Smart-contract libraries
Anchor
A Solana program framework. The coral-xyz repository URL now resolves elsewhere.
Amber — conditions, and a legal review before you copy it in
- SPDX or status
- Apache-2.0
- Confidence
- medium
- Maintainer
- Repository now under otter-sec; verify before use
- Runtime
- Solana programs
- Repository
- otter-sec/anchor
On 2026-10-01 the GitHub API for coral-xyz/anchor resolved to otter-sec/anchor and reported Apache-2.0. Confirm that this is the project you mean before you depend on it. Blockchain Lab has not audited this repository. A licence check is not a vulnerability scan, a dependency review, or a security audit.
Keep the Apache notice, and confirm maintainer continuity.
Reuse status
Research available. Review required.
Copyleft, mixed terms, a dated dual licence, or a repository whose maintainer record is not settled. Legal review would be required before any copy. The scan gates are also unmet.
- Source class
- S3 conditional
- Commit
- Not pinned
- Source-derived demo
- Held
Available
- E0: Metadata
- E1: Research report
- E2: Citation bundle
- E3: Pattern blueprint
- E4: Test plan
- E5: Original scaffold
Not available
- E6: Source-derived demo pack — held
- E7: Full source bundle — held
- E8: Dataset export — held
- E9: Model-training pack — held
- E10: Production candidate pack — held
Anchor is conditional. Copyleft, mixed terms, or a maintainer caveat still needs a legal reading, and the scan gates are unmet. Non-commercial or demo use does not remove the licence duty. When in doubt, link — do not copy.
Use
- A Solana program prototype after you confirm the maintainer you intend
Do not use for
- An unreviewed dependency
- A token launch
Risks
- A redirected repository is a supply-chain event until a human confirms it.
- Account and signer bugs on Solana are not EVM bugs.
Reviews required
- Maintainer confirmation
- Security review before value
No source code is reproduced on this page. No commit SHA is published, because this release did not pin one.
