slither-analyzer

Static Analyzer for Solidity and Vyper

https://github.com/crytic/slither

Science Score: 46.0%

This score indicates how likely this project is to be science-related based on various indicators:

  • CITATION.cff file
  • codemeta.json file
    Found codemeta.json file
  • .zenodo.json file
    Found .zenodo.json file
  • DOI references
  • Academic publication links
    Links to: arxiv.org, researchgate.net, mdpi.com, ieee.org
  • Committers with academic emails
    2 of 158 committers (1.3%) from academic institutions
  • Institutional organization owner
  • JOSS paper metadata
  • Scientific vocabulary similarity
    Low similarity (13.7%) to scientific vocabulary

Keywords

ethereum solidity static-analysis vyper

Keywords from Contributors

vulnerability-detection academic-papers conference-presentations security-reviews optim binary-analysis emulation program-analysis z3 smt
Last synced: 6 months ago · JSON representation

Repository

Static Analyzer for Solidity and Vyper

Basic Info
Statistics
  • Stars: 5,865
  • Watchers: 70
  • Forks: 1,057
  • Open Issues: 463
  • Releases: 45
Topics
ethereum solidity static-analysis vyper
Created over 7 years ago · Last pushed 6 months ago
Metadata Files
Readme Contributing License Citation Codeowners

README.md

Slither, the smart contract static analyzer

Slither Static Analysis Framework Logo

Build Status PyPI Slither - Read the Docs Slither - Wiki

Join the Empire Hacking Slack

Slack Status

- Discussions and Support

Slither is a Solidity & Vyper static analysis framework written in Python3. It runs a suite of vulnerability detectors, prints visual information about contract details, and provides an API to easily write custom analyses. Slither enables developers to find vulnerabilities, enhance their code comprehension, and quickly prototype custom analyses.

Features

  • Detects vulnerable Solidity code with low false positives (see the list of trophies)
  • Identifies where the error condition occurs in the source code
  • Easily integrates into continuous integration and Hardhat/Foundry builds
  • Built-in 'printers' quickly report crucial contract information
  • Detector API to write custom analyses in Python
  • Ability to analyze contracts written with Solidity >= 0.4
  • Intermediate representation (SlithIR) enables simple, high-precision analyses
  • Correctly parses 99.9% of all public Solidity code
  • Average execution time of less than 1 second per contract
  • Integrates with Github's code scanning in CI
  • Support for Vyper smart contracts

Usage

Run Slither on a Hardhat/Foundry/Dapp/Brownie application:

console slither .

This is the preferred option if your project has dependencies as Slither relies on the underlying compilation framework to compile source code.

However, you can run Slither on a single file that does not import dependencies:

console slither tests/uninitialized.sol

How to install

Note
Slither requires Python 3.8+. If you're not going to use one of the supported compilation frameworks, you need solc, the Solidity compiler; we recommend using solc-select to conveniently switch between solc versions.

Using Pip

console python3 -m pip install slither-analyzer

How to upgrade

console python3 -m pip install --upgrade slither-analyzer

Using Brew

console brew install slither-analyzer

Using Git

bash git clone https://github.com/crytic/slither.git && cd slither python3 -m pip install .

We recommend using a Python virtual environment, as detailed in the Developer Installation Instructions, if you prefer to install Slither via git.

Using Docker

Use the eth-security-toolbox docker image. It includes all of our security tools and every major version of Solidity in a single image. /home/share will be mounted to /share in the container.

bash docker pull trailofbits/eth-security-toolbox

To share a directory in the container:

bash docker run -it -v /home/share:/share trailofbits/eth-security-toolbox

Integration

  • For GitHub action integration, use slither-action.
  • For pre-commit integration, use (replace $GIT_TAG with real tag) ```YAML
    • repo: https://github.com/crytic/slither rev: $GIT_TAG hooks:
      • id: slither ```
  • To generate a Markdown report, use slither [target] --checklist.
  • To generate a Markdown with GitHub source code highlighting, use slither [target] --checklist --markdown-root https://github.com/ORG/REPO/blob/COMMIT/ (replace ORG, REPO, COMMIT)

