Skip to content
CAI
Software that uses CAICheck a score

otter-sec/anchor

61.8

Adequate · 30 September 2026

102.3k

lines of production code

Rust

with TypeScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Anchor is a development toolkit for building Solana programs in Rust and interacting with them via TypeScript SDKs. It provides a macro-based DSL and CLI to automate IDL generation, handle account validation, and manage cross-program invocations. The framework ensures program safety through language abstractions and supports advanced features like zero-copy deserialization and integration with Solana Program Library tokens.

How it got here

2020–2021 — Anchor v1.2.0 release and framework rewrite

77 changes.

This period marks the initial release of Anchor v1.2.0, characterized by a comprehensive rewrite of the framework's core architecture and documentation. The work involved removing legacy procedural macros and IDL parsing modules while introducing new macro-based attributes for accounts, errors, and program structure. It also established new tooling, including an updated CLI with account inspection and coverage commands, and expanded the tutorial and test suites to validate the new features.

2022–2023 — Test coverage expansion and SDK features

55 changes.

This period focused on significantly expanding the test suite with comprehensive coverage for new language features such as CPI returns, PDA derivation, and safety checks. It also introduced key SDK enhancements, including automatic dependency resolution in AVM, optimized serialization via the lazy-account feature, and new TypeScript client libraries for SPL programs.

2024–2026 — IDL v0.1.0 and declare\_program! macro

32 changes.

This period focused on introducing the new IDL v0.1.0 schema and the \declare\_program!\ macro for generating strongly-typed Rust client bindings from external program IDLs. It also added comprehensive Anchor wrappers for Solana Token-2022 extensions and expanded test coverage for IDL generation, custom discriminators, and account validation logic.

Features

AVM introduces automatic Anchor-to-Solana CLI and platform-tools resolution

The Anchor Version Manager (AVM) now automatically resolves and installs the correct Solana CLI and platform-tools versions required by a given Anchor release. This is achieved through new static mapping files (\anchor-solana-map.toml\, \platform-tools-map.toml\, \solana-cli-versions.toml\) and corresponding Rust modules that map Anchor versions to recommended Solana CLI versions and platform-tools toolchains. The \avm\ CLI gains new \solana\ and \platform-tools\ subcommands to resolve, install, and manage these dependencies, ensuring that the build environment matches the Anchor version's requirements without manual configuration.

avm · high confidence

Add Basic-2 tutorial program demonstrating account initialization and state management

Introduces the Basic-2 tutorial program, which implements a simple counter state managed on-chain. The program allows users to initialize a new counter account with an associated authority and subsequently increment the counter value. It demonstrates key Anchor features including account initialization with specific space allocation, signer verification, and basic state mutation.

examples/tutorial/basic-2/programs/basic-2 · high confidence

Add Borsh serialization support with u256 and u128 types

The borsh package now includes support for 256-bit unsigned integers (u256) and 128-bit unsigned integers (u128) in addition to existing 64-bit types, allowing users to serialize and deserialize larger numeric values. This change also introduces TypeScript configuration and type definitions for the buffer-layout dependency, ensuring proper type checking and compilation for the serialization logic.

ts/packages/borsh · high confidence

Add Puppet tutorial program example

Introduces a new Anchor-based tutorial program (\puppet\) that demonstrates basic account initialization and data mutation. The example includes an \initialize\ instruction to create a \Data\ account and a \set\_data\ instruction to update its \u64\ field, serving as a reference for users learning the framework's account constraints and state management.

examples/tutorial/basic-3/programs/puppet · high confidence

Add TypeScript SDKs for SPL Binary Option, Binary Oracle Pair, and Feature Proposal programs

New TypeScript client libraries have been added for three Solana programs: \spl-binary-option\, \spl-binary-oracle-pair\, and \spl-feature-proposal\. Each package provides an IDL, Rust program stubs, and a full TypeScript SDK (including coders for accounts, instructions, and types) built on the \@anchor-lang/core\ framework. These SDKs enable developers to interact with the binary option trading logic, the oracle pair decision mechanism, and the feature proposal voting system directly from TypeScript applications.

(repo-wide) · high confidence

Add basic-0 tutorial example with Anchor integration

Introduces a new tutorial example (basic-0) that demonstrates how to generate and use a program client from an IDL using the @anchor-lang/core library. The example includes an Anchor.toml configuration for localnet deployment and a client.js script showing how to set up an AnchorProvider, load the IDL, instantiate the Program, and execute the initialize instruction.

examples/tutorial/basic-0 · high confidence

Add basic-0 tutorial program

Introduces the basic-0 example program for the tutorial, providing a minimal Anchor-based Solana program that defines an initialize instruction and the corresponding Initialize accounts struct.

examples/tutorial/basic-0/programs/basic-0 · high confidence

Add basic-1 tutorial program demonstrating account initialization and updates

Introduces the basic-1 tutorial program, which implements a simple state management pattern using Anchor. The program defines a \MyAccount\ struct to store a \u64\ data field and provides two instructions: \initialize\, which creates a new account with specific space requirements and assigns the initial data, and \update\, which modifies the data in an existing account. This serves as a foundational example for users learning how to define accounts, handle signers, and interact with the system program for account creation.

