otter-sec/anchor
61.8
Adequate · 30 September 2026
102.3k
lines of production code
Rust
with TypeScript
2
measurements over time
What this system is
Anchor is a development toolkit for building Solana programs in Rust and interacting with them via TypeScript SDKs. It provides a macro-based DSL and CLI to automate IDL generation, handle account validation, and manage cross-program invocations. The framework ensures program safety through language abstractions and supports advanced features like zero-copy deserialization and integration with Solana Program Library tokens.
How it got here
2020–2021 — Anchor v1.2.0 release and framework rewrite
77 changes.
This period marks the initial release of Anchor v1.2.0, characterized by a comprehensive rewrite of the framework's core architecture and documentation. The work involved removing legacy procedural macros and IDL parsing modules while introducing new macro-based attributes for accounts, errors, and program structure. It also established new tooling, including an updated CLI with account inspection and coverage commands, and expanded the tutorial and test suites to validate the new features.
2022–2023 — Test coverage expansion and SDK features
55 changes.
This period focused on significantly expanding the test suite with comprehensive coverage for new language features such as CPI returns, PDA derivation, and safety checks. It also introduced key SDK enhancements, including automatic dependency resolution in AVM, optimized serialization via the lazy-account feature, and new TypeScript client libraries for SPL programs.
2024–2026 — IDL v0.1.0 and declare\_program! macro
32 changes.
This period focused on introducing the new IDL v0.1.0 schema and the \declare\_program!\ macro for generating strongly-typed Rust client bindings from external program IDLs. It also added comprehensive Anchor wrappers for Solana Token-2022 extensions and expanded test coverage for IDL generation, custom discriminators, and account validation logic.
Features
AVM introduces automatic Anchor-to-Solana CLI and platform-tools resolution
The Anchor Version Manager (AVM) now automatically resolves and installs the correct Solana CLI and platform-tools versions required by a given Anchor release. This is achieved through new static mapping files (\anchor-solana-map.toml\, \platform-tools-map.toml\, \solana-cli-versions.toml\) and corresponding Rust modules that map Anchor versions to recommended Solana CLI versions and platform-tools toolchains. The \avm\ CLI gains new \solana\ and \platform-tools\ subcommands to resolve, install, and manage these dependencies, ensuring that the build environment matches the Anchor version's requirements without manual configuration.
avm · high confidence
Add Basic-2 tutorial program demonstrating account initialization and state management
Introduces the Basic-2 tutorial program, which implements a simple counter state managed on-chain. The program allows users to initialize a new counter account with an associated authority and subsequently increment the counter value. It demonstrates key Anchor features including account initialization with specific space allocation, signer verification, and basic state mutation.
examples/tutorial/basic-2/programs/basic-2 · high confidence
Add Borsh serialization support with u256 and u128 types
The borsh package now includes support for 256-bit unsigned integers (u256) and 128-bit unsigned integers (u128) in addition to existing 64-bit types, allowing users to serialize and deserialize larger numeric values. This change also introduces TypeScript configuration and type definitions for the buffer-layout dependency, ensuring proper type checking and compilation for the serialization logic.
ts/packages/borsh · high confidence
Add Puppet tutorial program example
Introduces a new Anchor-based tutorial program (\puppet\) that demonstrates basic account initialization and data mutation. The example includes an \initialize\ instruction to create a \Data\ account and a \set\_data\ instruction to update its \u64\ field, serving as a reference for users learning the framework's account constraints and state management.
examples/tutorial/basic-3/programs/puppet · high confidence
Add TypeScript SDKs for SPL Binary Option, Binary Oracle Pair, and Feature Proposal programs
New TypeScript client libraries have been added for three Solana programs: \spl-binary-option\, \spl-binary-oracle-pair\, and \spl-feature-proposal\. Each package provides an IDL, Rust program stubs, and a full TypeScript SDK (including coders for accounts, instructions, and types) built on the \@anchor-lang/core\ framework. These SDKs enable developers to interact with the binary option trading logic, the oracle pair decision mechanism, and the feature proposal voting system directly from TypeScript applications.
(repo-wide) · high confidence
Add basic-0 tutorial example with Anchor integration
Introduces a new tutorial example (basic-0) that demonstrates how to generate and use a program client from an IDL using the @anchor-lang/core library. The example includes an Anchor.toml configuration for localnet deployment and a client.js script showing how to set up an AnchorProvider, load the IDL, instantiate the Program, and execute the initialize instruction.
examples/tutorial/basic-0 · high confidence
Add basic-0 tutorial program
Introduces the basic-0 example program for the tutorial, providing a minimal Anchor-based Solana program that defines an initialize instruction and the corresponding Initialize accounts struct.
examples/tutorial/basic-0/programs/basic-0 · high confidence
Add basic-1 tutorial program demonstrating account initialization and updates
Introduces the basic-1 tutorial program, which implements a simple state management pattern using Anchor. The program defines a \MyAccount\ struct to store a \u64\ data field and provides two instructions: \initialize\, which creates a new account with specific space requirements and assigns the initial data, and \update\, which modifies the data in an existing account. This serves as a foundational example for users learning how to define accounts, handle signers, and interact with the system program for account creation.