Detectors

Num | Detector | What it Detects | Impact | Confidence --- | --- | --- | --- | --- 1 | abiencoderv2-array | Storage abiencoderv2 array | High | High 2 | arbitrary-send-erc20 | transferFrom uses arbitrary from | High | High 3 | array-by-reference | Modifying storage array by value | High | High 4 | encode-packed-collision | ABI encodePacked Collision | High | High 5 | incorrect-shift | The order of parameters in a shift instruction is incorrect. | High | High 6 | multiple-constructors | Multiple constructor schemes | High | High 7 | name-reused | Contract's name reused | High | High 8 | protected-vars | Detected unprotected variables | High | High 9 | public-mappings-nested | Public mappings with nested variables | High | High 10 | rtlo | Right-To-Left-Override control character is used | High | High 11 | shadowing-state | State variables shadowing | High | High 12 | suicidal | Functions allowing anyone to destruct the contract | High | High 13 | uninitialized-state | Uninitialized state variables | High | High 14 | uninitialized-storage | Uninitialized storage variables | High | High 15 | unprotected-upgrade | Unprotected upgradeable contract | High | High 16 | codex | Use Codex to find vulnerabilities. | High | Low 17 | arbitrary-send-erc20-permit | transferFrom uses arbitrary from with permit | High | Medium 18 | arbitrary-send-eth | Functions that send Ether to arbitrary destinations | High | Medium 19 | controlled-array-length | Tainted array length assignment | High | Medium 20 | controlled-delegatecall | Controlled delegatecall destination | High | Medium 21 | delegatecall-loop | Payable functions using delegatecall inside a loop | High | Medium 22 | incorrect-exp | Incorrect exponentiation | High | Medium 23 | incorrect-return | If a return is incorrectly used in assembly mode. | High | Medium 24 | msg-value-loop | msg.value inside a loop | High | Medium 25 | reentrancy-eth | Reentrancy vulnerabilities (theft of ethers) | High | Medium 26 | return-leave | If a return is used instead of a leave. | High | Medium 27 | storage-array | Signed storage integer array compiler bug | High | Medium 28 | unchecked-transfer | Unchecked tokens transfer | High | Medium 29 | weak-prng | Weak PRNG | High | Medium 30 | domain-separator-collision | Detects ERC20 tokens that have a function whose signature collides with EIP-2612's DOMAIN_SEPARATOR() | Medium | High 31 | enum-conversion | Detect dangerous enum conversion | Medium | High 32 | erc20-interface | Incorrect ERC20 interfaces | Medium | High 33 | erc721-interface | Incorrect ERC721 interfaces | Medium | High 34 | incorrect-equality | Dangerous strict equalities | Medium | High 35 | locked-ether | Contracts that lock ether | Medium | High 36 | mapping-deletion | Deletion on mapping containing a structure | Medium | High 37 | pyth-deprecated-functions | Detect Pyth deprecated functions | Medium | High 38 | pyth-unchecked-confidence | Detect when the confidence level of a Pyth price is not checked | Medium | High 39 | pyth-unchecked-publishtime | Detect when the publishTime of a Pyth price is not checked | Medium | High 40 | shadowing-abstract | State variables shadowing from abstract contracts | Medium | High 41 | tautological-compare | Comparing a variable to itself always returns true or false, depending on comparison | Medium | High 42 | tautology | Tautology or contradiction | Medium | High 43 | write-after-write | Unused write | Medium | High 44 | boolean-cst | Misuse of Boolean constant | Medium | Medium 45 | chronicle-unchecked-price | Detect when Chronicle price is not checked. | Medium | Medium 46 | constant-function-asm | Constant functions using assembly code | Medium | Medium 47 | constant-function-state | Constant functions changing the state | Medium | Medium 48 | divide-before-multiply | Imprecise arithmetic operations order | Medium | Medium 49 | gelato-unprotected-randomness | Call to _requestRandomness within an unprotected function | Medium | Medium 50 | out-of-order-retryable | Out-of-order retryable transactions | Medium | Medium 51 | reentrancy-no-eth | Reentrancy vulnerabilities (no theft of ethers) | Medium | Medium 52 | reused-constructor | Reused base constructor | Medium | Medium 53 | tx-origin | Dangerous usage of tx.origin | Medium | Medium 54 | unchecked-lowlevel | Unchecked low-level calls | Medium | Medium 55 | unchecked-send | Unchecked send | Medium | Medium 56 | uninitialized-local | Uninitialized local variables | Medium | Medium 57 | unused-return | Unused return values | Medium | Medium 58 | chainlink-feed-registry | Detect when chainlink feed registry is used | Low | High 59 | incorrect-modifier | Modifiers that can return the default value | Low | High 60 | optimism-deprecation | Detect when deprecated Optimism predeploy or function is used. | Low | High 61 | shadowing-builtin | Built-in symbol shadowing | Low | High 62 | shadowing-local | Local variables shadowing | Low | High 63 | uninitialized-fptr-cst | Uninitialized function pointer calls in constructors | Low | High 64 | variable-scope | Local variables used prior their declaration | Low | High 65 | void-cst | Constructor called not implemented | Low | High 66 | calls-loop | Multiple calls in a loop | Low | Medium 67 | events-access | Missing Events Access Control | Low | Medium 68 | events-maths | Missing Events Arithmetic | Low | Medium 69 | incorrect-unary | Dangerous unary expressions | Low | Medium 70 | missing-zero-check | Missing Zero Address Validation | Low | Medium 71 | reentrancy-benign | Benign reentrancy vulnerabilities | Low | Medium 72 | reentrancy-events | Reentrancy vulnerabilities leading to out-of-order Events | Low | Medium 73 | return-bomb | A low level callee may consume all callers gas unexpectedly. | Low | Medium 74 | timestamp | Dangerous usage of block.timestamp | Low | Medium 75 | assembly | Assembly usage | Informational | High 76 | assert-state-change | Assert state change | Informational | High 77 | boolean-equal | Comparison to boolean constant | Informational | High 78 | cyclomatic-complexity | Detects functions with high (> 11) cyclomatic complexity | Informational | High 79 | deprecated-standards | Deprecated Solidity Standards | Informational | High 80 | erc20-indexed | Un-indexed ERC20 event parameters | Informational | High 81 | function-init-state | Function initializing state variables | Informational | High 82 | incorrect-using-for | Detects using-for statement usage when no function from a given library matches a given type | Informational | High 83 | low-level-calls | Low level calls | Informational | High 84 | missing-inheritance | Missing inheritance | Informational | High 85 | naming-convention | Conformity to Solidity naming conventions | Informational | High 86 | pragma | If different pragma directives are used | Informational | High 87 | redundant-statements | Redundant statements | Informational | High 88 | solc-version | Incorrect Solidity version | Informational | High 89 | unimplemented-functions | Unimplemented functions | Informational | High 90 | unused-state | Unused state variables | Informational | High 91 | costly-loop | Costly operations in a loop | Informational | Medium 92 | dead-code | Functions that are not used | Informational | Medium 93 | reentrancy-unlimited-gas | Reentrancy vulnerabilities through send and transfer | Informational | Medium 94 | too-many-digits | Conformance to numeric notation best practices | Informational | Medium 95 | cache-array-length | Detects for loops that use length member of some storage array in their loop condition and don't modify it. | Optimization | High 96 | constable-states | State variables that could be declared constant | Optimization | High 97 | external-function | Public function that could be declared external | Optimization | High 98 | immutable-states | State variables that could be declared immutable | Optimization | High 99 | var-read-using-this | Contract reads its own variable using this | Optimization | High

For more information, see

Printers

Quick Review Printers

In-Depth Review Printers

To run a printer, use --print and a comma-separated list of printers.