examples/tutorial/basic-1/programs/basic-1 · high confidence

Add basic-4 tutorial program with PDA-backed counter and authorization

The tutorial example basic-4 introduces a Solana program that manages a counter stored in an account derived via a program-derived address (PDA) using seeds \[b"counter"\] and a bump. The program provides an initialize instruction to create the counter account (paying with the authority) and an increment instruction that enforces authorization by requiring the caller to match the stored authority key, returning a custom Unauthorized error if not. The counter struct tracks the authority pubkey, a u64 count, and the bump seed, with explicit space calculation for account initialization.

examples/tutorial/basic-4/programs/basic-4 · high confidence

Add branded assets to the v2 documentation site

The v2 documentation site now includes a set of public assets to improve branding and user experience. This adds a new favicon with support for both light and dark color schemes, social media icons for Discord, GitHub, and Stack Exchange, and landing page illustrations for account validation in both light and dark modes.

docs-v2/src · high confidence

Add multithreaded and async integration test runner for client examples

The client example now includes a new \run-test.sh\ script that automates integration testing by deploying five programs (composite, basic-2, basic-4, events, optional) to a local \surfpool\ validator and executing the Rust client binary. The example client source has been updated to support three execution modes: a default single-threaded run, a multithreaded run using shared \Arc\-based clients, and an async run using \tokio\ (enabled via the \async\ feature). A \setup.tx\ file is also provided to define the program deployment configuration for the test environment.

client/example · high confidence

Added basic-5 tutorial example demonstrating PDA-based state management

The tutorial now includes a new example program (basic-5) that illustrates how to manage on-chain state using Program Derived Addresses (PDAs). The example defines an \ActionState\ account initialized with specific space requirements and seeds tied to the user's public key. It provides instructions to create this state, update the action status (walk, run, jump), and reset it, enforcing access control via \has\_one\ constraints to ensure only the owning user can modify the state.

examples/tutorial/basic-5/programs/basic-5 · high confidence

Anchor CLI v3.0.0 release with new account inspection and coverage commands

The CLI has been updated to version 3.0.0, introducing the \anchor account\ command to inspect program account data (including hex dumps and JSON output) and the \anchor coverage\ command to generate LCOV source-level coverage from SBF register traces. The release also adds \anchor codama\ commands to convert Anchor IDLs to the Codama format and generate client libraries in JavaScript, Rust, and Go, alongside a new \AbsolutePath\ trait to ensure all CLI paths are resolved to absolute forms.

cli/src · high confidence

Anchor wrappers for Token-2022 extensions

This location adds Anchor-compatible instruction wrappers and account structs for a comprehensive set of Solana Token-2022 extensions, including CPI Guard, Default Account State, Group and Group Member Pointers, Immutable Owner, Interest Bearing Mint, Memo Transfer, Metadata Pointer, Mint Close Authority, Non-Transferable, Pausable, Permanent Delegate, Token Group, Token Metadata, Transfer Fee, and Transfer Hook. These wrappers allow programs to initialize and update these extensions via CPI, with the specific exception of CPI Guard enable/disable which is deprecated in this wrapper because the Token-2022 program rejects CPI-initiated toggling (users must build and send the instruction client-side instead).

_spl/src/token\_2022\extensions · high confidence

Client now supports asynchronous RPC operations

The client library now offers an \async\ feature that enables non-blocking RPC calls. When enabled, the \Program\ and \RequestBuilder\ APIs expose asynchronous methods (e.g., \account\, \accounts\, \signed\_transaction\), allowing users to integrate the client into async contexts without blocking threads. The default behavior remains synchronous, maintaining backward compatibility for existing blocking code.

client/src · high confidence

Compile-time hashing and custom discriminator support

The language syntax crate now includes a local SHA-256 hashing implementation to enable compile-time hash calculations, removing the dependency on runtime Solana program imports for this purpose. Additionally, users can now override the default 8-byte discriminator for instructions and accounts by specifying a custom value via the \\#\[instruction\]\ or \\#\[account\]\ attributes.

lang/syn/src · high confidence

Initial release of Anchor v1.2.0 with comprehensive documentation and tooling

This release introduces Anchor v1.2.0, establishing the new version baseline for the framework. It includes a complete rewrite of the project documentation, adding detailed guides for contributing, a code of conduct, and security policies. The release also standardizes the development environment by introducing a cspell dictionary for consistent terminology, a .gitignore file to exclude build artifacts and local configurations, and a version bump script to automate release processes across Rust and TypeScript packages.

