Releases: OpenZeppelin/openzeppelin-contracts
Releases · OpenZeppelin/openzeppelin-contracts
v5.2.0-rc.0
Changes by category
General
- Update some pragma directives to ensure that all file requirements match that of the files they import. (#5273)
Account
ERC4337Utils: Add a reusable library to manipulate user operations and interact with ERC-4337 contracts (#5274)ERC7579Utils: Add a reusable library to interact with ERC-7579 modular accounts (#5274)
Governance
GovernorCountingOverridable: Add a governor counting module that enables token holders to override the vote of their delegate. (#5192)VotesExtended: Create an extension ofVoteswhich checkpoints balances and delegates. (#5192)
Proxy
Clones: AddcloneWithImmutableArgsandcloneDeterministicWithImmutableArgsvariants that create clones with per-instance immutable arguments. The immutable arguments can be retrieved usingfetchCloneArgs. The correspondingpredictDeterministicWithImmutableArgsfunction is also included. (#5109)
Tokens
ERC1363Utils: Add helper similar to the existingERC721UtilsandERC1155Utils(#5133)
Utils
Bytes: Add a library of common operation that operate onbytesobjects. (#5252)CAIP2andCAIP10: Add libraries for formatting and parsing CAIP-2 and CAIP-10 identifiers. (#5252)NoncesKeyed: Add a variant ofNoncesthat implements the ERC-4337 entrypoint nonce system. (#5272)Packing: Add variants for packingbytes10andbytes22(#5274)Strings: AddparseUint,parseInt,parseHexUintandparseAddressto parse strings into numbers and addresses. Also provide variants of these functions that parse substrings, andtryXxxvariants that do not revert on invalid input. (#5166)
v5.1.0
Breaking changes
ERC1967Utils: Removed duplicate declaration of theUpgraded,AdminChangedandBeaconUpgradedevents. These events are still available through theIERC1967interface located under thecontracts/interfaces/directory. Minimum pragma version is now 0.8.21.Governor,GovernorCountingSimple: The_countVotevirtual function now returns anuint256with the total votes casted. This change allows for more flexibility for partial and fractional voting. Upgrading users may get a compilation error that can be fixed by adding a return statement to the_countVotefunction.
Custom error changes
This version comes with changes to the custom error identifiers. Contracts previously depending on the following errors should be replaced accordingly:
- Replace
Address.FailedInnerCallwithErrors.FailedCall - Replace
Address.AddressInsufficientBalancewithErrors.InsufficientBalance - Replace
Clones.Create2InsufficientBalancewithErrors.InsufficientBalance - Replace
Clones.ERC1167FailedCreateClonewithErrors.FailedDeployment - Replace
Clones.Create2FailedDeploymentwithErrors.FailedDeployment SafeERC20: ReplaceAddress.AddressEmptyCodewithSafeERC20FailedOperationif there is no code at the token's address.SafeERC20: Replace genericError(string)withSafeERC20FailedOperationif the returned data can't be decoded asbool.SafeERC20: Replace genericSafeERC20FailedOperationwith the revert message from the contract call if it fails.
