セキュリティとテスト56セキュリティとテスト見つかったリソース: 56 / 56セキュリティとテスト(56)デバッグと検査(31)CodeTracerCodeTracerは、幅広いweb3プログラミング言語をサポートするように設計された、ユーザーフレンドリーなタイムトラベルデバッガーです。EDB: The Ethereum Project DebuggerEDBは、オンチェーンまたはテストでのコントラクトの動作に対するIDEレベルの可視性が必要な場合に、ステッピング、ローカル変数、ウォッチ、およびブレークポイントを備えたSolidity実行用のソースレベルデバッガーです。Simbolik - Solidity DebuggerSimbolikは、従来のブレークポイントデバッグとシンボリック実行を組み合わせた強力なSolidityデバッガーであり、開発者が考えられるすべての実行パスを探索し、脆弱性を正確に発見できるようにします。VSCode拡張機能として利用可能なSimbolikは、既存のワークフローにシームレスに統合され、ブレークポイントスタイルのデバッグ、SolidityおよびEVMレベルの検査、および形式的検証機能を提供します。Abi NinjaAbi Ninjaは、既知のABI、貼り付けられたABI、または逆コンパイルされたバイトコードを使用してコントラクトを呼び出すためのブラウザUIです。ローカルで実行されているHardhatまたはAnvilノードを含む多くのネットワーク全体で、プロキシを認識した読み取りが可能です。4byte4byte.directory maps four-byte function selectors and 32-byte event-signature hashes to their human-readable signatures. Builders query it when decoding calldata or logs from contracts without a published ABI.ABI Calldata Layout VisualizerThe ABI Calldata Layout Visualizer decodes ABI calldata and draws its byte layout, showing where heads, tails, and offsets sit in the encoded payload. Builders open it when a plain decoder does not explain why an encoding is wrong.evm-storageevm-storage turns a transaction hash into readable state diffs and can list a contract's full storage. Builders install the command line tool when they need to see exactly which storage slots a call changed.EVMConnectorEVMConnector is a browser workspace for calling contract functions on any EVM chain, with saved contracts and shareable call links. Builders use it to drive a contract without writing a script.forkyforky is a fork choice viewer for the Ethereum beacon chain. Consensus client developers self-host it or use the public instances to see and debug fork choice behavior on mainnet and testnets.geas (Good Ethereum Assembler)geas, the Good Ethereum Assembler, is an assembler for writing raw EVM bytecode by hand, maintained by a go-ethereum core developer. It is used for EIP test cases and other low-level contract work.hardhat-tracerhardhat-tracer is a Hardhat plugin that prints internal calls, events, and storage operations for a transaction in the console. Hardhat users install it to see what actually happened inside a failing test transaction.HashEx ABI EncoderThe HashEx ABI Encoder is a web form that ABI-encodes constructor and function arguments from a pasted signature and values. Builders use it when they need encoded arguments and are not at a terminal.heimdall-rsheimdall-rs is a Rust EVM toolkit that disassembles bytecode, decompiles contracts, generates control flow graphs, and decodes calldata and traces. Builders reach for it when they need to understand a contract that has no published source.pyevmasmpyevmasm is a Python disassembler and assembler for EVM bytecode from Trail of Bits. Analysis scripts import it to turn bytecode into instructions and back.Radar (Auditware)Radar, from Auditware, is a static analysis tool that covers Solidity as well as Rust, Anchor, and Stylus contracts. Auditors run it to get findings across a mixed contract codebase.recursive calldata decoderA calldata decoder that also unwraps nested function calls. Builders open it when a flat decoder leaves the inner calls of a batched or forwarded transaction unreadable.scopelintscopelint is an opinionated formatter and linter for Foundry Solidity projects. Builders install it to hold a codebase to the ScopeLift conventions.Semgrep (smart-contracts rules)Semgrep is a pattern-based static analysis tool with rulesets for Solidity vulnerabilities. Builders run those rules over a codebase to catch known vulnerable patterns and style issues before review.SmartContractGUISmartContractGUI turns an uploaded ABI into an interface for reading from and writing to that contract on any EVM chain. Builders use it when they have an ABI but no frontend.sol-profilersol-profiler is a command line tool that lists a Solidity contract's methods with their visibility, mutability and modifiers. Reviewers run it to see the surface of a contract at a glance.sol2umlsol2uml generates UML class and storage-layout diagrams from Solidity source or from verified contracts. Builders run it to see contract relationships and how state variables are packed into storage.TenderlyTenderly provides transaction simulation, trace debugging, alerting, and Virtual TestNets for contracts. Builders use it to replay a failing transaction, watch deployed contracts, and test against a forked network.Tenderly CLIThe Tenderly CLI is the command line client for Tenderly, pushing contracts for verification and driving error tracking, monitoring, and alerting. Builders install it to run those steps from a terminal or a continuous integration job.tracoortracoor is an explorer for beacon states and execution traces. Client and protocol developers self-host it to inspect block and state traces on devnets and testnets.Web3ClientWeb3Client is a browser tool for creating, testing, and sharing contract ABIs and the calls made against them. Builders use it to work out a call and hand the result to someone else.WalnutEVM向けのWebベースのトランザクションデバッガーおよびシミュレーター。オープンソースでセルフホスト可能です。すべてのステップで変数の状態を検査し、デプロイ前にトランザクションをシミュレートし、ガス使用量をプロファイリングします。任意のRPCプロバイダーをサポートします。viem-tracerviem-tracerはViemクライアントを拡張し、失敗したethestimateGasおよびethsendTransaction呼び出しに、sourcify.devでデコードされた人間が読めるトレース出力が自動的に含まれるようにします。また、debug_traceCallの周りに型付きヘルパーを追加するため、開発者は既存のRPCスタックから離れることなく実行を検査できます。EVMoleEVMole extracts function selectors, arguments, and control flow from raw EVM bytecode, including contracts with no verified source. Builders point it at an unknown contract to work out what its functions take.revm-inspectorsrevm-inspectors is a Rust crate of EVM execution hooks and tracing built on revm, and it powers call tracing in Reth and Foundry. Rust builders import it to build their own tracers and debuggers.hardhat-gas-reporterスマートコントラクトのテストスイートにガス使用量の分析を提供するHardhatプラグインです。OP Stackチェーンの専用サポートがあり、15万以上のGitHubリポジトリで依存関係として使用され、NPMから週に10万回以上ダウンロードされています。SlippySlippy is a Solidity linter for static analysis of smart contracts. Teams install the npm package to lint contracts as part of a build.ファズ/プロパティテスト(18)ChimeraChimeraは、FoundryでSolidityのテストを記述し、Echidna、Medusa、Halmos、Kontrolなどの他のオープンソースツールで再利用できるようにするためのフレームワークです。Slitherスリザーは、SolidityおよびVyper向けのTrail of BitsのPython静的解析エンジンです。CIで実行して検出器を起動したり、コントラクトの構造ビューを出力したり、コードベース全体にわたるカスタムチェックをスクリプト化したりできます。SynpressSynpressは、Playwrightにイーサリアム対応のブラウザ自動化を重ねることで、CIでウォレットのポップアップやチェーンの切り替えを含む分散型アプリケーション (dapp) のエンドツーエンドテストを行えるようにします。AderynAderynは、プロトコルエンジニアやセキュリティ研究者がSolidityコードベースの脆弱性を見つけるのを支援するように設計された、CyfrinのオープンソースでRustベースのSolidityスマート・コントラクト静的アナライザーです。TitanoboaTitanoboaは、完全なFoundryループの外部でコントラクトを実験する際の高速なフィードバックループのための、インタラクティブなVyperインタープリターおよびテストハーネスです。MedusaMedusaは、Echidnaにインスパイアされたステートフルなスマートコントラクトファザーです。スマートコントラクトの並列ファジングテストと、高度なスマートコントラクトの不変条件の検証を提供します。