(repo-wide) · high confidence

Initial release of the \`derive/accounts\` macro with comprehensive constraint documentation

This change introduces the \lang/derive/accounts\ crate, providing the \\#\[derive(Accounts)\]\ macro for Anchor programs. The implementation includes support for standard account constraints such as \signer\, \mut\, \init\, and \seeds\, along with specific handling for duplicate mutable accounts via the \dup\ constraint. The diff also embeds extensive inline documentation detailing how these constraints function, including requirements for payer accounts, space allocation, and PDA derivation, serving as the primary reference for users defining account structs.

lang/derive/accounts · high confidence

Introduce @anchor-lang/errors package and refactor Anchor error handling

The Anchor TypeScript client now includes a dedicated \@anchor-lang/errors\ package that exports all Anchor error codes (such as \ANCHOR\ERROR\\_CONSTRAINT\_MUT\ and \ANCHOR\ERROR\\_ACCOUNT\_DISCRIMINATOR\_MISMATCH\) as constants and a union type. This change decouples error definitions from the core logic, allowing developers to import and check specific error codes directly. The core \anchor\ package has been updated to import these definitions from the new package, ensuring consistent error handling across the SDK.

ts/packages/anchor · high confidence

Introduce InitSpace derive macro for calculating account space

The \lang/derive/space\ crate now provides the \InitSpace\ derive macro, which automatically implements the \anchor\_lang::Space\ trait for structs and enums. This allows users to calculate the required account space for Anchor programs without manually summing field sizes. The macro supports primitive types, \String\, \Vec\, \Option\, arrays, and nested types, using the \\#\[max\_len(...)\]\ attribute to specify sizes for variable-length fields like strings and vectors. It also handles unit structs, unnamed fields, and enums by taking the maximum space of any variant.

lang/derive/space · high confidence

Introduce \`declare\_program!\` macro for generating client bindings from IDLs

The \declare\_program!\ macro is now available to automatically generate Rust client bindings for external Solana programs. By pointing to a program's IDL JSON file, the macro generates a module containing type definitions for accounts and instructions, CPI (Cross-Program Invocation) client structs, error definitions, event parsers, and constants for the program ID. This allows developers to interact with external programs using strongly-typed Rust code without manually writing the binding logic.

_lang/attribute/program/src/declare\program · high confidence

Introduce \`declare\_program!\` macro for on-chain program introspection

The \declare\_program!\ macro now generates a structured Rust module from a program's IDL, providing direct access to program definitions, account types, events, constants, and error codes. It automatically implements serialization and deserialization traits (Borsh and zero-copy) for accounts and events, generates CPI instruction wrappers with proper context handling, and provides off-chain client helpers for parsing account and event data from raw bytes.

_lang/attribute/program/src/declare\program/mods · high confidence

Introduce \`lazy-account\` feature for optimized serialization and size calculation

This change adds a new \lazy-account\ feature to the \anchor\_derive\_serde\ crate that enables optimized serialization and size calculation for accounts. When enabled, the \AnchorSerialize\ and \AnchorDeserialize\ derives generate implementations that calculate the size of serialized data without fully deserializing it, using a new \Lazy\ trait implementation. This optimization is particularly beneficial for large accounts where size calculation is frequent. The feature also introduces support for \\#\[borsh(use\_discriminant = false)\]\ attributes on enums when \lazy-account\ is enabled, while explicitly rejecting other \borsh\ attributes like \skip\ that are not yet compatible with the lazy deserialization logic.

lang/derive/serde · high confidence

Introduce anchor\_spl crate with CPI wrappers for Solana programs

This change introduces the \anchor\_spl\ crate, providing Anchor-compatible CPI wrappers and account types for key Solana programs. It includes modules for Token (v1), Token-2022, Associated Token, Metadata, Governance, Stake, and Memo, enabling developers to interact with these programs using Anchor's idioms. The crate also adds an \idl\_build\ module to support IDL generation for these wrapper types.

spl/src · high confidence

Introduction of \#\[error\_code\] attribute and error! macro for Solana program error handling

The \lang/attribute/error\ crate is added, providing the \\#\[error\_code\]\ procedural macro attribute and the \error!\ macro to simplify error definitions in Anchor programs. The \\#\[error\_code\]\ attribute allows developers to define a Rust enum where variants are automatically mapped to error codes and messages (via \\#\[msg\]\), while the \error!\ macro generates the necessary \AnchorError\ structs including source file and line information for better debugging. This enables users to return custom, descriptive errors from instruction handlers using a standard \Result\<T, Error\>\ pattern.

lang/attribute/error · high confidence

New \#\[account\] macro with lazy account loading and configurable discriminators

The \\#\[account\]\ attribute macro in \lang/attribute/account\ has been updated to support new \LazyAccount\ functionality, which caches deserialized field references to avoid repeated deserialization overhead, and allows users to override the default 8-byte discriminator via a \discriminator\ argument. The macro now also generates a \declare\_id!\-style macro for static program IDs and enforces that discriminators are not all-zero or empty.

lang/attribute/account · high confidence

New \#\[constant\] attribute for IDL inclusion

The lang/attribute/constant crate introduces a new \#\[constant\] procedural macro attribute. When the idl-build feature is enabled, this attribute marks const values so they are included in the generated Interface Description Language (IDL) by generating a helper function for their representation, while remaining functionally inert otherwise.

