
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
truffle-contract-size
Advanced tools
This Truffle plugin displays the contract size of all or a selection of your smart contracts in kilobytes.
npm install truffle-contract-size
truffle.js
or truffle-config.js
file module.exports = {
/* ... rest of truffle-config */
plugins: [
'truffle-contract-size'
]
}
The command can be executed without any arguments to display the size of all contracts in the projects.
truffle run contract-size
To show only certain contracts one or more contract names can be given as arguments to the contracts option:
truffle run contract-size --contracts ExampleContract1 ExampleContract2
The plugin can be used to check that the smart contracts aren't bigger than the allowed maximum contract size of the Ethereum Mainnet (24 kb). For example this can be used, to make a CI/CD pipeline fail, if a contract is bigger than allowed.
truffle run contract-size --checkMaxSize
If another size limit than the default one should be checked, it can be given as argument to the option. For example to set the maximum to 48 kb the following command can be used:
truffle run contract-size --checkMaxSize 48
If one or more of the contracts are bigger than the maximum size, an error message will de displayed, and the exit status will be 1.
Mock contracts are used to improve the testing of smart contracts. As they are only used during testing and will not be deployed, it can be useful to ignore when calculating the contract sizes. When the option is used, all contract which names are ending with Mock
will be ignored. This can especially be useful in combination with the --checkMaxSize
option.
truffle run contract-size --ignoreMocks
FAQs
Displays the size of a truffle contracts in kilobytes
The npm package truffle-contract-size receives a total of 565 weekly downloads. As such, truffle-contract-size popularity was classified as not popular.
We found that truffle-contract-size demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.