See the Printer documentation for the complete lists.

Tools

See the Tool documentation for additional tools.

Contact us to get help on building custom tools.

API Documentation

Documentation on Slither's internals is available here.

Getting Help

Feel free to stop by our Slack channel (#ethereum) for help using or extending Slither.

FAQ

How do I exclude mocks or tests?

How do I fix "unknown file" or compilation issues?

  • Because slither requires the solc AST, it must have all dependencies available. If a contract has dependencies, slither contract.sol will fail. Instead, use slither . in the parent directory of contracts/ (you should see contracts/ when you run ls). If you have a node_modules/ folder, it must be in the same directory as contracts/. To verify that this issue is related to slither, run the compilation command for the framework you are using e.g npx hardhat compile. That must work successfully; otherwise, slither's compilation engine, crytic-compile, cannot generate the AST.

License

Slither is licensed and distributed under the AGPLv3 license. Contact us if you're looking for an exception to the terms.

Publications

Trail of Bits publication

External publications

Title | Usage | Authors | Venue | Code --- | --- | --- | --- | --- ReJection: A AST-Based Reentrancy Vulnerability Detection Method | AST-based analysis built on top of Slither | Rui Ma, Zefeng Jian, Guangyuan Chen, Ke Ma, Yujia Chen | CTCIS 19 | - MPro: Combining Static and Symbolic Analysis for Scalable Testing of Smart Contract | Leverage data dependency through Slither | William Zhang, Sebastian Banescu, Leodardo Pasos, Steven Stewart, Vijay Ganesh | ISSRE 2019 | MPro ETHPLOIT: From Fuzzing to Efficient Exploit Generation against Smart Contracts | Leverage data dependency through Slither | Qingzhao Zhang, Yizhuo Wang, Juanru Li, Siqi Ma | SANER 20 | - Verification of Ethereum Smart Contracts: A Model Checking Approach | Symbolic execution built on top of Slithers CFG | Tam Bang, Hoang H Nguyen, Dung Nguyen, Toan Trieu, Tho Quan | IJMLC 20 | - Smart Contract Repair | Rely on Slithers vulnerabilities detectors | Xiao Liang Yu, Omar Al-Bataineh, David Lo, Abhik Roychoudhury | TOSEM 20 | SCRepair Demystifying Loops in Smart Contracts | Leverage data dependency through Slither | Ben Mariano, Yanju Chen, Yu Feng, Shuvendu Lahiri, Isil Dillig | ASE 20 | - Trace-Based Dynamic Gas Estimation of Loops in Smart Contracts | Use Slithers CFG to detect loops | Chunmiao Li, Shijie Nie, Yang Cao, Yijun Yu, Zhenjiang Hu | IEEE Open J. Comput. Soc. 1 (2020) | - SAILFISH: Vetting Smart Contract State-Inconsistency Bugs in Seconds | Rely on SlithIR to build a storage dependency graph | Priyanka Bose, Dipanjan Das, Yanju Chen, Yu Feng, Christopher Kruegel, and Giovanni Vigna | S&P 22 | Sailfish SolType: Refinement