> For the complete documentation index, see [llms.txt](https://gotts.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gotts.gitbook.io/docs/gotts-vaults/vault/12-dependencies.md).

# Dependencies

> **Part of**: [Vault PRD](/docs/gotts-vaults/vault.md) | **Last Updated**: 2026-02-20

***

## Dependencies and Tech Stack

### Solidity Dependencies

| Package                   | Version | Purpose                                                                        | Used By              |
| ------------------------- | ------- | ------------------------------------------------------------------------------ | -------------------- |
| `@openzeppelin/contracts` | ^5.0.0  | ERC-4626, ERC-20, ReentrancyGuard, Ownable, AccessControl, TimelockController  | vault, agent-proxy   |
| `v4-core`                 | latest  | IPoolManager, PoolKey, PoolId, BalanceDelta, Hooks                             | vault                |
| `v4-periphery`            | latest  | BaseHook, HookMiner, StateLibrary, ERC4626Hook reference                       | vault                |
| `forge-std`               | latest  | Testing utilities, Script, console.log                                         | vault, agent-proxy   |
| `@gnosis.pm/zodiac`       | latest  | Delay Modifier, Roles Modifier -- Safe integration path for time-delayed proxy | agent-proxy (Path 1) |
| `@rhinestone/module-sdk`  | latest  | ERC-7579 module utilities, ColdStorage Hook                                    | agent-proxy (Path 2) |

### External Contract Dependencies (Read/Call)

| Contract                         | Repository                                     | Key Interface                                                                                                                                                                                                                                                                                             |
| -------------------------------- | ---------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ERC-8004 IdentityRegistry        | ERC-8004 spec                                  | `register()`, `getIdentity()`, `ownerOf()`                                                                                                                                                                                                                                                                |
| ERC-8004 ReputationRegistry      | ERC-8004 spec                                  | `submitFeedback()`, `getSummary()`                                                                                                                                                                                                                                                                        |
| ContinuousClearingAuction        | github.com/Uniswap/continuous-clearing-auction | `submitBid()`, `exitBid()`, `exitPartiallyFilledBid()`, `claimTokens()`, `checkpoint()`, `isGraduated()`                                                                                                                                                                                                  |
| ContinuousClearingAuctionFactory | Same repo                                      | `initializeDistribution()`                                                                                                                                                                                                                                                                                |
| LiquidityLauncher                | github.com/Uniswap/liquidity-launcher          | `createToken()`, `distributeToken()`                                                                                                                                                                                                                                                                      |
| FullRangeLBPStrategy             | Same repo                                      | `migrate()`                                                                                                                                                                                                                                                                                               |
| AdvancedLBPStrategy              | Same repo                                      | `migrate()` with one-sided position support                                                                                                                                                                                                                                                               |
| Uniswap V4 PoolManager           | github.com/Uniswap/v4-core                     | `initialize()`, `swap()`, `modifyLiquidity()`                                                                                                                                                                                                                                                             |
| V4 PositionManager               | github.com/Uniswap/v4-periphery                | `mint()`, `burn()`, `modifyLiquidities()`                                                                                                                                                                                                                                                                 |
| Uniswap Trading API              | `trade-api.gateway.uniswap.org/v1`             | REST API: `/check_approval`, `/quote`, `/swap`, `/order`, `/lp/*`. Optional (requires `GOTTS_UNISWAP_API_KEY`). Provides optimized swap routing, LP management, UniswapX gasless execution, V3→V4 migration. Fallback: local SDK computation. No additional npm package needed — uses standard `fetch()`. |

### TypeScript Dependencies

| Package                         | Version | Purpose                                                                                                                                                                                                                                                                                                                                                                                              |
| ------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `@modelcontextprotocol/sdk`     | ^1.0.0  | MCP server framework for standalone vault server                                                                                                                                                                                                                                                                                                                                                     |
| `@uniswap/v4-sdk`               | ^1.24.0 | V4Planner, V4PositionManager, Pool, Position                                                                                                                                                                                                                                                                                                                                                         |
| `@uniswap/smart-order-router`   | latest  | AlphaRouter for optimal cross-pool routing                                                                                                                                                                                                                                                                                                                                                           |
| `@uniswap/sdk-core`             | ^7.9.0  | Token, CurrencyAmount, Percent, TradeType                                                                                                                                                                                                                                                                                                                                                            |
| `@uniswap/universal-router-sdk` | latest  | RoutePlanner, CommandType, PERMIT2\_ADDRESS                                                                                                                                                                                                                                                                                                                                                          |
| `@uniswap/v3-sdk`               | ^3.27.0 | nearestUsableTick, TickMath, encodeSqrtRatioX96                                                                                                                                                                                                                                                                                                                                                      |
| `@x402/express`                 | latest  | x402 payment middleware for strategy endpoints                                                                                                                                                                                                                                                                                                                                                       |
| `viem`                          | ^2.0.0  | On-chain interaction, account abstraction                                                                                                                                                                                                                                                                                                                                                            |
| `zod`                           | ^3.23.0 | Parameter validation for MCP tools                                                                                                                                                                                                                                                                                                                                                                   |
| `lru-cache`                     | ^11.0.0 | Standalone response caching with tiered TTLs                                                                                                                                                                                                                                                                                                                                                         |
| `@lancedb/lancedb`              | ^0.26.2 | Episodic memory store (DeFi Brain). Lance columnar format with hybrid BM25+vector search via RRF. Used for storing trade outcomes and per-operation reflections.                                                                                                                                                                                                                                     |
| `better-sqlite3`                | ^11.0.0 | Synchronous SQLite driver for semantic memory store (insights, confidence scores, decay metadata). Embedded, zero-config.                                                                                                                                                                                                                                                                            |
| `sqlite-vec`                    | ^0.1.7  | SQLite extension for vector similarity search (`vec0` virtual tables). Lightweight KNN for insight embeddings (<10K vectors).                                                                                                                                                                                                                                                                        |
| `@huggingface/transformers`     | ^3.8.1  | Local text embedding pipeline (Transformers.js). Currently runs `Xenova/all-MiniLM-L6-v2` (384-dim, \~23MB q8) in-process. Planned Tier 1 upgrade to `nomic-ai/nomic-embed-text-v1.5` (768-dim MRL, \~75MB q8) for Matryoshka adaptive-dimension retrieval (14x speedup). See [memory-architecture.md](/docs/prd-shared/memory-architecture.md) Part 1 §4 (embedder code), Part 2 §2 (MRL research). |
| `opossum`                       | ^8.0.0  | Production-ready circuit breaker for Node.js (Red Hat-supported, 70K+ weekly npm downloads). Wraps external calls (RPC, oracles, DEX routers) with configurable timeout, error threshold, reset, and fallback. See [memory-architecture.md](/docs/prd-shared/memory-architecture.md) Part 1 §10 (setup code), Part 2 §6 (research).                                                                  |
| `drizzle-orm`                   | ^0.45.1 | Type-safe ORM for SQLite semantic memory schema. Migrations, typed queries, zero runtime overhead.                                                                                                                                                                                                                                                                                                   |
| `drizzle-kit`                   | ^0.30.0 | Schema migration tooling for Drizzle ORM (dev dependency). Generates and runs SQLite migrations.                                                                                                                                                                                                                                                                                                     |