examples/tutorial/basic-1/programs/basic-1 · high confidence
Add basic-4 tutorial program with PDA-backed counter and authorization
The tutorial example basic-4 introduces a Solana program that manages a counter stored in an account derived via a program-derived address (PDA) using seeds \[b"counter"\] and a bump. The program provides an initialize instruction to create the counter account (paying with the authority) and an increment instruction that enforces authorization by requiring the caller to match the stored authority key, returning a custom Unauthorized error if not. The counter struct tracks the authority pubkey, a u64 count, and the bump seed, with explicit space calculation for account initialization.
examples/tutorial/basic-4/programs/basic-4 · high confidence
Add branded assets to the v2 documentation site
The v2 documentation site now includes a set of public assets to improve branding and user experience. This adds a new favicon with support for both light and dark color schemes, social media icons for Discord, GitHub, and Stack Exchange, and landing page illustrations for account validation in both light and dark modes.
docs-v2/src · high confidence
Add multithreaded and async integration test runner for client examples
The client example now includes a new \run-test.sh\ script that automates integration testing by deploying five programs (composite, basic-2, basic-4, events, optional) to a local \surfpool\ validator and executing the Rust client binary. The example client source has been updated to support three execution modes: a default single-threaded run, a multithreaded run using shared \Arc\-based clients, and an async run using \tokio\ (enabled via the \async\ feature). A \setup.tx\ file is also provided to define the program deployment configuration for the test environment.
client/example · high confidence
Added basic-5 tutorial example demonstrating PDA-based state management
The tutorial now includes a new example program (basic-5) that illustrates how to manage on-chain state using Program Derived Addresses (PDAs). The example defines an \ActionState\ account initialized with specific space requirements and seeds tied to the user's public key. It provides instructions to create this state, update the action status (walk, run, jump), and reset it, enforcing access control via \has\_one\ constraints to ensure only the owning user can modify the state.
examples/tutorial/basic-5/programs/basic-5 · high confidence
Anchor CLI v3.0.0 release with new account inspection and coverage commands
The CLI has been updated to version 3.0.0, introducing the \anchor account\ command to inspect program account data (including hex dumps and JSON output) and the \anchor coverage\ command to generate LCOV source-level coverage from SBF register traces. The release also adds \anchor codama\ commands to convert Anchor IDLs to the Codama format and generate client libraries in JavaScript, Rust, and Go, alongside a new \AbsolutePath\ trait to ensure all CLI paths are resolved to absolute forms.
cli/src · high confidence
Anchor wrappers for Token-2022 extensions
This location adds Anchor-compatible instruction wrappers and account structs for a comprehensive set of Solana Token-2022 extensions, including CPI Guard, Default Account State, Group and Group Member Pointers, Immutable Owner, Interest Bearing Mint, Memo Transfer, Metadata Pointer, Mint Close Authority, Non-Transferable, Pausable, Permanent Delegate, Token Group, Token Metadata, Transfer Fee, and Transfer Hook. These wrappers allow programs to initialize and update these extensions via CPI, with the specific exception of CPI Guard enable/disable which is deprecated in this wrapper because the Token-2022 program rejects CPI-initiated toggling (users must build and send the instruction client-side instead).
_spl/src/token\_2022\extensions · high confidence
Client now supports asynchronous RPC operations
The client library now offers an \async\ feature that enables non-blocking RPC calls. When enabled, the \Program\ and \RequestBuilder\ APIs expose asynchronous methods (e.g., \account\, \accounts\, \signed\_transaction\), allowing users to integrate the client into async contexts without blocking threads. The default behavior remains synchronous, maintaining backward compatibility for existing blocking code.
client/src · high confidence
Compile-time hashing and custom discriminator support
The language syntax crate now includes a local SHA-256 hashing implementation to enable compile-time hash calculations, removing the dependency on runtime Solana program imports for this purpose. Additionally, users can now override the default 8-byte discriminator for instructions and accounts by specifying a custom value via the \\#\[instruction\]\ or \\#\[account\]\ attributes.
lang/syn/src · high confidence
Initial release of Anchor v1.2.0 with comprehensive documentation and tooling
This release introduces Anchor v1.2.0, establishing the new version baseline for the framework. It includes a complete rewrite of the project documentation, adding detailed guides for contributing, a code of conduct, and security policies. The release also standardizes the development environment by introducing a cspell dictionary for consistent terminology, a .gitignore file to exclude build artifacts and local configurations, and a version bump script to automate release processes across Rust and TypeScript packages.