Types for Arithmetic Overflow in Solidity | Use Slither as frontend to build refinement type system | Bryan Tan, Benjamin Mariano, Shuvendu K. Lahiri, Isil Dillig, Yu Feng | POPL 22 | - Do Not Rug on Me: Leveraging Machine Learning Techniques for Automated Scam Detection | Use Slither to extract tokens' features (mintable, pausable, ..) | Mazorra, Bruno, Victor Adan, and Vanesa Daza | Mathematics 10.6 (2022) | - MANDO: Multi-Level Heterogeneous Graph Embeddings for Fine-Grained Detection of Smart Contract Vulnerabilities | Use Slither to extract the CFG and call graph | Hoang Nguyen, Nhat-Minh Nguyen, Chunyao Xie, Zahra Ahmadi, Daniel Kudendo, Thanh-Nam Doan and Lingxiao Jiang| IEEE 9th International Conference on Data Science and Advanced Analytics (DSAA, 2022) | ge-sc Automated Auditing of Price Gouging TOD Vulnerabilities in Smart Contracts | Use Slither to extract the CFG and data dependencies| Sidi Mohamed Beillahi, Eric Keilty, Keerthi Nelaturu, Andreas Veneris, and Fan Long | 2022 IEEE International Conference on Blockchain and Cryptocurrency (ICBC) | Smart-Contract-Repair Modeling and Enforcing Access Control Policies for Smart Contracts | Extend Slither's data dependencies | Jan-Philipp Toberg, Jonas Schiffl, Frederik Reiche, Bernhard Beckert, Robert Heinrich, Ralf Reussner | IEEE International Conference on Decentralized Applications and Infrastructures (DAPPS), 2022 | SolidityAccessControlEnforcement Smart Contract Vulnerability Detection Based on Deep Learning and Multimodal Decision Fusion | Use Slither to extract the CFG | Weichu Deng, Huanchun Wei, Teng Huang, Cong Cao, Yun Peng, and Xuan Hu | Sensors 2023, 23, 7246 | - Semantic-enriched Code Knowledge Graph to Reveal Unknowns in Smart Contract Code Reuse | Use Slither to extract the code features (CFG, function, parameters types, ..) | Qing Huang, Dianshu Liao, Zhenchang Xing, Zhengkang Zuo, Changjing Wang, Xin Xia | ACM Transactions on Software Engineering and Methodology, 2023 | - Smart Contract Parallel Execution with Fine-Grained State Accesses | Use Slither to build state access graphs | Xiaodong Qi, Jiao Jiao, Yi Li | International Conference on Distributed Computing Systems (ICDCS), 2023 | - Bad Apples: Understanding the Centralized Security Risks in Decentralized Ecosystems | Implement an internal analysis on top of Slither | Kailun Yan , Jilian Zhang , Xiangyu Liu , Wenrui Diao , Shanqing Guo | ACM Web Conference April 2023 | - Identifying Vulnerabilities in Smart Contracts using Interval Analysis | Create 4 detectors on top of Slither | tefan-Claudiu Susan, Andrei Arusoaie | FROM 2023 | - Storage State Analysis and Extraction of Ethereum Blockchain Smart Contracts (no PDF in open access) | Rely on Slither's CFG and AST | Maha Ayub , Tania Saleem , Muhammad Janjua , Talha Ahmad | TOSEM 2023 | SmartMuv

