Security News
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" by Security Experts
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
@pangolindex/exchange-contracts
Advanced tools
This repo contains all of the smart contracts used to run Pangolin.
Factory address: 0xefa94DE7a4656D787667C749f7E1223D71E9FD88
Router address: 0xE54Ca86531e17Ef3616d22Ca28b0D458b6C89106
These contracts are compiled and deployed using Hardhat. They can also be run using the Remix IDE. A tutorial for using Remix is located here.
To prepare the dev environment, run yarn install
. To compile the contracts, run yarn compile
. Yarn is available to install here if you need it.
Please note Currently Hedera does not support Hardhat. There are instructions for Hedera under contracts/hedera/readme.md
If you need to use any of the contract ABIs, you can install this repo as an npm package with npm install --dev @pangolindex/exchange-contracts
. Then import the ABI like so: import { abi as IPangolinPairABI } from '@pangolindex/exchange-contracts/artifacts/contracts/pangolin-core/interfaces/IPangolinPair.sol/IPangolinPair.json'
.
These contracts were adapted from these Uniswap repos: uniswap-v2-core, uniswap-v2-periphery, and uniswap-lib.
To deploy to any chain you want, you need to complete the following steps:
.env.example
to .env
and add your private key thereconstants/NETWORK_NAME.js
yarn deploy [--network NETWORK_NAME]
The deployment script will deploy all the contracts and set them up according to the configuration file.
The deployment scripts gets chain specific configuration from the respective file in constants/
. You can copy an existing configuration such as constants/fantom_mainnet.js
when creating a configuration file for another chain. The deployer must be familiar with the purpose of each constant.
The deployment script transfers the amount specified in the config to the Airdrop contract. But the script does not manage the whitelisting. To handle airdrop, the multisig must call setWhitelister()
function of Airdrop
to appoint a trusted individual to whitelist airdrop recipients using a bot. After multisig ensures that whitelist is accurate, it must call allowClaiming()
to begin the airdrop.
The deployment script transfers all the PNG (except what went to Airdrop) to TreasuryVester
. After the deployment, the multisig must call startVesting()
function of TreasuryVester
. Then, a bot must be set up the ensure distribute()
function of TreasuryVester
is called every 24 hours. Vester allocation can only be changed through governance (timelock+multisig by default).
The deployment script sets up FeeCollector
to manage funding of the PNG staking contract. A bot must be set up to call harvest()
function of FeeCollector
daily to divert MiniChef rewards to the PNG staking contract. The bot would also track swap fees accumulated in FeeCollector
and call the harvest()
function accordingly to distribute the swap fees to the recipients.
Portion of swap fees accumulated in FeeCollector
is sent to RevenueDistributor
. This contract allows anyone to call its distributeToken
function to allocate revenue to pre-determined recipients. In default configuration, these recipients are the new DAO with 80% allocation, and Pangolin Foundation DAO with 20% allocation. The allocation can be later changed by the joint agreement of both DAOs, using the JointMultisig
contract. Any future ERC20 revenue of the DAO must also be transferred to the Revenue Distributor.
The deployment script adds minimum two farms to MiniChef, based on the constants PNG_STAKING_ALLOCATION
, WETH_PNG_FARM_ALLOCATION
, and INITIAL_FARMS
. INITIAL_FARMS
is optional and can be left as an empty array. Multisig can later add or remove farms without timelock or governance.
Currently on Aurora you need to get funds into Goerli and then bridge across. You can do this by following these steps:
Faucet: https://testnet.binance.org/faucet-smart
Faucet: https://cronos.crypto.org/faucet Testnet Explorer: https://cronos.crypto.org/explorer/testnet3/
To get Harmony tokens on the testnet please go here https://faucet.pops.one/. Please note the Metamask address is different to your Harmony address, so you'll need to go to the Explorer to convert https://explorer.pops.one/
FAQs
Contracts for the Pangolin Dex.
We found that @pangolindex/exchange-contracts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
Security News
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approaches.
Security News
Bun 1.2 enhances its JavaScript runtime with 90% Node.js compatibility, built-in S3 and Postgres support, HTML Imports, and faster, cloud-first performance.