Changes by category
General
AccessManager,VestingWallet,TimelockControllerandERC2771Forwarder: Added a publicinitializerfunction in their corresponding upgradeable variants. (#5008)
Access
AccessControlEnumerable: Add agetRoleMembersmethod to return all accounts that haverole. (#4546)AccessManager: Allow theonlyAuthorizedmodifier to restrict functions added to the manager. (#5014)
Finance
VestingWalletCliff: Add an extension of theVestingWalletcontract with an added cliff. (#4870)
Governance
GovernorCountingFractional: Add a governor counting module that allows distributing voting power amongst 3 options (For, Against, Abstain). (#5045)Votes: Set_moveDelegateVotesvisibility to internal instead of private. (#5007)
Proxy
Clones: Add version ofcloneandcloneDeterministicthat support sending value at creation. (#4936)TransparentUpgradeableProxy: Make internal_proxyAdmin()getter haveviewvisibility. (#4688)ProxyAdmin: Fixed documentation forUPGRADE_INTERFACE_VERSIONgetter. (#5031)
Tokens
ERC1363: Add implementation of the token payable standard allowing execution of contract code after transfers and approvals. (#4631)ERC20TemporaryApproval: Add an ERC-20 extension that implements temporary approval using transient storage, based on ERC7674 (draft). (#5071)SafeERC20: Add "relaxed" function for interacting with ERC-1363 functions in a way that is compatible with EOAs. (#4631)SafeERC20: Document risks ofsafeIncreaseAllowanceandsafeDecreaseAllowancewhen associated with ERC-7674. (#5262)ERC721UtilsandERC1155Utils: Add reusable libraries with functions to perform acceptance checks onIERC721ReceiverandIERC1155Receiverimplementers. (#4845)ERC1363Utils: Add helper similar to the existing ERC721Utils and ERC1155Utils. (#5133)
Utils
Arrays: add asortfunctions foraddress[],bytes32[]anduint256[]memory arrays. (#4846)Arrays: add new functionslowerBound,upperBound,lowerBoundMemoryandupperBoundMemoryfor lookups in sorted arrays with potential duplicates. (#4842)Arrays: deprecatefindUpperBoundin favor of the newlowerBound. (#4842)Base64: AddencodeURLfollowing section 5 of RFC4648 for URL encoding (#4822)Comparator: A library of comparator functions, useful for customizing the behavior of the Heap structure. (#5084)Create2: Bubbles up returndata from a deployed contract that reverted during construction. (#5052)Create2,Clones: MaskcomputeAddressandcloneDeterministicoutputs to produce a clean value for anaddresstype (i.e. only use 20 bytes) (#4941)Errors: New library of common custom errors. (#4936)Hashes: A library with commonly used hash functions. (#3617)Packing: Added a new utility for packing, extracting and replacing bytesXX values. (#4992)Panic: Add a library for reverting with panic codes. (#3298)ReentrancyGuardTransient: Added a variant ofReentrancyGuardthat uses transient storage. (#4988)Strings: Added a utility function for converting an address to checksummed string. (#5067)SlotDerivation: Add a library of methods for derivating common storage slots. (#4975)TransientSlot: Add primitives for operating on the transient storage space using a typed-slot representation. (#4980)
Cryptography
SignatureChecker: refactorisValidSignatureNowto avoid validating ECDSA signatures if there is code deployed at the signer's address. (#4951)MerkleProof: Add variations ofverify,processProof,multiProofVerifyandprocessMultiProof(and equivalent calldata version) with support for custom hashing functions. (#4887)P256: Library for verification and public key recovery of P256 (aka secp256r1) signatures. (#4881)RSA: Library to verify signatures according to RFC 8017 Signature Verification Operation (#4952)
Math
Math: add aninvModfunction to get the modular multiplicative inverse of a number in Z/nZ. (#4839)Math: AddmodExpfunction that exposes theEIP-198precompile. Includesuint256andbytes memoryversions. (#3298)Math: Custom errors replaced with native panic codes. (#3298)Math,SignedMath: Add a branchlessternaryfunction that computescond ? a : bin constant gas cost. (#4976)SafeCast: AddtoUint(bool)for operating onboolvalues asuint256. (#4878)
Structures
CircularBuffer: Add a data structure that stores the lastNvalues pushed to it. (#4913)DoubleEndedQueue: Custom errors replaced with native panic codes. (#4872)EnumerableMap: addUintToBytes32Map,AddressToAddressMap,AddressToBytes32MapandBytes32ToAddressMap. (#4843)Heap: A data structure that implements a heap-based priority queue. (#5084)MerkleTree: A data structure that allows inserting elements into a merkle tree and updating its root hash. (#3617)
v5.1.0-rc.0
Breaking changes
ERC1967Utils: Removed duplicate declaration of theUpgraded,AdminChangedandBeaconUpgradedevents. These events are still available through theIERC1967interface located under thecontracts/interfaces/directory. Minimum pragma version is now 0.8.21.Governor,GovernorCountingSimple: The_countVotesvirtual function now returns anuint256with the total votes casted. This change allows for more flexibility for partial and fractional voting. Upgrading users may get a compilation error that can be fixed by adding a return statement to the_countVotesfunction.
Custom error changes
This version comes with changes to the custom error identifiers. Contracts previously depending on the following errors should be replaced accordingly:
- Replace
Address.FailedInnerCallwithErrors.FailedCall - Replace
Address.AddressInsufficientBalancewithErrors.InsufficientBalance - Replace
Clones.Create2InsufficientBalancewithErrors.InsufficientBalance - Replace
Clones.ERC1167FailedCreateClonewithErrors.FailedDeployment - Replace
Clones.Create2FailedDeploymentwithErrors.FailedDeployment SafeERC20: ReplaceAddress.AddressEmptyCodewithSafeERC20FailedOperationif there is no code at the token's address.SafeERC20: Replace genericError(string)withSafeERC20FailedOperationif the returned data can't be decoded asbool.SafeERC20: Replace genericSafeERC20FailedOperationwith the revert message from the contract call if it fails.
Changes by category
General
AccessManager,VestingWallet,TimelockControllerandERC2771Forwarder: Added a publicinitializerfunction in their corresponding upgradeable variants. (#5008)
Access
AccessControlEnumerable: Add agetRoleMembersmethod to return all accounts that haverole. (#4546)AccessManager: Allow theonlyAuthorizedmodifier to restrict functions added to the manager. (#5014)
Finance
VestingWalletCliff: Add an extension of theVestingWalletcontract with an added cliff. (#4870)
Governance
GovernorCountingFractional: Add a governor counting module that allows distributing voting power amongst 3 options (For, Against, Abstain). (#5045)Votes: Set_moveDelegateVotesvisibility to internal instead of private. (#5007)
Proxy
Clones: Add version ofcloneandcloneDeterministicthat support sending value at creation. (#4936)TransparentUpgradeableProxy: Make internal_proxyAdmin()getter haveviewvisibility. (#4688)ProxyAdmin: Fixed documentation forUPGRADE_INTERFACE_VERSIONgetter. (#5031)
Tokens
ERC1363: Add implementation of the token payable standard allowing execution of contract code after transfers and approvals. (#4631)ERC20TemporaryApproval: Add an ERC-20 extension that implements temporary approval using transient storage, based on ERC7674 (draft). (#5071)SafeERC20: Add "relaxed" function for interacting with ERC-1363 functions in a way that is compatible with EOAs. (#4631)ERC721UtilsandERC1155Utils: Add reusable libraries with functions to perform acceptance checks onIERC721ReceiverandIERC1155Receiverimplementers. (#4845)ERC1363Utils: Add helper similar to the existing ERC721Utils and ERC1155Utils. (#5133)
Utils
Arrays: add asortfunctions foraddress[],bytes32[]anduint256[]memory arrays. (#4846)Arrays: add new functionslowerBound,upperBound,lowerBoundMemoryandupperBoundMemoryfor lookups in sorted arrays with potential duplicates. (#4842)Arrays: deprecatefindUpperBoundin favor of the newlowerBound. (#4842)Base64: AddencodeURLfollowing section 5 of RFC4648 for URL encoding (#4822)Comparator: A library of comparator functions, useful for customizing the behavior of the Heap structure. (#5084)Create2: Bubbles up returndata from a deployed contract that reverted during construction. (#5052)Create2,Clones: MaskcomputeAddressandcloneDeterministicoutputs to produce a clean value for anaddresstype (i.e. only use 20 bytes) (#4941)Errors: New library of common custom errors. (#4936)Hashes: A library with commonly used hash functions. (#3617)Packing: Added a new utility for packing, extracting and replacing bytesXX values. (#4992)Panic: Add a library for reverting with panic codes. (#3298)ReentrancyGuardTransient: Added a variant ofReentrancyGuardthat uses transient storage. (#4988)Strings: Added a utility function for converting an address to checksummed string. (#5067)SlotDerivation: Add a library of methods for derivating common storage slots. (#4975)StorageSlot: Add primitives for operating on the transient storage space using a typed-slot representation. (#4980)
Cryptography