solidity-coveragesolidity-coverageは、Hardhat開発者プラットフォームにスマートコントラクトのコードカバレッジを提供します。精度が非常に高く、完全なviaIR Solidityコンパイルと、Solidity固有のコードブランチパターンの大規模なセットをサポートしています。約23万のGitHubプロジェクトにインストールされており、NPMから週に約10万回ダウンロードされています。hevmhevmは、スマート・コントラクトの問題を見つけることができる、オープンソースで最先端の高速なシンボリックおよびコンクリートEVM実行エンジンです。そのシンボリック実行および分析システムを通じて、hevmはコントラクトをシンボリック、半コンクリート、またはコンクリートに実行してバグを見つけたり、2つの異なるコントラクトを比較して不一致がないか確認し、等価性チェックを実行したりできます。Crytic-PropertiesCrytic-Propertiesは、ERC-20、ERC-721、ERC-4626など、最も広く使用されているトークン標準のいくつかに対する再利用可能なセキュリティテストのスイートです。bulloakBranching Tree Technique (分岐ツリー手法) に基づくスマートコントラクトのテストジェネレーターです。AssertoorAssertoor runs configurable checks and assertions against a live Ethereum devnet to validate its behavior. Client and devnet teams use it to confirm a running network is healthy, in the same family as Hive.contender (Flashbots)contender from Flashbots is a load-testing tool that floods EVM execution nodes over JSON-RPC and benchmarks the results. Teams benchmarking a client point it at an endpoint to generate load and measure throughput.EchidnaEchidna is a property-based and grammar fuzzer for Ethereum smart contracts. Builders and auditors write properties with it to find inputs that break contract invariants.eth-testereth-tester is a pluggable in-memory Ethereum backend used by web3.py for fast unit tests. Python builders import it when tests should run against a simulated chain instead of a node.ItyFuzzItyFuzz is a bytecode-level smart-contract fuzzer that combines fuzzing with symbolic analysis. Builders and auditors run it against EVM bytecode when source-level fuzzing is not enough or no source is available.spamoorspamoor is a configurable Ethereum transaction generator for load-testing testnets and devnets with realistic traffic. Teams point it at a network to see how it behaves under sustained transaction volume.goevmlabgoevmlab is an EVM fuzzing and differential testing lab built by a go-ethereum core developer. EVM implementers use it to fuzz their own implementation and compare its behavior against others to find divergences.HiveHive is an end-to-end integration test harness that runs Ethereum clients in Docker across simulator scenarios. Client teams use it to check that implementations agree with each other.形式的検証(7)K Semantics of the Ethereum Virtual Machine (EVM)KEVMは、EVMのKフレームワークの実行可能なセマンティクスです。適合性がチェックされた実行、シンボリックな探索、ガスの推論、またはイーサリアムのルールを厳密に追跡する証明が必要な場合は、これをバイトコードに向けます。haxhaxは、Rustの大部分をF*やRocqなどの形式言語に高保証で変換するためのツールです。Kontrol - formal verification tool based on Foundry and KEVMKontrolは、FoundryのプロパティテストをKEVMがサポートする証明に引き上げるため、生のKEVM単独の場合よりも手書きの仕様作業を減らして、形式的保証を追求できます。ActActは、EVMプログラムのすべての動作を記述するためのイーサリアムの宣言型仕様言語およびツールチェーンです。これにより、SMTソルバー、定理証明器、または経済分析ツールは、具体的な実装に対する自動的な詳細化証明を含め、バイトコードレベルの正確性とインセンティブの互換性について推論できます。Certora AutoProverCertora AutoProver is an AI bot that automates parts of formal verification for smart contracts. Verification engineers use it to generate and run checks with less manual specification work.VerifereumVerifereumは、イーサリアムのスマート・コントラクトをHOL4を利用した定理証明に接続するため、自動化されたSMTアプローチでは不十分な場合に、非常に強力な正確性の主張を目指すことができます。Certora ProverCertora Prover is a cloud formal-verification service that checks specifications written in CVL against deployed contract code. Verification engineers use it to prove that a contract holds stated properties for all inputs.リソースを提案するリストに掲載すべき優れたビルダーリソースをご存知ですか?Issueを作成して共有してください。リソースを提案する (新しいタブで開きます)