(repo-wide) · high confidence
Initial release of the \`derive/accounts\` macro with comprehensive constraint documentation
This change introduces the \lang/derive/accounts\ crate, providing the \\#\[derive(Accounts)\]\ macro for Anchor programs. The implementation includes support for standard account constraints such as \signer\, \mut\, \init\, and \seeds\, along with specific handling for duplicate mutable accounts via the \dup\ constraint. The diff also embeds extensive inline documentation detailing how these constraints function, including requirements for payer accounts, space allocation, and PDA derivation, serving as the primary reference for users defining account structs.
lang/derive/accounts · high confidence
Introduce @anchor-lang/errors package and refactor Anchor error handling
The Anchor TypeScript client now includes a dedicated \@anchor-lang/errors\ package that exports all Anchor error codes (such as \ANCHOR\ERROR\\_CONSTRAINT\_MUT\ and \ANCHOR\ERROR\\_ACCOUNT\_DISCRIMINATOR\_MISMATCH\) as constants and a union type. This change decouples error definitions from the core logic, allowing developers to import and check specific error codes directly. The core \anchor\ package has been updated to import these definitions from the new package, ensuring consistent error handling across the SDK.
ts/packages/anchor · high confidence
Introduce InitSpace derive macro for calculating account space
The \lang/derive/space\ crate now provides the \InitSpace\ derive macro, which automatically implements the \anchor\_lang::Space\ trait for structs and enums. This allows users to calculate the required account space for Anchor programs without manually summing field sizes. The macro supports primitive types, \String\, \Vec\, \Option\, arrays, and nested types, using the \\#\[max\_len(...)\]\ attribute to specify sizes for variable-length fields like strings and vectors. It also handles unit structs, unnamed fields, and enums by taking the maximum space of any variant.
lang/derive/space · high confidence
Introduce \`declare\_program!\` macro for generating client bindings from IDLs
The \declare\_program!\ macro is now available to automatically generate Rust client bindings for external Solana programs. By pointing to a program's IDL JSON file, the macro generates a module containing type definitions for accounts and instructions, CPI (Cross-Program Invocation) client structs, error definitions, event parsers, and constants for the program ID. This allows developers to interact with external programs using strongly-typed Rust code without manually writing the binding logic.
_lang/attribute/program/src/declare\program · high confidence
Introduce \`declare\_program!\` macro for on-chain program introspection
The \declare\_program!\ macro now generates a structured Rust module from a program's IDL, providing direct access to program definitions, account types, events, constants, and error codes. It automatically implements serialization and deserialization traits (Borsh and zero-copy) for accounts and events, generates CPI instruction wrappers with proper context handling, and provides off-chain client helpers for parsing account and event data from raw bytes.
_lang/attribute/program/src/declare\program/mods · high confidence
Introduce \`lazy-account\` feature for optimized serialization and size calculation
This change adds a new \lazy-account\ feature to the \anchor\_derive\_serde\ crate that enables optimized serialization and size calculation for accounts. When enabled, the \AnchorSerialize\ and \AnchorDeserialize\ derives generate implementations that calculate the size of serialized data without fully deserializing it, using a new \Lazy\ trait implementation. This optimization is particularly beneficial for large accounts where size calculation is frequent. The feature also introduces support for \\#\[borsh(use\_discriminant = false)\]\ attributes on enums when \lazy-account\ is enabled, while explicitly rejecting other \borsh\ attributes like \skip\ that are not yet compatible with the lazy deserialization logic.
lang/derive/serde · high confidence
Introduce anchor\_spl crate with CPI wrappers for Solana programs
This change introduces the \anchor\_spl\ crate, providing Anchor-compatible CPI wrappers and account types for key Solana programs. It includes modules for Token (v1), Token-2022, Associated Token, Metadata, Governance, Stake, and Memo, enabling developers to interact with these programs using Anchor's idioms. The crate also adds an \idl\_build\ module to support IDL generation for these wrapper types.
spl/src · high confidence
Introduction of \#\[error\_code\] attribute and error! macro for Solana program error handling
The \lang/attribute/error\ crate is added, providing the \\#\[error\_code\]\ procedural macro attribute and the \error!\ macro to simplify error definitions in Anchor programs. The \\#\[error\_code\]\ attribute allows developers to define a Rust enum where variants are automatically mapped to error codes and messages (via \\#\[msg\]\), while the \error!\ macro generates the necessary \AnchorError\ structs including source file and line information for better debugging. This enables users to return custom, descriptive errors from instruction handlers using a standard \Result\<T, Error\>\ pattern.
lang/attribute/error · high confidence
New \#\[account\] macro with lazy account loading and configurable discriminators
The \\#\[account\]\ attribute macro in \lang/attribute/account\ has been updated to support new \LazyAccount\ functionality, which caches deserialized field references to avoid repeated deserialization overhead, and allows users to override the default 8-byte discriminator via a \discriminator\ argument. The macro now also generates a \declare\_id!\-style macro for static program IDs and enforces that discriminators are not all-zero or empty.
lang/attribute/account · high confidence
New \#\[constant\] attribute for IDL inclusion
The lang/attribute/constant crate introduces a new \#\[constant\] procedural macro attribute. When the idl-build feature is enabled, this attribute marks const values so they are included in the generated Interface Description Language (IDL) by generating a helper function for their representation, while remaining functionally inert otherwise.
