Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@safe-global/safe-modules-deployments
Advanced tools
Collection of Safe modules contract deployments
This contract contains a collection of deployments of audited contracts from the Safe modules repository.
For each deployment the address on the different networks and the abi files are available. To get an overview of the available versions check the available json assets.
To add additional deployments please follow the deployment steps in the module folder in the Safe modules repository.
npm i @safe-global/safe-modules-deployments
yarn add @safe-global/safe-modules-deployments
pnpm install @safe-global/safe-modules-deployments
It is possible to directly use the json files in the assets folder that contain the addresses and abi definitions.
An alternative is to use the JavaScript library methods to query the correct deployment. The library supports different methods to get the deployment of a specific contract.
Each of the method takes an optional DeploymentFilter
as a parameter.
interface DeploymentFilter {
version?: string;
released?: boolean; // Defaults to true if no filter is specified
network?: string; // Chain id of the network
}
The method will return a Deployment
object or undefined
if no deployment was found for the specified filter.
interface Deployment {
version: string;
abi: any[];
networkAddresses: Record<string, string>; // Address of the contract by network
contractName: string;
released: boolean; // A released version was audited and has a running bug bounty
}
For example, in order to get various deployments for the Safe Allowance module:
const allowanceModule = getAllowanceModuleDeployment();
// Returns latest contract version, even if not finally released yet
const allowanceModuleNightly = getAllowanceModuleDeployment({ released: undefined });
// Returns released contract version for specific network
const allowanceModuleGörli = getAllowanceModuleDeployment({ network: '5' });
// Returns released contract version for specific version
const allowanceModule010 = getAllowanceModuleDeployment({ version: '0.1.0' });
This repository contains deployments for the following modules:
A list of network information can be found at chainid.network
This library is released under MIT.
FAQs
Collection of Safe modules contract deployments
We found that @safe-global/safe-modules-deployments demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.