lang/attribute/constant · high confidence

New Docker build infrastructure and security pinning checks

This change introduces a new Makefile in the docker directory to streamline building and pushing the Anchor CLI Docker image (anchored at v1.2.0 with Solana toolchain v4.1.2) to the quay.io/ottersec registry. It also adds a check-docker-pin.sh script that enforces security best practices by ensuring all Dockerfiles use pinned SHA256 image references rather than mutable tags, failing the build if unpinned images are detected.

docker · high confidence

New IDL generation and conversion capabilities

The IDL module now provides a new \IdlBuilder\ API for generating IDLs via compilation, replacing the deprecated \build\_idl\ function. It also introduces bidirectional conversion between the new IDL spec (v0.1.0) and the legacy pre-v0.30 format, allowing users to migrate or maintain compatibility with older tooling.

idl · high confidence

New account types for lazy deserialization, schema migration, and optional accounts

The \lang/src/accounts\ module now includes \LazyAccount\ for on-demand field deserialization to reduce compute and memory usage, \Migration\<'info, From, To\>\ for handling account schema migrations with idempotent conversion, and \Option\<T\>\ to support optional positional accounts. Additionally, \InterfaceAccount\ is available for accounts owned by multiple programs, and \Box\<T\>\ is provided to prevent stack violations for large accounts.

lang/src/accounts · high confidence

New client and CPI account code generation modules

The \lang/syn/src/codegen/accounts\ module now generates dedicated \\_\_client\accounts\ and \\\_cpi\_client\_accounts\ modules. The client module produces structs with \Pubkey\ fields for use by external Rust clients, while the CPI module produces structs with \AccountInfo\ fields for cross-program invocation contexts. This change introduces new code generation logic for these specific account representations, including handling of optional fields, composite account re-exports, and signer/mutable metadata for both client-facing and CPI-facing account structures.

lang/syn/src/codegen/accounts · high confidence

New compile-time IDL generation via \`idl-build\` feature

The \lang/syn\ crate now includes a new \idl\ module that generates the Anchor IDL at compile time rather than relying on the CLI. This change introduces new source files (\accounts.rs\, \address.rs\, \common.rs\, \constant.rs\, \defined.rs\, \error.rs\, \event.rs\, \external.rs\, \program.rs\) that implement the \IdlBuild\ trait and generate IDL structures for accounts, events, errors, constants, and program metadata. Users can now build their IDL directly during compilation, which improves build times and allows for better IDE integration and type safety.

lang/syn/src/idl · high confidence

New event logging macros and CPI-based event emission

The \lang/attribute/event\ crate introduces the \\#\[event\]\ attribute macro for defining event structs and the \emit!\ macro for logging them via Solana's \sol\_log\_data\ syscall. It also adds the \emit\_cpi!\ macro (available with the \event-cpi\ feature), which logs events by invoking a self-CPI to ensure data is stored in the transaction ledger rather than just program logs. The \\#\[event\]\ macro supports custom discriminators via an argument and implements \AnchorSerialize\, \AnchorDeserialize\, \Event\, and \Discriminator\ traits, optimizing serialization with a default 256-byte capacity.

lang/attribute/event · high confidence

New idl/spec crate for Anchor IDL schema definitions

A new \idl/spec\ crate has been added to the project, introducing a dedicated Rust library for defining and serializing the Anchor Interface Definition Language (IDL) schema. This crate exports the core data structures (such as \Idl\, \IdlInstruction\, \IdlAccount\, and \IdlTypeDef\) required to represent smart contract interfaces, enabling standardized parsing and generation of IDL files for Solana programs.

idl/spec · high confidence

New proc-macro attributes for program structure and instruction customization

The \lang/attribute/program\ crate introduces three new procedural macros to define and customize Solana programs. The \\#\[program\]\ attribute marks the module containing instruction handlers and, when the \idl-build\ feature is enabled, automatically generates IDL print functions. The \\#\[instruction\]\ attribute allows developers to override the default 8-byte discriminator for specific instructions (e.g., using \discriminator = \[1, 2, 3, 4\]\). Additionally, the \declare\_program!\ macro enables the generation of client-side modules from external IDLs found in an \idls\ directory, facilitating cross-program interactions without requiring the external crate as a direct dependency.

lang/attribute/program/src · high confidence

New puppet-master tutorial example demonstrating CPI with Program type

Added a new tutorial example (puppet-master) that demonstrates how to invoke another program (puppet) via Cross-Program Invocation (CPI). The example shows using the \Program\ type to reference the target program and constructing a \CpiContext\ to call the \set\_data\ instruction, illustrating the updated language syntax for program interactions.

examples/tutorial/basic-3/programs/puppet-master · high confidence

New v2 documentation site and MCP API endpoint

The v2 Anchor documentation is now built with Astro, featuring a new site structure, Tailwind CSS styling, and Pagefind for client-side search. This change also introduces a new Model Context Protocol (MCP) API endpoint at /api/mcp, which allows external agents to search and read Anchor documentation pages via tools like search\_anchor\_docs and read\_anchor\_doc.

docs-v2 · high confidence

Support for multiple access control checks in a single attribute

The \\#\[access\_control\]\ attribute now accepts multiple comma-separated expressions, allowing users to define several preconditions or validation checks (e.g., \\#\[access\_control(is\_admin(&ctx), not\_paused(&ctx.accounts.config))\]\) that are executed in order before the instruction handler runs. This change enables more complex access control logic without requiring multiple separate attributes or manual ordering in the function body.

lang/attribute/access-control · high confidence

Removals

Removal of Anchor Accounts derive macro

The \derive\ crate has been removed, eliminating the \\#\[proc\_macro\_derive(Accounts)\]\ macro that previously allowed users to automatically generate account deserialization logic for structs annotated with \account\ attributes. This change removes the dependency on \anchor\_syn\ for this specific code generation capability.

derive · high confidence

Removal of Anchor-based code generation modules

The \syn/src/codegen\ directory has been completely removed, eliminating the code generation logic for Anchor accounts (\anchor.rs\), program entrypoints (\program.rs\), and IDLs (\idl.rs\). This deletes the implementation that generated \try\_anchor\ and \exit\ methods for account structs, as well as the instruction dispatching and entrypoint scaffolding for Solana programs.

syn/src/codegen · high confidence

Removal of Anchor-specific IDL parser modules

The parser modules responsible for generating the Anchor IDL from Rust source code have been removed. Specifically, \syn/src/parser/anchor.rs\ (which parsed \\#\[anchor\]\ attributes and constraints like \mut\, \signer\, \belongs\_to\, and \owner\), \syn/src/parser/file.rs\ (which orchestrated the parsing of program modules and account structs into an \Idl\ structure), \syn/src/parser/program.rs\ (which extracted RPC methods and their arguments), and the module declarations in \syn/src/parser/mod.rs\ are all deleted. This eliminates the ability to automatically derive Anchor-compatible Interface Description Language (IDL) definitions from the annotated Rust structs and program modules in this location.

syn/src/parser · high confidence

Removal of access-control and program proc-macro attributes

The \access\_control\ and \program\ procedural macro attributes have been removed from the codebase. The \access\_control\ attribute, which previously injected access checks into function bodies, and the \program\ attribute, which generated Anchor program code from module definitions, are no longer available for use.

attributes/access-control, attributes/program · high confidence

Removal of internal DSL and IDL parsing modules

The internal \syn/src/idl.rs\ and \syn/src/lib.rs\ modules have been removed from the codebase. This deletion eliminates the previous implementation of the Intermediate Language (IDL) data structures (including type definitions, methods, and account metadata) and the core DSL syntax tokens (such as \Program\, \Rpc\, and \AccountsStruct\ definitions). Users relying on these specific internal components for program introspection or DSL-based program definition will no longer have access to them.

syn/src · high confidence

Removal of legacy Anchor-based basic example

The legacy basic example located in \examples/basic\ has been removed. This deletion eliminates the old Makefile build configuration, the Anchor-based program source code (including account structures and instruction handlers), and the associated test file, effectively cleaning up the repository from this outdated implementation.

examples/basic · high confidence

Removal of legacy core library and Solana SDK dependencies

The \src/lib.rs\ file has been completely removed, eliminating the previous implementation of core types such as \ProgramAccount\, \Accounts\, and \Context\, along with the re-exported Solana SDK dependencies (\AccountInfo\, \Pubkey\, etc.) and Borsh serialization traits. This change removes the explicit coupling to these specific Solana SDK components and the legacy account handling structures from the library's public API.

src · high confidence

Architecture

Refactored \#\[program\] macro code generation into modular components

The code generation for the \\#\[program\]\ macro in \lang/syn/src/codegen/program\ has been restructured from a monolithic implementation into distinct modules (\entry\, \dispatch\, \handlers\, \instruction\, \cpi\, \accounts\, \idl\, and \common\). This refactoring organizes the generation of the program entrypoint, instruction dispatch logic, handler wrappers, instruction structs, CPI client methods, and IDL support into separate, focused files. For users, this maintains the existing functionality of the Anchor framework while improving the maintainability and clarity of the underlying macro code, with no changes to the public API or generated program behavior.

lang/syn/src/codegen/program · high confidence

Behavioural changes

Anchor framework codebase restructuring and new account types

The \lang/src\ module has been reorganized into distinct source files, introducing a dedicated \error\ crate for framework error codes and adding support for new account types such as \ProgramData\ (for BPF upgradeable state) and \System\ (for system program CPI wrappers). The framework now includes a \BpfWriter\ for optimized memory writes, implements \LazyAccount\ optimizations for sized fields, and provides new context structures (\Context\ and \CpiContext\) for handling account validation and cross-program invocations. Additionally, legacy IDL instruction support is deprecated in favor of Program Metadata, and the \AccountInfo\ type is deprecated in favor of \UncheckedAccount\ for safer unchecked account handling.

lang/src · high confidence

Custom error code generation and macro hygiene improvements

The Anchor framework now generates code for custom error enums defined with \\#\[error\_code\]\, automatically implementing \Display\, \name\, and conversion traits to integrate with \anchor\_lang::error::Error\. This allows users to define structured error types that include optional custom messages and support a configurable code offset. Additionally, the codegen module introduces a \private\_ident\ helper to ensure macro-generated identifiers are hygienic, preventing shadowing issues between user code and macro-generated variables.

lang/syn/src/codegen · high confidence

Instruction parsing now supports return values and configuration attributes

The parser in \lang/syn/src/parser/program\ has been updated to allow instruction handlers to specify return values, which are now captured in the \IxReturn\ struct, and to preserve \\#\[cfg\]\ attributes on instructions via the new \cfgs\ field. Additionally, the parser now explicitly validates that instruction arguments are named (rejecting \self\ receivers) and enforces that only one fallback function is defined, providing clearer error messages for these constraints.

lang/syn/src/parser/program · high confidence

NPM package now supports non-Linux platforms via global binary fallback

The @anchor-lang/cli NPM package now attempts to use a globally installed \anchor\ binary when running on non-Linux or non-x86\_64 architectures, rather than failing immediately. The new \anchor.js\ wrapper first checks if the bundled binary is compatible (Linux x64); if not, it searches the system PATH for a globally installed \anchor\ executable with a matching version. This allows users on macOS, Windows, or ARM platforms to use the NPM package as a version-aware shim for their existing global installation.

cli/npm-package · high confidence

New parser module structure with safety checks and error parsing

The parser module has been restructured into dedicated files (context, docs, error, program) to handle crate parsing, documentation extraction, and error code parsing. A key behavioral change is the addition of safety checks that enforce documentation for unsafe account fields (AccountInfo/UncheckedAccount) using a '/// CHECK:' comment, with accurate line/column reporting. Error enums now support the \#\[msg("...")\] attribute for specifying error strings, and the parser uses BTreeMap for module storage to ensure deterministic iteration order.

lang/syn/src/parser · high confidence

Parser refactoring and enhanced validation for account constraints

The account constraint parser has been restructured into a dedicated module, introducing stricter validation rules and new constraint support. Users will now encounter compile-time errors if they attempt to use the \init\ constraint on a \SystemAccount\, as this type represents an existing account that cannot be initialized. The parser now enforces that \init\ constraints require the presence of a \system\_program\ field, and token-related initializations (\Token\, \AssociatedToken\, \Mint\) strictly require a \token\_program\ field. Additionally, the \init\_if\_needed\ feature now preserves mint and extension constraints (such as \mint::authority\ and \extensions::group\_member\_pointer\) to ensure that reused accounts are re-validated against their original configuration. The \event\_cpi\ feature automatically injects \event\_authority\ and \program\ fields into accounts structs marked with \\#\[event\_cpi\]\ to support self-CPI event emission.

lang/syn/src/parser/accounts · high confidence

SPL Governance TypeScript SDK v3.0.0

The SPL Governance TypeScript client has been updated to version 3.0.0, introducing a new program interface that includes instructions for creating realms, depositing and withdrawing governing tokens, managing governance delegates, and handling proposals and votes. This release adds support for V2 account structures (such as realmV2, proposalV2, and governanceV2) alongside legacy V1 types, and updates the underlying Anchor integration to use the @anchor-lang/core package for encoding and decoding program data.

ts/packages/spl-governance · high confidence

Standardized build script and test configuration for TypeScript packages

The TypeScript build process now uses a new \build-packages.sh\ script that enforces \yarn --frozen-lockfile\ for the Anchor package to ensure reproducible builds, while other packages continue using their internal \init:yarn\ scripts. Additionally, a dedicated \tsconfig.json\ has been added for the test suite, configuring the compiler to target ES2019 with CommonJS modules and strict type-checking options.

ts · high confidence

Test coverage

Add benchmarking infrastructure and scripts; Added IDL test program for Rust generics and precise-capture syntax; Added IDL workspace test suite; Added JavaScript tests for the basic-2 tutorial program; Added Pyth oracle integration tests; Added TypeScript integration test for the typescript program; Added TypeScript tests for PDA derivation and account resolution; Added TypeScript tests for relations derivation and address constraint handling; Added benchmark test suite for Anchor program performance; Added benchmarking tests for binary size, compute units, and stack memory; Added comprehensive IDL generation test programs; Added comprehensive test coverage for Anchor language features; Added compute unit test for zero-copy program; Added deployment migration script for custom coder tests; Added escrow program example with token-2022 support; Added integration tests for Anchor CLI IDL and verification commands; Added integration tests for Solana SPL programs via Anchor; Added integration tests for \declare\_program!\ CPI scenarios; Added integration tests for custom coders; Added integration tests for the IDO pool program; Added integration tests for the Tic-Tac-Toe program; Added integration tests for the chat Solana program; Added integration tests for the declare\_program macro; Added integration tests for the realloc constraint group; Added lockup program implementation and test utilities; Added lockup program test suite and deployment scripts; Added migration scripts for test suite examples; Added misc test program to validate Anchor account constraints and data structures; Added native auction-house program tests; Added realloc program tests for various payer scenarios; Added shared test programs for misc, TypeScript, and zero-copy contexts; Added test coverage for IDL relations derivation; Added test coverage for remaining accounts functionality; Added test coverage for the Anchor SPL metadata feature; Added test for ambiguous discriminator compilation error; Added test for cross-program invocation in basic-3 tutorial; Added test for declared program ID validation; Added test harness for CPI event emission; Added test harness for SPL Associated Token Account program; Added test harness for Solana Token Extensions; Added test harness for SystemAccount type; Added test harness for \declare\_program!\ macro edge cases; Added test harness for custom error propagation and require macros; Added test harness for the Cashiers Check program; Added test harness programs for Solana program dependency validation; Added test harnesses for native system and SPL token programs; Added test program for Anchor optional accounts; Added test program for composite account structures; Added test program for float data types; Added test program for init\_if\_needed account initialization; Added test program for multiple test suites; Added test program for optional account constraints and PDA initialization; Added test program for relations derivation and address constraints; Added test program for remaining accounts handling; Added test program for zeroed discriminators; Added test programs for CLI IDL command validation; Added test programs for Pyth, sysvars, and TypeScript integration; Added test programs to verify safety checks for unchecked accounts; Added test suite for declare-id program validation; Added test suite for misc Anchor program; Added test suite for misc Anchor programs and CI configuration; Added test suite for multiple error definitions; Added test suite for multiple scripts support; Added test suite for selective test execution; Added test suite for the \declare\_program!\ macro; Added test suite for the registry staking program; Added test suite for token extensions program; Added tests for AccountLoader buffer truncation and legacy migration; Added tests for Anchor error handling and IDL validation; Added tests for Anchor program event handling and CPI events; Added tests for BPF upgradeable state program constraints; Added tests for BPF upgradeable state program validation; Added tests for CPI return value handling; Added tests for CPI return value handling and security fixes; Added tests for Escrow program token program compatibility; Added tests for IDL attribute parsing, qualified builtin handling, and program argument validation; Added tests for IDL documentation, case conversion, and workspace program access; Added tests for InterfaceAccount account substitution fix; Added tests for InterfaceAccount account substitution validation; Added tests for LazyAccount usage and behavior; Added tests for automatic SOL and SPL token account generation in test validators; Added tests for basic-1 tutorial program; Added tests for custom discriminator validation and error handling; Added tests for custom discriminators on instructions, accounts, and events; Added tests for custom program validation logic; Added tests for debugger symbol resolution; Added tests for duplicate mutable account constraints; Added tests for instruction argument count and type validation; Added tests for instruction argument validation; Added tests for legacy IDL CLI commands; Added tests for multiple test suites with separate local validators; Added tests for optional account handling in Anchor programs; Added tests for overflow-checks enforcement and arithmetic panics; Added tests for safety checks on unchecked accounts; Added tests for solana-program dependency conflict detection; Added tests for system account initialization and validation; Added tests for sysvar account validation; Added tests for the Lamports trait and overflow error handling; Added tests for the LazyAccount program; Added tests for the Tic-Tac-Toe program; Added tests for the anchor account CLI subcommand; Added tests for validator-clone functionality; Added tests for validator-clone program initialization; Added tests for zero-copy account creation and updates; Added token-proxy program example for testing Anchor SPL interactions; Added zero-CPI test program to validate cross-program invocation with AccountLoader; Added zero-copy account test program; Initial test suite for the IDO pool program; Native auction-house test suite with Anchor integration.

Dependencies

Anchor framework upgraded to version 1.2.0 with Solana 3.x toolchain support

The Anchor framework and its associated CLI, language crates, and TypeScript packages have been updated to version 1.2.0. This release upgrades the underlying Solana toolchain dependencies to version 3.x (e.g., \solana-pubkey 3.0.0\, \solana-hash 3.1.0\) and updates the Borsh serialization library to 1.5.7. The Rust edition for the CLI macros has been bumped to 2024, and the minimum supported Rust version (MSRV) for \anchor-lang\ is now 1.89. Additionally, the documentation site has been migrated to Astro v6 with React 19, and the AVM (Anchor Version Manager) now uses \reqwest\ 0.13.4 to align with Solana crate requirements.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 63 → 62 (-1.6)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 76 → 77 (+0.1)
  • Architecture 80 → 78 (-1.8)
  • Maturity 57 → 59 (+2.2)
  • Readiness 64 → 58 (-5.9)
  • Security 74 → 75 (+1.0)
  • Accessibility 68 → 66 (-2.1)
  • Performance 70 (new)

Resolved (122)

  • Critical CVE: [CVE redacted] (ts/yarn.lock)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 3) (lang/syn/src/parser/accounts/mod.rs)
  • Duplicated block (13 lines × 2) (lang/syn/src/codegen/accounts/try_accounts.rs)
  • Duplicated block (16 lines × 2) (lang/attribute/program/src/declare_program/mods/cpi.rs)
  • Duplicated block (19 lines × 2) (lang/syn/src/codegen/accounts/__client_accounts.rs)
  • Duplicated block (21 lines × 2) (cli/src/keygen.rs)
  • Duplicated block (9 lines × 2) (avm/src/platform_tools.rs)
  • Duplicated block (9 lines × 2) (lang/syn/src/codegen/accounts/constraints.rs)
  • FileTooLong: src/platform_tools.rs (avm/src/platform_tools.rs)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • High CVE: [CVE redacted] (ts/yarn.lock)
  • …and 102 more

