Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

docs: `foundryup` recommendation can install a version different from the repository-pinned Foundry toolchain

未关闭 适合新手
#403 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
1/5
预计耗时
1-3 小时
新手友好度
86/100
Issue 类型
文档
描述清晰度
描述清楚
活跃度
活跃
技术栈
solidity

调研方向

阅读 README.md 中受影响的设置和恢复说明,并对照 .mise.toml 中固定的 Foundry 版本。验证文档中的命令使用仓库固定的 toolchain,并保留现有的 semver-lock 工作流。完成的标准是 README.md 不再引导 contributors 使用未固定版本的 foundryup 路径,且其中的设置说明与权威版本定义一致。

由索引模型根据 Issue 内容生成。

描述

Summary

The repository pins Foundry to a specific version in .mise.toml for deterministic builds, ABI/storage snapshots, and semver-lock hashes.

However, the README currently recommends running:

foundryup

when semver-lock fails because of a Foundry version mismatch.

foundryup normally updates Foundry independently of the repository's .mise.toml pin. This can leave contributors on a different Foundry version from the one explicitly required by the repository and CI.

The recovery instruction can therefore make the original version-mismatch problem worse rather than resolving it.

Affected Files

  • README.md
  • .mise.toml

Current Behavior

.mise.toml explicitly states that the repository pins tooling so contributors and CI execute builds, tests, snapshots, and semver-lock generation with byte-identical tooling.

The current pin is:

[tools]
foundry = "1.5.1"

The README, however, says that if semver-lock still fails because of a Foundry version mismatch, contributors should run:

foundryup
just semver-lock

This does not guarantee installation of Foundry 1.5.1.

Why This Is a Problem

A contributor can follow the README exactly and still end up using a toolchain different from CI.

Example flow:

  1. Contributor clones the repository.
  2. Contributor has an older or newer Foundry version.
  3. just semver-lock fails.
  4. Contributor follows the documented recovery instructions.
  5. foundryup installs the current Foundry release.
  6. The installed version is not necessarily the repository-pinned 1.5.1.
  7. Generated semver-lock hashes or snapshots can still differ from CI.

This contradicts the reproducibility requirement documented in .mise.toml.

Expected Behavior

The README should direct contributors to install the exact repository-pinned toolchain.

For example:

mise install
mise exec -- just semver-lock

or otherwise explicitly install the same Foundry version used by CI.

Suggested Fix

Replace:

If CI still rejects it (Foundry version mismatch), update your local Foundry first:

```bash
foundryup
just semver-lock

with something similar to:

```markdown
If CI still rejects it because of a Foundry version mismatch, install the repository-pinned toolchain:

```bash
mise install
mise exec -- just semver-lock

The Foundry version is pinned in .mise.toml and should match CI.


## Additional Improvement

The setup section currently also says:

```bash
just install-foundry

Consider making mise install the canonical setup path if .mise.toml is intended to be the authoritative source of tool versions.

Alternatively, just install-foundry could explicitly install the version defined by .mise.toml.

Impact

This is primarily a developer-experience and build-reproducibility issue.

It can cause:

  • unnecessary CI failures;
  • semver-lock hash mismatches;
  • snapshot differences;
  • contributors regenerating artifacts with unsupported tooling;
  • confusion when following the documented remediation steps.

Environment

Repository:

base/contracts

Branch:

main

Affected documentation:

README.md

Toolchain definition:

.mise.toml

主要语言
Solidity
星标
329
派生
247
平均合并
1 天 4 小时
30 天内合并 PR
13

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

base/contracts 的其他 Issue

查看 base/contracts 的全部 Issue

相似的 Issue

更多 Build System Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。