Skip to content

Resolve Hardhat 3 npm sources through build-info remappings - #706

Open
tamtamchik wants to merge 2 commits into
crytic:masterfrom
tamtamchik:fix/hardhat-v3-npm-source-resolution
Open

tamtamchik wants to merge 2 commits into
crytic:masterfrom
tamtamchik:fix/hardhat-v3-npm-source-resolution

Conversation

@tamtamchik

@tamtamchik tamtamchik commented Oct 7, 2026 •

Copy link
Copy Markdown

Problem

Hardhat 3 names an npm source npm/<package>@<version>/<path>. crytic-compile removes the version and reads node_modules/<package>/<path>. This file is wrong when the package is installed in a different directory:

  • An aliased dependency, such as "oz-v5": "npm:@openzeppelin/contracts@5.2.0", is in node_modules/oz-v5/. crytic-compile fails with Unknown file or reads the files of a different version.
  • A second version of a package is in the node_modules folder of the package that imports it. Both versions map to one file, and Slither loses the contracts of one version.

Also, crytic-compile strips only project/contracts/. A Solidity file under project/test/ fails with Unknown file.

Fix

The build-info input has a remapping for each import, for example project/:oz-v5/=npm/@openzeppelin/contracts@5.2.0/. The remapping shows the directory from which Hardhat resolved the import. For a Hardhat 3 build-info, crytic-compile now does the same lookup. It accepts a directory only if its package.json has the same name and version. project/<path> resolves from the project root.

Filename.used now keeps the compiler source name, for example npm/@openzeppelin/contracts@5.2.0/access/Ownable.sol. This name is unique for each version, and the AST uses it. Thus filename_lookup does not need its own Hardhat 3 normalization.

Tests

  • tests/test_hardhat_v3.py resolves a synthetic build-info with an alias, nested versions, user remappings, and a source under project/test/.
  • tests/hardhat-v3 adds OpenZeppelin 5.2.0 as an alias next to 4.9.6. crytic-compile . fails on master and passes with this change.

Copilot AI balanced review requested due to automatic review settings October 7, 2026 16:02
@CLAassistant

CLAassistant commented Oct 7, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Subpath remapping targets cannot act as contexts for resolving nested dependencies.

1 open finding
What changed in this PR

Improves Hardhat 3 source resolution using build-info remappings.

Changes:

  • Resolves aliases, nested dependencies, and project-relative sources.
  • Preserves compiler source names for filename lookup.
  • Adds synthetic and integration coverage.
File Description
crytic_compile/​platform/​hardhat.py Implements remapping-based resolution.
crytic_compile/​compilation_unit.py Removes obsolete Hardhat normalization.
tests/​test_hardhat_v3.py Tests Hardhat 3 source resolution.
tests/​hardhat-v3/​package.json Adds versioned OpenZeppelin dependencies.
tests/​hardhat-v3/​contracts/​Aliased.sol Exercises aliased imports.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread crytic_compile/platform/hardhat.py Outdated

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants