From 6684cdc2f0d0d1dd81cad6249d75255a50837c48 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 1 Sep 2025 07:19:59 +0000 Subject: [PATCH 1/3] Initial plan From c6a805fe84d86e699b8b1a86c0477e18c5efd75b Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 1 Sep 2025 07:27:58 +0000 Subject: [PATCH 2/3] Enhance hardhat config: Convert to ES6, add multi-network etherscan support Co-authored-by: sonnyquinn24 <227287527+sonnyquinn24@users.noreply.github.com> --- hardhat.config.js | 65 ++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 62 insertions(+), 3 deletions(-) diff --git a/hardhat.config.js b/hardhat.config.js index 1497c04..e86856f 100644 --- a/hardhat.config.js +++ b/hardhat.config.js @@ -1,34 +1,93 @@ -require("@nomicfoundation/hardhat-toolbox"); +/** + * Environment Variables Required: + * + * Network RPC URLs: + * - SEPOLIA_RPC_URL: Sepolia testnet RPC URL + * - MAINNET_RPC_URL: Ethereum mainnet RPC URL + * - POLYGON_RPC_URL: Polygon mainnet RPC URL + * - ARBITRUM_RPC_URL: Arbitrum One mainnet RPC URL + * - BSC_RPC_URL: BSC mainnet RPC URL + * - INFURA_API_KEY: Infura project ID (fallback for RPC URLs) + * + * Account Configuration: + * - PRIVATE_KEY: Private key for deployment account + * + * Block Explorer API Keys: + * - ETHERSCAN_API_KEY: API key for Etherscan (Ethereum networks) + * - POLYGONSCAN_API_KEY: API key for PolygonScan + * - ARBISCAN_API_KEY: API key for Arbiscan (Arbitrum networks) + * - BSCSCAN_API_KEY: API key for BscScan + * + * Optional: + * - REPORT_GAS: Set to any value to enable gas reporting + */ + +import "@nomicfoundation/hardhat-toolbox"; /** @type import('hardhat/config').HardhatUserConfig */ const config = { solidity: "0.8.24", networks: { + // Local development network hardhat: {}, + + // Ethereum Sepolia testnet sepolia: { url: process.env.SEPOLIA_RPC_URL || `https://sepolia.infura.io/v3/${process.env.INFURA_API_KEY}`, accounts: process.env.PRIVATE_KEY ? [process.env.PRIVATE_KEY] : [], }, + + // Ethereum mainnet mainnet: { url: process.env.MAINNET_RPC_URL || `https://mainnet.infura.io/v3/${process.env.INFURA_API_KEY}`, accounts: process.env.PRIVATE_KEY ? [process.env.PRIVATE_KEY] : [], }, + + // Polygon mainnet polygon: { url: process.env.POLYGON_RPC_URL || `https://polygon-mainnet.infura.io/v3/${process.env.INFURA_API_KEY}`, accounts: process.env.PRIVATE_KEY ? [process.env.PRIVATE_KEY] : [], }, + + // Arbitrum One mainnet + arbitrum: { + url: process.env.ARBITRUM_RPC_URL || "https://arb1.arbitrum.io/rpc", + accounts: process.env.PRIVATE_KEY ? [process.env.PRIVATE_KEY] : [], + }, + + // BSC mainnet bsc: { url: process.env.BSC_RPC_URL || "https://bsc-dataseed1.binance.org", accounts: process.env.PRIVATE_KEY ? [process.env.PRIVATE_KEY] : [], }, }, + + // Gas usage reporting configuration gasReporter: { enabled: process.env.REPORT_GAS !== undefined, currency: "USD", }, + + // Block explorer verification configuration etherscan: { - apiKey: process.env.ETHERSCAN_API_KEY, + apiKey: { + // Ethereum networks (mainnet, sepolia, etc.) + mainnet: process.env.ETHERSCAN_API_KEY, + sepolia: process.env.ETHERSCAN_API_KEY, + + // Polygon networks + polygon: process.env.POLYGONSCAN_API_KEY, + polygonMumbai: process.env.POLYGONSCAN_API_KEY, + + // Arbitrum networks + arbitrumOne: process.env.ARBISCAN_API_KEY, + arbitrumSepolia: process.env.ARBISCAN_API_KEY, + + // BSC networks + bsc: process.env.BSCSCAN_API_KEY, + bscTestnet: process.env.BSCSCAN_API_KEY, + }, }, }; -module.exports = config; \ No newline at end of