An optional detector that highlights all the constant addresses appearing in the source code.

Using hardcoded addresses can sometimes indicate poor contract design. Some constant addresses may need to be set dynamically, e.g., using contractAddress, or at least have a way to change them at runtime, for example, when upgrading a contract.

contract Main {
  proxy: Address;
  init() {
    // Bad: Constant address highlighted by the analyzer.
    self.proxy = address("UQBKgXCNLPexWhs2L79kiARR1phGH1LwXxRbNsCFF9doczSI");
  }
}

Use instead:

contract Main {
  proxy: Address;
  init() {
   let proxy: Proxy = initOf Proxy(myAddress());
    // OK: Address depends on how the proxy contact has been deployed
    self.proxy = contractAddress(proxy);
  }
}

Hierarchy (view full)

Constructors

Properties

severity: Severity = Severity.INFO

Gets the severity of the detector.

Accessors

  • get id(): string
  • Gets the short identifier of the detector, used in analyzer warnings.

    Returns string

    The unique identifier of the detector.

  • get shareImportedWarnings(): WarningsBehavior
  • Defines the behavior of warnings generated by this detector when working with multiple projects within a single Tact configuration.

    Here are the available options:

    1. "union" Leave this value if you don't care about warnings generated in other projects.
    2. "intersect" If the warning is generated for some source location of the imported file, it should be generated by each of the projects. Example: Constants from an imported file should not be reported iff they are unused in all the projects, so you need "intersect".

    Returns WarningsBehavior

  • get usesSouffle(): boolean
  • Checks whether this detector needs the Soufflé binary to be executed.

    Returns boolean

Methods