SignatureChecker: refactorisValidSignatureNowto avoid validating ECDSA signatures if there is code deployed at the signer's address. (#4951)MerkleProof: Add variations ofverify,processProof,multiProofVerifyandprocessMultiProof(and equivalent calldata version) with support for custom hashing functions. (#4887)P256: Library for verification and public key recovery of P256 (aka secp256r1) signatures. (#4881)RSA: Library to verify signatures according to RFC 8017 Signature Verification Operation (#4952)
Math
Math: add aninvModfunction to get the modular multiplicative inverse of a number in Z/nZ. (#4839)Math: AddmodExpfunction that exposes theEIP-198precompile. Includesuint256andbytes memoryversions. (#3298)Math: Custom errors replaced with native panic codes. (#3298)Math,SignedMath: Add a branchlessternaryfunction that computescond ? a : bin constant gas cost. (#4976)SafeCast: AddtoUint(bool)for operating onboolvalues asuint256. (#4878)
Structures
CircularBuffer: Add a data structure that stores the lastNvalues pushed to it. (#4913)DoubleEndedQueue: Custom errors replaced with native panic codes. (#4872)EnumerableMap: addUintToBytes32Map,AddressToAddressMap,AddressToBytes32MapandBytes32ToAddressMap. (#4843)Heap: A data structure that implements a heap-based priority queue. (#5084)MerkleTree: A data structure that allows inserting elements into a merkle tree and updating its root hash. (#3617)
v5.0.2
v4.9.6
v4.9.5
Multicall: Make aware of non-canonical context (i.e.msg.senderis not_msgSender()), allowing compatibility withERC2771Context. Patch duplicatedAddress.functionDelegateCallin v4.9.4 (removed).
v5.0.1
v4.9.4
v5.0.0
Additions Summary
The following contracts and libraries were added:
AccessManager: A consolidated system for managing access control in complex systems.AccessManaged: A module for connecting a contract to an authority in charge of its access control.GovernorTimelockAccess: An adapter for time-locking governance proposals using anAccessManager.AuthorityUtils: A library of utilities for interacting with authority contracts.
GovernorStorage: A Governor module that stores proposal details in storage.ERC2771Forwarder: An ERC2771 forwarder for meta transactions.ERC1967Utils: A library with ERC1967 events, errors and getters.Nonces: An abstraction for managing account nonces.MessageHashUtils: A library for producing digests for ECDSA operations.Time: A library with helpers for manipulating time-related objects.
Removals Summary
The following contracts, libraries, and functions were removed:
Address.isContract(because of its ambiguous nature and potential for misuse)Checkpoints.HistoryCountersERC20SnapshotERC20VotesCompERC165Storage(in favor of inheritance based approach)ERC777ERC1820ImplementerGovernorVotesCompGovernorProposalThreshold(deprecated since 4.4)PaymentSplitterPullPaymentSafeMathSignedSafeMathTimersTokenTimelock(in favor ofVestingWallet)- All escrow contracts (
Escrow,ConditionalEscrowandRefundEscrow) - All cross-chain contracts, including
AccessControlCrossChainand all the vendored bridge interfaces - All presets in favor of OpenZeppelin Contracts Wizard
These removals were implemented in the following PRs: #3637, #3880, #3945, #4258, #4276, #4289
Changes by category
General
- Replaced revert strings and require statements with custom errors. (#4261)
- Bumped minimum compiler version required to 0.8.20 (#4288)
- Use of
abi.encodeCallin place ofabi.encodeWithSelectorandabi.encodeWithSignaturefor improved type-checking of parameters (#4293) - Replaced some uses of
abi.encodePackedwith clearer alternatives (e.g.bytes.concat,string.concat). (#4504) (#4296) - Overrides are now used internally for a number of functions that were previously hardcoded to their default implementation in certain locations:
ERC1155Supply.totalSupply,ERC721.ownerOf,ERC721.balanceOfandERC721.totalSupplyinERC721Enumerable,ERC20.totalSupplyinERC20FlashMint, andERC1967._getImplementationinERC1967Proxy. (#4299) - Removed the
overridespecifier from functions that only override a single interface function. (#4315) - Switched to using explicit Solidity import statements. Some previously available symbols may now have to be separately imported. (#4399)
