
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@reality.eth/contracts
Advanced tools
Collection of smart contracts for the Realitio fact verification platform
Contracts for Reality.eth, including source code, ABI and addresses of contracts on mainnet and test networks.
networks/ contains a directory hierarchy with a file for the deployed version of each live contract on the specified network for the specified token. Each file also lists any whitelisted arbitrators. It may also contain additional post-deployment files for arbitrators we deployed.
tokens/ contains a file describing each supported token.
chains/ contains the full raw data from chainid.network, and a file listing chains we specifically support, and adding useful configuration information not supplied by chainid.network.
The above are combined into JSON files under generated/ using npm run-script generate
.
truffle/ contains source files and build files for contracts from the original build, as laid out by truffle. These files are no longer supported as a way of managing contract addresses.
config/templates contains information about templates deployed by the constructor to save fetching them from the event logs.
Contract tests use python3.
$ cd tests/python
$ pip install -r requirements.txt
You can then run the tests with:
$ python test.py
The version we will deploy on XDai, v2.1, has an additional fee, called the claim fee. You can test it with:
$ CLAIM_FEE=40 REALITIO=Realitio_v2_1 python test.py
We now use Etherlime rather than Truffle for compilation and deployment. The existing build files already contain the compiled code, so if you're not changing the code and just deploying versions of a previous contract for a new token, you don't need to compile.
$ cd truffle
$ etherlime compile --solcVersion=0.4.25 --runs=200
The above builds contracts under truffle/build
. If you don't need to merge with any existing contract definitions (eg to preserve the addresses of existing contracts) you can copy them to the normal truffle location under truffle/build/contracts
.
You will need the private key of an account with funds to deploy on the relevant network. It should be in hex, beginning "0x", in a file called mainnet.sec
or rinkeby.sec
or the equivalent for the network you will deploy to.
$ mkdir truffle/etherlime_deploy/secrets
The .gitignore
file should prevent it from being checked into Git, but be careful not to share it.
To deploy contracts using the code compiled under truffle/build/contracts, use
$ cd truffle/etherlime_deploy
$ node deploy.js <Realitio|Arbitrator|ERC20> <network> <token_name> [<dispute_fee>] [<arbitrator_owner>]
This will add contract addresses to the existing deployed contract .json definitions, and deploy per-token versions in the format expected by the realitio-dapp
ui.
If the token or network was not previously supported, you will need to add its configuration files and run npm run-script generate
.
If you have added Reality.eth for a new token, or a new arbitrator, or both, please submit the changes to this repo as a PR.
FAQs
Collection of smart contracts for the Realitio fact verification platform
The npm package @reality.eth/contracts receives a total of 534 weekly downloads. As such, @reality.eth/contracts popularity was classified as not popular.
We found that @reality.eth/contracts demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.