New (73)

  • Duplicate method name rpc() with different return types (RpcClient vs AsyncRpcClient) on the same type Program. This is a signature collision or implies overloading which is not standard in Rust without distinct names. It creates confusion about which client to use.
  • Duplicated block (10 lines × 3) (lang/syn/src/parser/accounts/mod.rs)
  • Duplicated block (14–15 lines × 2) (lang/syn/src/codegen/accounts/try_accounts.rs)
  • Duplicated block (16 lines × 2) (cli/src/keygen.rs)
  • Duplicated block (16 lines × 2) (lang/attribute/program/src/declare_program/mods/cpi.rs)
  • Duplicated block (19 lines × 2) (avm/src/lib.rs)
  • Duplicated block (22 lines × 2) (lang/syn/src/codegen/accounts/__client_accounts.rs)
  • Duplicated block (9 lines × 2) (lang/syn/src/codegen/accounts/constraints.rs)
  • Excessive method proliferation for transaction sending. There are 4 distinct methods for sending transactions that differ only by versioning and spinner/config options. This violates the principle of least surprise and makes the API verbose.
  • FileTooLong: src/main.rs (avm/src/main.rs)
  • FunctionTooLong: anchor_cli::run_test_suite (cli/src/lib.rs)
  • High CVE: [GHSA redacted] (ts/yarn.lock)
  • High CVE: [GHSA redacted] (ts/yarn.lock)
  • High CVE: [GHSA redacted] (ts/yarn.lock)
  • High CVE: [GHSA redacted] (ts/yarn.lock)
  • High vulnerability: [GHSA redacted] (docs-v2/bun.lock)
  • Hotspot: lang/syn/src/codegen/accounts/__cpi_client_accounts.rs (lang/syn/src/codegen/accounts/__cpi_client_accounts.rs)
  • Inconsistent handling of wallet/payer. Config.wallet_kp() returns a keypair, while Client and RequestBuilder accept a generic C (likely a signer trait). This forces users to convert between keypairs and signers manually in some places but not others.
  • Inconsistent naming and signature for discovery operations. Config uses discover with an override object, Manifest has two variants (discover and discover_from_path), and TestConfig uses discover with explicit path arguments. The intent (locating configuration/test files) is the same, but the API surface is fragmented.
  • Inconsistent return types and naming for program identity retrieval. pubkey() returns a Pubkey (likely), while keypair() and keypair_file() return Result (likely containing a Keypair or path). This forces callers to use different logic to get the program's address depending on whether they have a keypair or just need the ID.
  • …and 53 more

Changes since last survey

  • 33 commits — 17 feature/other, 16 fixes

By area

  • (root) — 5 commits
  • docs-v2/src — 5 commits
  • .github/workflows — 4 commits
  • cli/src — 4 commits
  • lang/syn — 3 commits
  • avm/src — 2 commits
  • ts/packages — 2 commits
  • avm/anchor-solana-map.toml — 1 commit
  • avm/install — 1 commit
  • idl/src — 1 commit
  • lang/attribute — 1 commit
  • lang/src — 1 commit
  • lang/tests — 1 commit
  • tests/idl — 1 commit
  • tests/spl — 1 commit

Notable commits

  • fix: Fix path hygiene for composite fields in #[derive(Accounts)] (#4668)
  • fix: Fix/init if needed mint extensions (#4845)
  • fix: fix(avm): avoid copying AVM onto itself (#5064)
  • fix: fix(avm): configure PATH from installer (#5065)
  • fix: fix(avm): map Anchor 1.2 to Solana 4.1.2 (#5034)
  • fix: fix(ci): temporarily use legacy validator for validator-clone (#5044)
  • fix: fix(client): Don't report failed transactions in events listener (#4884)
  • fix: fix(lang): Store CPI return data in Vec (#4931)
  • fix: fix(lang): emit 'info lifetime on CPI client accounts struct with no fields (#4737)
  • fix: fix(lang): support safe borsh attrs in IDL build (#4623)
  • fix: fix(lang/syn): Fix macro hygiene to avoid shadowing between user code and macro generated variables (#5105)
  • fix: fix(ts): anchor.BN undefined in ESM — guard CJS globals in index.ts (#4525)
  • fix: fix(ts): reject invalid hex strings (#4807)
  • fix: fix: Followup to security.json metadata issues (#5052)
  • fix: fix: Update AVM version mappings for v3 compatability (#5055)
  • fix: fix: report safety check field locations accurately (#5120)
  • change: Add NO_DNA support to Anchor CLI (#4773)
  • change: Pass v3 arch to build-sbf and update platform-tools to v1.57 (#4684)
  • change: Resolve and install project toolchains in AVM (#4824)
  • change: ci: cancel superseded pull request workflow runs (#5041)
  • …and 13 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

otter-sec/anchor was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bce1622349d2303483e990548f424c79e510b5f1 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.