If you are using Slither on an academic work, consider applying to the Crytic $10k Research Prize.

Owner

  • Name: Crytic
  • Login: crytic
  • Kind: organization
  • Email: opensource@trailofbits.com
  • Location: New York, NY

Blockchain Security, by @trailofbits

GitHub Events

Total
  • Create event: 52
  • Release event: 3
  • Issues event: 115
  • Watch event: 541
  • Delete event: 61
  • Issue comment event: 136
  • Push event: 187
  • Gollum event: 1
  • Pull request review event: 38
  • Pull request review comment event: 67
  • Pull request event: 153
  • Fork event: 97
Last Year
  • Create event: 52
  • Release event: 3
  • Issues event: 115
  • Watch event: 541
  • Delete event: 61
  • Issue comment event: 136
  • Push event: 187
  • Gollum event: 1
  • Pull request review event: 38
  • Pull request review comment event: 67
  • Pull request event: 153
  • Fork event: 97

Committers

Last synced: 9 months ago

All Time
  • Total Commits: 3,432
  • Total Committers: 158
  • Avg Commits per committer: 21.722
  • Development Distribution Score (DDS): 0.55
Past Year
  • Commits: 220
  • Committers: 23
  • Avg Commits per committer: 9.565
  • Development Distribution Score (DDS): 0.714
Top Committers
Name Email Commits
Josselin j****n@t****m 1,546
alpharush 0****h@p****m 437
webthethird r****l@g****m 183
Simone s****a@t****m 176
David Pokora d****a@g****m 89
Emilio López e****z@t****m 83
rajeevgopalakrishna r****a@g****m 77
bohendo b****n@t****m 56
dependabot[bot] 4****] 51
Alexis a****e@t****m 42
Alexander Remie u****r@r****e 36
samczsun g****b@s****m 35
ggrieco-tob g****o@t****m 33
devtooligan d****n@t****v 33
Dan Guido d****n@t****m 24
Maximilian Krueger k****i@g****m 24
bart1e b****i@o****l 23
disconnect3d d****a@g****m 21
Tadashi t****o@g****m 20
nisedo 7****o 18
Tigran Avagyan t****v@g****m 17
Vishnuram Rajkumar v****3@g****m 16
Pascal Marco Caversaccio p****o@h****h 15
Omidiora Samuel 8****y 15
Boyan-MILANOV b****v@t****m 15
William Aaron Cheung t****r@l****m 13
Judy Wu j****u@g****m 13
S.Sidarth 3****6 12
Jaime 2****s 12
0xGusMcCrae 0****e@p****m 11
and 128 more...

Issues and Pull Requests

Last synced: 6 months ago

All Time
  • Total issues: 454
  • Total pull requests: 716
  • Average time to close issues: 12 months
  • Average time to close pull requests: about 1 month
  • Total issue authors: 234
  • Total pull request authors: 106
  • Average comments per issue: 1.79
  • Average comments per pull request: 1.27
  • Merged pull requests: 425
  • Bot issues: 11
  • Bot pull requests: 133
Past Year
  • Issues: 82
  • Pull requests: 175
  • Average time to close issues: about 1 month
  • Average time to close pull requests: 16 days
  • Issue authors: 58
  • Pull request authors: 37
  • Average comments per issue: 0.66
  • Average comments per pull request: 0.46
  • Merged pull requests: 93
  • Bot issues: 6
  • Bot pull requests: 37
Top Authors
Issue Authors
  • 0xalpharush (32)
  • montyly (32)
  • kevinclancy (24)
  • Tiko7454 (15)
  • github-actions[bot] (12)
  • mds1 (7)
  • dguido (7)
  • trocher (6)
  • lum7na (6)
  • izcoser (6)
  • alexanderhawl (5)
  • bsamuels453 (5)
  • zhangzone (5)
  • smonicas (5)
  • gustavo-grieco (4)
Pull Request Authors
  • dependabot[bot] (141)
  • 0xalpharush (139)
  • smonicas (128)
  • DarkaMaul (39)
  • montyly (33)
  • elopez (22)
  • bohendo (12)
  • Tiko7454 (11)
  • webthethird (10)
  • nsiregar (10)
  • nisedo (9)
  • dokzai (9)
  • vijayarawat19 (8)
  • kevinclancy (8)
  • devtooligan (8)
Top Labels
Issue Labels
bug (112) bug-candidate (100) enhancement (91) good first issue (36) false-positive (27) High Priority (25) ir (15) help wanted (14) Need more info (14) question (12) duplicate (10) false-negative (8) documentation (6) vyper (5) cfg (4) echidna (4) ux (4) tracking (3) design (3) wontfix (2) meta (2) parsing (2) yul (2) new detector (2) 0.7 (2) Optimization (1) Upgradeability (1) testing (1) translation (1)
Pull Request Labels
dependencies (141) github_actions (121) javascript (19) new detector (6) High Priority (2) bug (1)

Packages

  • Total packages: 2
  • Total downloads:
    • pypi 58,098 last-month
    • homebrew 215 last-month
  • Total docker downloads: 124
  • Total dependent packages: 10
    (may contain duplicates)
  • Total dependent repositories: 186
    (may contain duplicates)
  • Total versions: 59
  • Total maintainers: 4
pypi.org: slither-analyzer

Slither is a Solidity and Vyper static analysis framework written in Python 3.