lang/attribute/constant · high confidence
New Docker build infrastructure and security pinning checks
This change introduces a new Makefile in the docker directory to streamline building and pushing the Anchor CLI Docker image (anchored at v1.2.0 with Solana toolchain v4.1.2) to the quay.io/ottersec registry. It also adds a check-docker-pin.sh script that enforces security best practices by ensuring all Dockerfiles use pinned SHA256 image references rather than mutable tags, failing the build if unpinned images are detected.
docker · high confidence
New IDL generation and conversion capabilities
The IDL module now provides a new \IdlBuilder\ API for generating IDLs via compilation, replacing the deprecated \build\_idl\ function. It also introduces bidirectional conversion between the new IDL spec (v0.1.0) and the legacy pre-v0.30 format, allowing users to migrate or maintain compatibility with older tooling.
idl · high confidence
New account types for lazy deserialization, schema migration, and optional accounts
The \lang/src/accounts\ module now includes \LazyAccount\ for on-demand field deserialization to reduce compute and memory usage, \Migration\<'info, From, To\>\ for handling account schema migrations with idempotent conversion, and \Option\<T\>\ to support optional positional accounts. Additionally, \InterfaceAccount\ is available for accounts owned by multiple programs, and \Box\<T\>\ is provided to prevent stack violations for large accounts.
lang/src/accounts · high confidence
New client and CPI account code generation modules
The \lang/syn/src/codegen/accounts\ module now generates dedicated \\_\_client\accounts\ and \\\_cpi\_client\_accounts\ modules. The client module produces structs with \Pubkey\ fields for use by external Rust clients, while the CPI module produces structs with \AccountInfo\ fields for cross-program invocation contexts. This change introduces new code generation logic for these specific account representations, including handling of optional fields, composite account re-exports, and signer/mutable metadata for both client-facing and CPI-facing account structures.
lang/syn/src/codegen/accounts · high confidence
New compile-time IDL generation via \`idl-build\` feature
The \lang/syn\ crate now includes a new \idl\ module that generates the Anchor IDL at compile time rather than relying on the CLI. This change introduces new source files (\accounts.rs\, \address.rs\, \common.rs\, \constant.rs\, \defined.rs\, \error.rs\, \event.rs\, \external.rs\, \program.rs\) that implement the \IdlBuild\ trait and generate IDL structures for accounts, events, errors, constants, and program metadata. Users can now build their IDL directly during compilation, which improves build times and allows for better IDE integration and type safety.
lang/syn/src/idl · high confidence
New event logging macros and CPI-based event emission
The \lang/attribute/event\ crate introduces the \\#\[event\]\ attribute macro for defining event structs and the \emit!\ macro for logging them via Solana's \sol\_log\_data\ syscall. It also adds the \emit\_cpi!\ macro (available with the \event-cpi\ feature), which logs events by invoking a self-CPI to ensure data is stored in the transaction ledger rather than just program logs. The \\#\[event\]\ macro supports custom discriminators via an argument and implements \AnchorSerialize\, \AnchorDeserialize\, \Event\, and \Discriminator\ traits, optimizing serialization with a default 256-byte capacity.
lang/attribute/event · high confidence
New idl/spec crate for Anchor IDL schema definitions
A new \idl/spec\ crate has been added to the project, introducing a dedicated Rust library for defining and serializing the Anchor Interface Definition Language (IDL) schema. This crate exports the core data structures (such as \Idl\, \IdlInstruction\, \IdlAccount\, and \IdlTypeDef\) required to represent smart contract interfaces, enabling standardized parsing and generation of IDL files for Solana programs.
idl/spec · high confidence
New proc-macro attributes for program structure and instruction customization
The \lang/attribute/program\ crate introduces three new procedural macros to define and customize Solana programs. The \\#\[program\]\ attribute marks the module containing instruction handlers and, when the \idl-build\ feature is enabled, automatically generates IDL print functions. The \\#\[instruction\]\ attribute allows developers to override the default 8-byte discriminator for specific instructions (e.g., using \discriminator = \[1, 2, 3, 4\]\). Additionally, the \declare\_program!\ macro enables the generation of client-side modules from external IDLs found in an \idls\ directory, facilitating cross-program interactions without requiring the external crate as a direct dependency.
lang/attribute/program/src · high confidence
New puppet-master tutorial example demonstrating CPI with Program type
Added a new tutorial example (puppet-master) that demonstrates how to invoke another program (puppet) via Cross-Program Invocation (CPI). The example shows using the \Program\ type to reference the target program and constructing a \CpiContext\ to call the \set\_data\ instruction, illustrating the updated language syntax for program interactions.
examples/tutorial/basic-3/programs/puppet-master · high confidence
New v2 documentation site and MCP API endpoint
The v2 Anchor documentation is now built with Astro, featuring a new site structure, Tailwind CSS styling, and Pagefind for client-side search. This change also introduces a new Model Context Protocol (MCP) API endpoint at /api/mcp, which allows external agents to search and read Anchor documentation pages via tools like search\_anchor\_docs and read\_anchor\_doc.
docs-v2 · high confidence
Support for multiple access control checks in a single attribute
The \\#\[access\_control\]\ attribute now accepts multiple comma-separated expressions, allowing users to define several preconditions or validation checks (e.g., \\#\[access\_control(is\_admin(&ctx), not\_paused(&ctx.accounts.config))\]\) that are executed in order before the instruction handler runs. This change enables more complex access control logic without requiring multiple separate attributes or manual ordering in the function body.
lang/attribute/access-control · high confidence
Removals
Removal of Anchor Accounts derive macro
The \derive\ crate has been removed, eliminating the \\#\[proc\_macro\_derive(Accounts)\]\ macro that previously allowed users to automatically generate account deserialization logic for structs annotated with \account\ attributes. This change removes the dependency on \anchor\_syn\ for this specific code generation capability.
derive · high confidence
Removal of Anchor-based code generation modules
The \syn/src/codegen\ directory has been completely removed, eliminating the code generation logic for Anchor accounts (\anchor.rs\), program entrypoints (\program.rs\), and IDLs (\idl.rs\). This deletes the implementation that generated \try\_anchor\ and \exit\ methods for account structs, as well as the instruction dispatching and entrypoint scaffolding for Solana programs.
syn/src/codegen · high confidence
Removal of Anchor-specific IDL parser modules
The parser modules responsible for generating the Anchor IDL from Rust source code have been removed. Specifically, \syn/src/parser/anchor.rs\ (which parsed \\#\[anchor\]\ attributes and constraints like \mut\, \signer\, \belongs\_to\, and \owner\), \syn/src/parser/file.rs\ (which orchestrated the parsing of program modules and account structs into an \Idl\ structure), \syn/src/parser/program.rs\ (which extracted RPC methods and their arguments), and the module declarations in \syn/src/parser/mod.rs\ are all deleted. This eliminates the ability to automatically derive Anchor-compatible Interface Description Language (IDL) definitions from the annotated Rust structs and program modules in this location.
syn/src/parser · high confidence
Removal of access-control and program proc-macro attributes
The \access\_control\ and \program\ procedural macro attributes have been removed from the codebase. The \access\_control\ attribute, which previously injected access checks into function bodies, and the \program\ attribute, which generated Anchor program code from module definitions, are no longer available for use.
attributes/access-control, attributes/program · high confidence
Removal of internal DSL and IDL parsing modules
The internal \syn/src/idl.rs\ and \syn/src/lib.rs\ modules have been removed from the codebase. This deletion eliminates the previous implementation of the Intermediate Language (IDL) data structures (including type definitions, methods, and account metadata) and the core DSL syntax tokens (such as \Program\, \Rpc\, and \AccountsStruct\ definitions). Users relying on these specific internal components for program introspection or DSL-based program definition will no longer have access to them.
syn/src · high confidence
Removal of legacy Anchor-based basic example
The legacy basic example located in \examples/basic\ has been removed. This deletion eliminates the old Makefile build configuration, the Anchor-based program source code (including account structures and instruction handlers), and the associated test file, effectively cleaning up the repository from this outdated implementation.
examples/basic · high confidence
Removal of legacy core library and Solana SDK dependencies
The \src/lib.rs\ file has been completely removed, eliminating the previous implementation of core types such as \ProgramAccount\, \Accounts\, and \Context\, along with the re-exported Solana SDK dependencies (\AccountInfo\, \Pubkey\, etc.) and Borsh serialization traits. This change removes the explicit coupling to these specific Solana SDK components and the legacy account handling structures from the library's public API.
src · high confidence
Architecture
Refactored \#\[program\] macro code generation into modular components
The code generation for the \\#\[program\]\ macro in \lang/syn/src/codegen/program\ has been restructured from a monolithic implementation into distinct modules (\entry\, \dispatch\, \handlers\, \instruction\, \cpi\, \accounts\, \idl\, and \common\). This refactoring organizes the generation of the program entrypoint, instruction dispatch logic, handler wrappers, instruction structs, CPI client methods, and IDL support into separate, focused files. For users, this maintains the existing functionality of the Anchor framework while improving the maintainability and clarity of the underlying macro code, with no changes to the public API or generated program behavior.
lang/syn/src/codegen/program · high confidence
Behavioural changes
Anchor framework codebase restructuring and new account types
The \lang/src\ module has been reorganized into distinct source files, introducing a dedicated \error\ crate for framework error codes and adding support for new account types such as \ProgramData\ (for BPF upgradeable state) and \System\ (for system program CPI wrappers). The framework now includes a \BpfWriter\ for optimized memory writes, implements \LazyAccount\ optimizations for sized fields, and provides new context structures (\Context\ and \CpiContext\) for handling account validation and cross-program invocations. Additionally, legacy IDL instruction support is deprecated in favor of Program Metadata, and the \AccountInfo\ type is deprecated in favor of \UncheckedAccount\ for safer unchecked account handling.
lang/src · high confidence
Custom error code generation and macro hygiene improvements
The Anchor framework now generates code for custom error enums defined with \\#\[error\_code\]\, automatically implementing \Display\, \name\, and conversion traits to integrate with \anchor\_lang::error::Error\. This allows users to define structured error types that include optional custom messages and support a configurable code offset. Additionally, the codegen module introduces a \private\_ident\ helper to ensure macro-generated identifiers are hygienic, preventing shadowing issues between user code and macro-generated variables.
lang/syn/src/codegen · high confidence
Instruction parsing now supports return values and configuration attributes
The parser in \lang/syn/src/parser/program\ has been updated to allow instruction handlers to specify return values, which are now captured in the \IxReturn\ struct, and to preserve \\#\[cfg\]\ attributes on instructions via the new \cfgs\ field. Additionally, the parser now explicitly validates that instruction arguments are named (rejecting \self\ receivers) and enforces that only one fallback function is defined, providing clearer error messages for these constraints.
lang/syn/src/parser/program · high confidence
NPM package now supports non-Linux platforms via global binary fallback
The @anchor-lang/cli NPM package now attempts to use a globally installed \anchor\ binary when running on non-Linux or non-x86\_64 architectures, rather than failing immediately. The new \anchor.js\ wrapper first checks if the bundled binary is compatible (Linux x64); if not, it searches the system PATH for a globally installed \anchor\ executable with a matching version. This allows users on macOS, Windows, or ARM platforms to use the NPM package as a version-aware shim for their existing global installation.
cli/npm-package · high confidence
New parser module structure with safety checks and error parsing
The parser module has been restructured into dedicated files (context, docs, error, program) to handle crate parsing, documentation extraction, and error code parsing. A key behavioral change is the addition of safety checks that enforce documentation for unsafe account fields (AccountInfo/UncheckedAccount) using a '/// CHECK:' comment, with accurate line/column reporting. Error enums now support the \#\[msg("...")\] attribute for specifying error strings, and the parser uses BTreeMap for module storage to ensure deterministic iteration order.
lang/syn/src/parser · high confidence
Parser refactoring and enhanced validation for account constraints
The account constraint parser has been restructured into a dedicated module, introducing stricter validation rules and new constraint support. Users will now encounter compile-time errors if they attempt to use the \init\ constraint on a \SystemAccount\, as this type represents an existing account that cannot be initialized. The parser now enforces that \init\ constraints require the presence of a \system\_program\ field, and token-related initializations (\Token\, \AssociatedToken\, \Mint\) strictly require a \token\_program\ field. Additionally, the \init\_if\_needed\ feature now preserves mint and extension constraints (such as \mint::authority\ and \extensions::group\_member\_pointer\) to ensure that reused accounts are re-validated against their original configuration. The \event\_cpi\ feature automatically injects \event\_authority\ and \program\ fields into accounts structs marked with \\#\[event\_cpi\]\ to support self-CPI event emission.
lang/syn/src/parser/accounts · high confidence
SPL Governance TypeScript SDK v3.0.0
The SPL Governance TypeScript client has been updated to version 3.0.0, introducing a new program interface that includes instructions for creating realms, depositing and withdrawing governing tokens, managing governance delegates, and handling proposals and votes. This release adds support for V2 account structures (such as realmV2, proposalV2, and governanceV2) alongside legacy V1 types, and updates the underlying Anchor integration to use the @anchor-lang/core package for encoding and decoding program data.
ts/packages/spl-governance · high confidence
Standardized build script and test configuration for TypeScript packages
The TypeScript build process now uses a new \build-packages.sh\ script that enforces \yarn --frozen-lockfile\ for the Anchor package to ensure reproducible builds, while other packages continue using their internal \init:yarn\ scripts. Additionally, a dedicated \tsconfig.json\ has been added for the test suite, configuring the compiler to target ES2019 with CommonJS modules and strict type-checking options.
ts · high confidence
Test coverage
Add benchmarking infrastructure and scripts; Added IDL test program for Rust generics and precise-capture syntax; Added IDL workspace test suite; Added JavaScript tests for the basic-2 tutorial program; Added Pyth oracle integration tests; Added TypeScript integration test for the typescript program; Added TypeScript tests for PDA derivation and account resolution; Added TypeScript tests for relations derivation and address constraint handling; Added benchmark test suite for Anchor program performance; Added benchmarking tests for binary size, compute units, and stack memory; Added comprehensive IDL generation test programs; Added comprehensive test coverage for Anchor language features; Added compute unit test for zero-copy program; Added deployment migration script for custom coder tests; Added escrow program example with token-2022 support; Added integration tests for Anchor CLI IDL and verification commands; Added integration tests for Solana SPL programs via Anchor; Added integration tests for \declare\_program!\ CPI scenarios; Added integration tests for custom coders; Added integration tests for the IDO pool program; Added integration tests for the Tic-Tac-Toe program; Added integration tests for the chat Solana program; Added integration tests for the declare\_program macro; Added integration tests for the realloc constraint group; Added lockup program implementation and test utilities; Added lockup program test suite and deployment scripts; Added migration scripts for test suite examples; Added misc test program to validate Anchor account constraints and data structures; Added native auction-house program tests; Added realloc program tests for various payer scenarios; Added shared test programs for misc, TypeScript, and zero-copy contexts; Added test coverage for IDL relations derivation; Added test coverage for remaining accounts functionality; Added test coverage for the Anchor SPL metadata feature; Added test for ambiguous discriminator compilation error; Added test for cross-program invocation in basic-3 tutorial; Added test for declared program ID validation; Added test harness for CPI event emission; Added test harness for SPL Associated Token Account program; Added test harness for Solana Token Extensions; Added test harness for SystemAccount type; Added test harness for \declare\_program!\ macro edge cases; Added test harness for custom error propagation and require macros; Added test harness for the Cashiers Check program; Added test harness programs for Solana program dependency validation; Added test harnesses for native system and SPL token programs; Added test program for Anchor optional accounts; Added test program for composite account structures; Added test program for float data types; Added test program for init\_if\_needed account initialization; Added test program for multiple test suites; Added test program for optional account constraints and PDA initialization; Added test program for relations derivation and address constraints; Added test program for remaining accounts handling; Added test program for zeroed discriminators; Added test programs for CLI IDL command validation; Added test programs for Pyth, sysvars, and TypeScript integration; Added test programs to verify safety checks for unchecked accounts; Added test suite for declare-id program validation; Added test suite for misc Anchor program; Added test suite for misc Anchor programs and CI configuration; Added test suite for multiple error definitions; Added test suite for multiple scripts support; Added test suite for selective test execution; Added test suite for the \declare\_program!\ macro; Added test suite for the registry staking program; Added test suite for token extensions program; Added tests for AccountLoader buffer truncation and legacy migration; Added tests for Anchor error handling and IDL validation; Added tests for Anchor program event handling and CPI events; Added tests for BPF upgradeable state program constraints; Added tests for BPF upgradeable state program validation; Added tests for CPI return value handling; Added tests for CPI return value handling and security fixes; Added tests for Escrow program token program compatibility; Added tests for IDL attribute parsing, qualified builtin handling, and program argument validation; Added tests for IDL documentation, case conversion, and workspace program access; Added tests for InterfaceAccount account substitution fix; Added tests for InterfaceAccount account substitution validation; Added tests for LazyAccount usage and behavior; Added tests for automatic SOL and SPL token account generation in test validators; Added tests for basic-1 tutorial program; Added tests for custom discriminator validation and error handling; Added tests for custom discriminators on instructions, accounts, and events; Added tests for custom program validation logic; Added tests for debugger symbol resolution; Added tests for duplicate mutable account constraints; Added tests for instruction argument count and type validation; Added tests for instruction argument validation; Added tests for legacy IDL CLI commands; Added tests for multiple test suites with separate local validators; Added tests for optional account handling in Anchor programs; Added tests for overflow-checks enforcement and arithmetic panics; Added tests for safety checks on unchecked accounts; Added tests for solana-program dependency conflict detection; Added tests for system account initialization and validation; Added tests for sysvar account validation; Added tests for the Lamports trait and overflow error handling; Added tests for the LazyAccount program; Added tests for the Tic-Tac-Toe program; Added tests for the anchor account CLI subcommand; Added tests for validator-clone functionality; Added tests for validator-clone program initialization; Added tests for zero-copy account creation and updates; Added token-proxy program example for testing Anchor SPL interactions; Added zero-CPI test program to validate cross-program invocation with AccountLoader; Added zero-copy account test program; Initial test suite for the IDO pool program; Native auction-house test suite with Anchor integration.
Dependencies
Anchor framework upgraded to version 1.2.0 with Solana 3.x toolchain support
The Anchor framework and its associated CLI, language crates, and TypeScript packages have been updated to version 1.2.0. This release upgrades the underlying Solana toolchain dependencies to version 3.x (e.g., \solana-pubkey 3.0.0\, \solana-hash 3.1.0\) and updates the Borsh serialization library to 1.5.7. The Rust edition for the CLI macros has been bumped to 2024, and the minimum supported Rust version (MSRV) for \anchor-lang\ is now 1.89. Additionally, the documentation site has been migrated to Astro v6 with React 19, and the AVM (Anchor Version Manager) now uses \reqwest\ 0.13.4 to align with Solana crate requirements.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 63 → 62 (-1.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 76 → 77 (+0.1)
- Architecture 80 → 78 (-1.8)
- Maturity 57 → 59 (+2.2)
- Readiness 64 → 58 (-5.9)
- Security 74 → 75 (+1.0)
- Accessibility 68 → 66 (-2.1)
- Performance 70 (new)
Resolved (122)
- Critical CVE: [CVE redacted] (ts/yarn.lock)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 3) (lang/syn/src/parser/accounts/mod.rs)
- Duplicated block (13 lines × 2) (lang/syn/src/codegen/accounts/try_accounts.rs)
- Duplicated block (16 lines × 2) (lang/attribute/program/src/declare_program/mods/cpi.rs)
- Duplicated block (19 lines × 2) (lang/syn/src/codegen/accounts/__client_accounts.rs)
- Duplicated block (21 lines × 2) (cli/src/keygen.rs)
- Duplicated block (9 lines × 2) (avm/src/platform_tools.rs)
- Duplicated block (9 lines × 2) (lang/syn/src/codegen/accounts/constraints.rs)
- FileTooLong: src/platform_tools.rs (avm/src/platform_tools.rs)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- High CVE: [CVE redacted] (ts/yarn.lock)
- …and 102 more
New (73)
- Duplicate method name rpc() with different return types (RpcClient vs AsyncRpcClient) on the same type Program. This is a signature collision or implies overloading which is not standard in Rust without distinct names. It creates confusion about which client to use.
