Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

docs: `foundryup` recommendation can install a version different from the repository-pinned Foundry toolchain

Đang mở Phù hợp với người mới
#403 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
1/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
86/100
Loại issue
Tài liệu
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
solidity

Hướng nghiên cứu

Đọc các hướng dẫn thiết lập và khôi phục liên quan trong README.md cùng với phiên bản Foundry được ghim trong .mise.toml. Xác minh rằng các lệnh được ghi lại sử dụng toolchain được ghim bởi repository và duy trì workflow semver-lock hiện có. Được xem là hoàn tất khi README.md không còn hướng dẫn contributors đến một đường dẫn foundryup không được ghim và hướng dẫn thiết lập của README.md khớp với định nghĩa phiên bản có thẩm quyền.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Summary

The repository pins Foundry to a specific version in .mise.toml for deterministic builds, ABI/storage snapshots, and semver-lock hashes.

However, the README currently recommends running:

foundryup

when semver-lock fails because of a Foundry version mismatch.

foundryup normally updates Foundry independently of the repository's .mise.toml pin. This can leave contributors on a different Foundry version from the one explicitly required by the repository and CI.

The recovery instruction can therefore make the original version-mismatch problem worse rather than resolving it.

Affected Files

  • README.md
  • .mise.toml

Current Behavior

.mise.toml explicitly states that the repository pins tooling so contributors and CI execute builds, tests, snapshots, and semver-lock generation with byte-identical tooling.

The current pin is:

[tools]
foundry = "1.5.1"

The README, however, says that if semver-lock still fails because of a Foundry version mismatch, contributors should run:

foundryup
just semver-lock

This does not guarantee installation of Foundry 1.5.1.

Why This Is a Problem

A contributor can follow the README exactly and still end up using a toolchain different from CI.

Example flow:

  1. Contributor clones the repository.
  2. Contributor has an older or newer Foundry version.
  3. just semver-lock fails.
  4. Contributor follows the documented recovery instructions.
  5. foundryup installs the current Foundry release.
  6. The installed version is not necessarily the repository-pinned 1.5.1.
  7. Generated semver-lock hashes or snapshots can still differ from CI.

This contradicts the reproducibility requirement documented in .mise.toml.

Expected Behavior

The README should direct contributors to install the exact repository-pinned toolchain.

For example:

mise install
mise exec -- just semver-lock

or otherwise explicitly install the same Foundry version used by CI.

Suggested Fix

Replace:

If CI still rejects it (Foundry version mismatch), update your local Foundry first:

```bash
foundryup
just semver-lock

with something similar to:

```markdown
If CI still rejects it because of a Foundry version mismatch, install the repository-pinned toolchain:

```bash
mise install
mise exec -- just semver-lock

The Foundry version is pinned in .mise.toml and should match CI.


## Additional Improvement

The setup section currently also says:

```bash
just install-foundry

Consider making mise install the canonical setup path if .mise.toml is intended to be the authoritative source of tool versions.

Alternatively, just install-foundry could explicitly install the version defined by .mise.toml.

Impact

This is primarily a developer-experience and build-reproducibility issue.

It can cause:

  • unnecessary CI failures;
  • semver-lock hash mismatches;
  • snapshot differences;
  • contributors regenerating artifacts with unsupported tooling;
  • confusion when following the documented remediation steps.

Environment

Repository:

base/contracts

Branch:

main

Affected documentation:

README.md

Toolchain definition:

.mise.toml

Ngôn ngữ chính
Solidity
Star
327
Fork
245
Merge trung bình
1 ngày 4 giờ
Pull request đã merge (30 ngày)
13

Chuẩn bị môi trường

Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của base/contracts

Tất cả issue của base/contracts

Issue tương tự

Thêm issue về Build System

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.