Repository navigation
Resolve Hardhat 3 npm sources through build-info remappings - #706
Open
tamtamchik wants to merge 2 commits into
Open
tamtamchik wants to merge 2 commits into
tamtamchik wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
Subpath remapping targets cannot act as contexts for resolving nested dependencies.
1 open finding
What changed in this PR
Improves Hardhat 3 source resolution using build-info remappings.
Changes:
- Resolves aliases, nested dependencies, and project-relative sources.
- Preserves compiler source names for filename lookup.
- Adds synthetic and integration coverage.
| File | Description |
|---|---|
crytic_compile/platform/hardhat.py |
Implements remapping-based resolution. |
crytic_compile/compilation_unit.py |
Removes obsolete Hardhat normalization. |
tests/test_hardhat_v3.py |
Tests Hardhat 3 source resolution. |
tests/hardhat-v3/package.json |
Adds versioned OpenZeppelin dependencies. |
tests/hardhat-v3/contracts/Aliased.sol |
Exercises aliased imports. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Problem
Hardhat 3 names an npm source
npm/<package>@<version>/<path>. crytic-compile removes the version and readsnode_modules/<package>/<path>. This file is wrong when the package is installed in a different directory:"oz-v5": "npm:@openzeppelin/contracts@5.2.0", is innode_modules/oz-v5/. crytic-compile fails withUnknown fileor reads the files of a different version.node_modulesfolder of the package that imports it. Both versions map to one file, and Slither loses the contracts of one version.Also, crytic-compile strips only
project/contracts/. A Solidity file underproject/test/fails withUnknown file.Fix
The build-info input has a remapping for each import, for example
project/:oz-v5/=npm/@openzeppelin/contracts@5.2.0/. The remapping shows the directory from which Hardhat resolved the import. For a Hardhat 3 build-info, crytic-compile now does the same lookup. It accepts a directory only if itspackage.jsonhas the same name and version.project/<path>resolves from the project root.Filename.usednow keeps the compiler source name, for examplenpm/@openzeppelin/contracts@5.2.0/access/Ownable.sol. This name is unique for each version, and the AST uses it. Thusfilename_lookupdoes not need its own Hardhat 3 normalization.Tests
tests/test_hardhat_v3.pyresolves a synthetic build-info with an alias, nested versions, user remappings, and a source underproject/test/.tests/hardhat-v3adds OpenZeppelin 5.2.0 as an alias next to 4.9.6.crytic-compile .fails onmasterand passes with this change.