- Duplicated block (10 lines × 3) (lang/syn/src/parser/accounts/mod.rs)
- Duplicated block (14–15 lines × 2) (lang/syn/src/codegen/accounts/try_accounts.rs)
- Duplicated block (16 lines × 2) (cli/src/keygen.rs)
- Duplicated block (16 lines × 2) (lang/attribute/program/src/declare_program/mods/cpi.rs)
- Duplicated block (19 lines × 2) (avm/src/lib.rs)
- Duplicated block (22 lines × 2) (lang/syn/src/codegen/accounts/__client_accounts.rs)
- Duplicated block (9 lines × 2) (lang/syn/src/codegen/accounts/constraints.rs)
- Excessive method proliferation for transaction sending. There are 4 distinct methods for sending transactions that differ only by versioning and spinner/config options. This violates the principle of least surprise and makes the API verbose.
- FileTooLong: src/main.rs (avm/src/main.rs)
- FunctionTooLong: anchor_cli::run_test_suite (cli/src/lib.rs)
- High CVE: [GHSA redacted] (ts/yarn.lock)
- High CVE: [GHSA redacted] (ts/yarn.lock)
- High CVE: [GHSA redacted] (ts/yarn.lock)
- High CVE: [GHSA redacted] (ts/yarn.lock)
- High vulnerability: [GHSA redacted] (docs-v2/bun.lock)
- Hotspot: lang/syn/src/codegen/accounts/__cpi_client_accounts.rs (lang/syn/src/codegen/accounts/__cpi_client_accounts.rs)
- Inconsistent handling of wallet/payer. Config.wallet_kp() returns a keypair, while Client and RequestBuilder accept a generic C (likely a signer trait). This forces users to convert between keypairs and signers manually in some places but not others.
- Inconsistent naming and signature for discovery operations. Config uses discover with an override object, Manifest has two variants (discover and discover_from_path), and TestConfig uses discover with explicit path arguments. The intent (locating configuration/test files) is the same, but the API surface is fragmented.
- Inconsistent return types and naming for program identity retrieval. pubkey() returns a Pubkey (likely), while keypair() and keypair_file() return Result (likely containing a Keypair or path). This forces callers to use different logic to get the program's address depending on whether they have a keypair or just need the ID.
- …and 53 more
Changes since last survey
- 33 commits — 17 feature/other, 16 fixes
By area
- (root) — 5 commits
- docs-v2/src — 5 commits
- .github/workflows — 4 commits
- cli/src — 4 commits
- lang/syn — 3 commits
- avm/src — 2 commits
- ts/packages — 2 commits
- avm/anchor-solana-map.toml — 1 commit
- avm/install — 1 commit
- idl/src — 1 commit
- lang/attribute — 1 commit
- lang/src — 1 commit
- lang/tests — 1 commit
- tests/idl — 1 commit
- tests/spl — 1 commit
Notable commits
- fix: Fix path hygiene for composite fields in #[derive(Accounts)] (#4668)
- fix: Fix/init if needed mint extensions (#4845)
- fix: fix(avm): avoid copying AVM onto itself (#5064)
- fix: fix(avm): configure PATH from installer (#5065)
- fix: fix(avm): map Anchor 1.2 to Solana 4.1.2 (#5034)
- fix: fix(ci): temporarily use legacy validator for validator-clone (#5044)
- fix: fix(client): Don't report failed transactions in events listener (#4884)
- fix: fix(lang): Store CPI return data in Vec (#4931)
- fix: fix(lang): emit 'info lifetime on CPI client accounts struct with no fields (#4737)
- fix: fix(lang): support safe borsh attrs in IDL build (#4623)
- fix: fix(lang/syn): Fix macro hygiene to avoid shadowing between user code and macro generated variables (#5105)
- fix: fix(ts): anchor.BN undefined in ESM — guard CJS globals in index.ts (#4525)
- fix: fix(ts): reject invalid hex strings (#4807)
- fix: fix: Followup to security.json metadata issues (#5052)
- fix: fix: Update AVM version mappings for v3 compatability (#5055)
- fix: fix: report safety check field locations accurately (#5120)
- change: Add NO_DNA support to Anchor CLI (#4773)
- change: Pass v3 arch to build-sbf and update platform-tools to v1.57 (#4684)
- change: Resolve and install project toolchains in AVM (#4824)
- change: ci: cancel superseded pull request workflow runs (#5041)
- …and 13 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
otter-sec/anchor was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit bce1622349d2303483e990548f424c79e510b5f1 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.