Governor,Initializable, andUUPSUpgradeable: Use internal functions in modifiers to optimize bytecode size. (#4472)- Upgradeable contracts now use namespaced storage (EIP-7201). (#4534)
- Upgradeable contracts no longer transpile interfaces and libraries. (#4628)
Access
Ownable: Added aninitialOwnerparameter to the constructor, making the ownership initialization explicit. (#4267)Ownable: Prevent using address(0) as the initial owner. (#4531)AccessControl: Added a boolean return value to the internal_grantRoleand_revokeRolefunctions indicating whether the role was granted or revoked. (#4241)access: MovedAccessControlextensions to a dedicated directory. (#4359)AccessManager: Added a new contract for managing access control of complex systems in a consolidated location. (#4121)AccessManager,AccessManaged,GovernorTimelockAccess: Ensure that calldata shorter than 4 bytes is not padded to 4 bytes. (#4624)AccessManager: Use named return parameters in functions that return multiple values. (#4624)AccessManager: Makescheduleandexecutemore conservative when delay is 0. (#4644)
Finance
VestingWallet: Fixed revert during 1 second time window when duration is 0. (#4502)VestingWallet: UseOwnableinstead of an immutablebeneficiary. (#4508)
Governance
Governor: Optimized use of storage for proposal data (#4268)Governor: Added validation in ERC1155 and ERC721 receiver hooks to ensure Governor is the executor. (#4314)Governor: Refactored internals to implement common queuing logic in the core module of the Governor. Addedqueueand_queueOperationsfunctions that act at different levels. Modules that implement queuing via timelocks are expected to override_queueOperationsto implement the timelock-specific logic. Added_executeOperationsas the equivalent for execution. (#4360)Governor: Addedvoterandnonceparameters in signed ballots, to avoid forging signatures for random addresses, prevent signature replay, and allow invalidating signatures. Addvoteras a new parameter in thecastVoteBySigandcastVoteWithReasonAndParamsBySigfunctions. (#4378)Governor: Added support for casting votes with ERC-1271 signatures by using abytes memory signatureinstead ofr,sandvarguments in thecastVoteBySigandcastVoteWithReasonAndParamsBySigfunctions. (#4418)Governor: Added a mechanism to restrict the address of the proposer using a suffix in the description.GovernorStorage: Added a new governor extension that stores the proposal details in storage, with an interface that operates onproposalId, as well as proposal enumerability. This replaces the oldGovernorCompatibilityBravomodule. (#4360)GovernorTimelockAccess: Added a module to connect a governor with an instance ofAccessManager, allowing the governor to make calls that are delay-restricted by the manager using the normalqueueworkflow. (#4523)GovernorTimelockControl: Clean up timelock id on execution for gas refund. (#4118)GovernorTimelockControl: Added the Governor instance address as part of the TimelockController operationsaltto avoid operation id collisions between governors using the same TimelockController. (#4432)TimelockController: Changed the role architecture to useDEFAULT_ADMIN_ROLEas the admin for all roles, instead of the bespokeTIMELOCK_ADMIN_ROLEthat was used previously. This aligns with the general recommendation forAccessControland makes the addition of new roles easier. Accordingly, theadminparameter and timelock will now be grantedDEFAULT_ADMIN_ROLEinstead ofTIMELOCK_ADMIN_ROLE. (#3799)TimelockController: Added a state getter that returns anOperationStateenum. (#4358)Votes: Use Trace208 for checkpoints. This enables EIP-6372 clock support for keys but reduces the max supported voting power to uint208. (#4539)
Metatx
ERC2771Forwarder: Addeddeadlinefor expiring transactions, batching, and more secure handling ofmsg.value. (#4346)ERC2771Context: Return the forwarder address whenever themsg.dataof a call originating from a trusted forwarder is not long enough to contain the request signer address (i.e.msg.data.lengthis less than 20 bytes), as...
v5.0.0-rc.2
AccessManager: Makescheduleandexecutemore conservative when delay is 0.