file +export default config; \ No newline at end of file From d5067fadb57a7b2591ef5c0dc0bc84ba606b9250 Mon Sep 17 00:00:00 2001 From: sonnyquinn24 <227287527+sonnyquinn24@users.noreply.github.com> Date: Fri, 5 Sep 2025 03:25:23 -0500 Subject: [PATCH 3/3] Add SARIF file upload step to APIsec workflow Added step to upload SARIF file after APIsec scan. --- .github/workflows/apisec-scan.yml | 75 ++----------------------------- 1 file changed, 4 insertions(+), 71 deletions(-) diff --git a/.github/workflows/apisec-scan.yml b/.github/workflows/apisec-scan.yml index f1bebe8..5237124 100644 --- a/.github/workflows/apisec-scan.yml +++ b/.github/workflows/apisec-scan.yml @@ -1,71 +1,4 @@ -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. - -# APIsec addresses the critical need to secure APIs before they reach production. -# APIsec provides the industry’s only automated and continuous API testing platform that uncovers security vulnerabilities and logic flaws in APIs. -# Clients rely on APIsec to evaluate every update and release, ensuring that no APIs go to production with vulnerabilities. - -# How to Get Started with APIsec.ai -# 1. Schedule a demo at https://www.apisec.ai/request-a-demo . -# -# 2. Register your account at https://cloud.apisec.ai/#/signup . -# -# 3. Register your API . See the video (https://www.youtube.com/watch?v=MK3Xo9Dbvac) to get up and running with APIsec quickly. -# -# 4. Get GitHub Actions scan attributes from APIsec Project -> Configurations -> Integrations -> CI-CD -> GitHub Actions -# -# apisec-run-scan -# -# This action triggers the on-demand scans for projects registered in APIsec. -# If your GitHub account allows code scanning alerts, you can then upload the sarif file generated by this action to show the scan findings. -# Else you can view the scan results from the project home page in APIsec Platform. -# The link to view the scan results is also displayed on the console on successful completion of action. - -# This is a starter workflow to help you get started with APIsec-Scan Actions - -name: APIsec - -# Controls when the workflow will run -on: - # Triggers the workflow on push or pull request events but only for the "main" branch - # Customize trigger events based on your DevSecOps processes. - push: - branches: [ "main" ] - pull_request: - branches: [ "main" ] - schedule: - - cron: '32 6 * * 0' - - # Allows you to run this workflow manually from the Actions tab - workflow_dispatch: - - -permissions: - contents: read - -jobs: - - Trigger_APIsec_scan: - permissions: - security-events: write # for github/codeql-action/upload-sarif to upload SARIF results - actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status - runs-on: ubuntu-latest - - steps: - - name: APIsec scan - uses: apisec-inc/apisec-run-scan@025432089674a28ba8fb55f8ab06c10215e772ea - with: - # The APIsec username with which the scans will be executed - apisec-username: ${{ secrets.apisec_username }} - # The Password of the APIsec user with which the scans will be executed - apisec-password: ${{ secrets.apisec_password}} - # The name of the project for security scan - apisec-project: "VAmPI" - # The name of the sarif format result file The file is written only if this property is provided. - sarif-result-file: "apisec-results.sarif" - - name: Import results - uses: github/codeql-action/upload-sarif@v3 - with: - sarif_file: ./apisec-results.sarif +- name: Upload SARIF file + uses: github/codeql-action/upload-sarif@ + with: + sarif_file: results.sarif