected.

Product
Add real-time Socket webhook events to your workflows to automatically receive software supply chain alert changes in real time.

Security News
ENISA has become a CVE Program Root, giving the EU a central authority for coordinating vulnerability reporting, disclosure, and cross-border response.