|
9 years ago | |
---|---|---|
contracts | 9 years ago | |
migrations | 9 years ago | |
scripts | 9 years ago | |
test | 9 years ago | |
.gitignore | 9 years ago | |
CONTRIBUTING.md | 9 years ago | |
LICENSE | 9 years ago | |
README.md | 9 years ago | |
package.json | 9 years ago | |
truffle.js | 9 years ago |
Zeppelin is a library for writing secure Smart Contracts on Ethereum.
With Zeppelin, you can build distributed applications, protocols and organizations:
Zeppelin integrates with Truffle, an Ethereum development environment. Please install Truffle and initialize your project with truffle init
.
sudo npm install -g truffle
mkdir myproject && cd myproject
truffle init
To install the Zeppelin library, run:
npm i zeppelin-solidity
After that, you'll get all the library's contracts in the contracts/zeppelin
folder. You can use the contracts in the library like so:
import "./zeppelin/Ownable.sol";
contract MyContract is Ownable {
...
}
NOTE: The current distribution channel is npm, which is not ideal. We're looking into providing a better tool for code distribution, and ideas are welcome.
To create a bounty for your contract, inherit from the base Bounty contract and provide an implementation for deployContract()
returning the new contract address.
import "./zeppelin/Bounty.sol";
import "./YourContract.sol";
contract YourBounty is Bounty {
function deployContract() internal returns(address) {
return new YourContract()
}
}
At contracts/YourContract.sol
contract YourContract {
function checkInvariant() returns(bool) {
// Implement your logic to make sure that none of the state is broken.
}
}
At migrations/2_deploy_contracts.js
module.exports = function(deployer) {
deployer.deploy(YourContract);
deployer.deploy(YourBounty);
};
After deploying the contract, send rewards money into the bounty contract.
From truffle console
address = 'your account address'
reward = 'reward to pay to a researcher'
web3.eth.sendTransaction({
from:address,
to:bounty.address,
value: web3.toWei(reward, "ether")
}
For each researcher who wants to hack the contract and claims the reward, refer to our test for the detail.
If you manage to protect your contract from security researchers and wants to end the bounty, kill the contract so that all the rewards go back to the owner of the bounty contract.
bounty.kill()
We also support Truffle Beta npm integration. If you're using Truffle Beta, the contracts in node_modules
will be enough, so feel free to delete the copies at your contracts
folder. If you're using Truffle Beta, you can use Zeppelin contracts like so:
import "zeppelin-solidity/contracts/Ownable.sol";
contract MyContract is Ownable {
...
}
For more info see the Truffle Beta package management tutorial.
Zeppelin is meant to provide secure, tested and community-audited code, but please use common sense when doing anything that deals with real money! We take no responsibility for your implementation decisions and any security problem you might experience.
If you find a security issue, please email security@openzeppelin.org.
Building a distributed application, protocol or organization with Zeppelin?
Interested in contributing to Zeppelin?
among others...
TODO
Code released under the MIT License.