  • Versions: 46
  • Dependent Packages: 9
  • Dependent Repositories: 186
  • Downloads: 58,098 Last month
  • Docker Downloads: 124
Rankings
Stargazers count: 1.0%
Dependent repos count: 1.1%
Forks count: 1.5%
Downloads: 1.5%
Average: 1.7%
Dependent packages count: 2.2%
Docker downloads count: 3.1%
Last synced: 6 months ago
formulae.brew.sh: slither-analyzer

Solidity static analysis framework written in Python 3

  • Versions: 13
  • Dependent Packages: 1
  • Dependent Repositories: 0
  • Downloads: 215 Last month
Rankings
Forks count: 3.6%
Stargazers count: 6.7%
Dependent packages count: 10.6%
Average: 24.3%
Downloads: 50.0%
Dependent repos count: 50.7%
Last synced: 6 months ago

Dependencies

plugin_example/setup.py pypi
  • slither-analyzer ==0.1
setup.py pypi
  • crytic-compile *
  • crytic-compile >=0.2.3
  • prettytable >=0.7.2
  • pysha3 >=1.0.2
.github/actions/upload-coverage/action.yml actions
  • actions/upload-artifact v3.1.0 composite
.github/workflows/black.yml actions
  • actions/checkout v3 composite
  • actions/setup-python v4 composite
  • super-linter/super-linter/slim v4.9.2 composite
.github/workflows/ci.yml actions
  • actions/checkout v3 composite
  • actions/setup-python v4 composite
  • cachix/cachix-action v12 composite
  • cachix/install-nix-action v22 composite
.github/workflows/docker.yml actions
  • actions/checkout v3 composite
  • docker/build-push-action v4 composite
  • docker/login-action v2 composite
  • docker/metadata-action v4 composite
  • docker/setup-buildx-action v2 composite
  • docker/setup-qemu-action v2 composite
.github/workflows/docs.yml actions
  • actions/checkout v3 composite
  • actions/configure-pages v3 composite
  • actions/deploy-pages v2 composite
  • actions/setup-python v4 composite
  • actions/upload-pages-artifact v1 composite
.github/workflows/doctor.yml actions
  • actions/checkout v3 composite
  • actions/setup-python v4 composite
.github/workflows/linter.yml actions
  • actions/checkout v3 composite
  • actions/setup-python v4 composite
  • super-linter/super-linter/slim v4.9.2 composite
.github/workflows/pip-audit.yml actions
  • actions/checkout v3 composite
  • actions/setup-python v4 composite
  • pypa/gh-action-pip-audit v1.0.8 composite
.github/workflows/publish.yml actions
  • actions/checkout v3 composite
  • actions/download-artifact v3 composite
  • actions/setup-python v4 composite
  • actions/upload-artifact v3 composite
  • pypa/gh-action-pypi-publish v1.8.7 composite
  • sigstore/gh-action-sigstore-python v1.2.3 composite
.github/workflows/pylint.yml actions
  • actions/checkout v3 composite
  • actions/setup-python v4 composite
  • super-linter/super-linter/slim v4.9.2 composite
.github/workflows/test.yml actions
  • ./.github/actions/upload-coverage * composite
  • actions/checkout v3 composite
  • actions/download-artifact v3.0.2 composite
  • actions/setup-node v3 composite
  • actions/setup-python v4 composite
Dockerfile docker
  • ubuntu jammy build
tests/e2e/compilation/test_data/test_node_modules/node_modules/@openzeppelin/contracts/package.json npm
tests/e2e/compilation/test_data/test_node_modules/package-lock.json npm
  • 295 dependencies
tests/e2e/compilation/test_data/test_node_modules/package.json npm
  • @openzeppelin/contracts ^4.4.0
  • hardhat ^2.13.0
pyproject.toml pypi
.github/workflows/matchers/yamllint.json actions
.github/workflows/issue-metrics.yml actions
  • github/issue-metrics v3 composite
  • peter-evans/create-issue-from-file v5 composite