**Optional peer dependencies**:

* `@gotts.ai/safe` (workspace:\*) -- provides the full safety pipeline for production deployments. When not installed, the vault uses its own built-in safety checks.
* `@gotts.ai/agent-proxy` (workspace:\*) -- provides ProxyClient, MonitorBot, DelayEngine for time-delayed proxy integration. When not installed, the vault executes transactions directly without proxy routing.

### Debug UI Dependencies

| Package                 | Version | Purpose                                     |
| ----------------------- | ------- | ------------------------------------------- |
| `react`                 | ^19.0   | UI framework                                |
| `react-dom`             | ^19.0   | React DOM renderer                          |
| `vite`                  | ^6.0    | Dev server and production build             |
| `tailwindcss`           | ^4.0    | Utility-first CSS styling                   |
| `@tanstack/react-query` | ^5.0    | Data fetching, caching, auto-refresh        |
| `wagmi`                 | ^2.0    | Ethereum wallet hooks (Anvil connection)    |
| `recharts`              | ^2.0    | Charts for TVL, APY, position visualization |
| `react-router-dom`      | ^7.0    | Client-side routing between views           |

### Development Dependencies

| Package      | Version | Purpose                      |
| ------------ | ------- | ---------------------------- |
| `typescript` | ^5.7.0  | Type-safe development        |
| `vitest`     | ^3.0.0  | Unit and integration testing |
| `tsx`        | ^4.19.0 | TypeScript execution         |
| `tsup`       | ^8.4.0  | Build (ESM output, Node 20)  |

### Solidity Testing Dependencies

| Package                      | Version | Purpose                                                                                                                                                                            |
| ---------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `a16z/erc4626-tests`         | latest  | ERC-4626 property test suite — validates round-trip properties, preview accuracy, caller independence. MUST pass for all vault templates before mainnet deployment (Phase 5 gate). |
| `slither`                    | latest  | Static analysis — zero high/critical findings required for mainnet                                                                                                                 |
| `certora-prover` or `halmos` | latest  | Formal verification of total supply consistency, solvency invariants, access control, fee calculations                                                                             |

### Oracle Infrastructure (D-021)

Multi-oracle aggregation for vault NAV calculations, strategy monitoring, and liquidation triggers:

| Oracle                   | Role                                      | Coverage                                   | Integration                                                                   |
| ------------------------ | ----------------------------------------- | ------------------------------------------ | ----------------------------------------------------------------------------- |
| **RedStone** (primary)   | NAV calculations, exotic asset pricing    | 110+ chains including Base, $9B+ secured   | RedStone Atom (liquidation-aware), Dynamic PT Oracle for yield-bearing assets |
| **Pyth** (fallback)      | High-frequency trading strategies         | 450+ price feeds, sub-second updates       | Pull-based oracle, low latency                                                |
| **Chainlink** (fallback) | Blue-chip asset pricing (ETH, BTC, USDC)  | Industry standard, battle-tested           | Push-based feeds                                                              |
| **TWAP** (internal)      | NAV calculations, manipulation resistance | Computed from Uniswap V4 pool observations | 4-24 hour windows for NAV; spot pricing only for liquidation triggers         |

**Safety rules**:

* If primary (RedStone) and fallback (Pyth or Chainlink) prices diverge by >2%, automatically pause the affected strategy
* TWAP is used for all NAV calculations to prevent single-block manipulation
* Spot pricing is permitted only for liquidation triggers where speed matters
* RedStone Credora credit ratings (acquired September 2025) enable real-time risk assessment for novel strategy adapters

### Future/Planned Dependencies (TypeScript Only)

| Package      | Version | Tier   | Purpose                                                                                                                                                                                                                                                                            |
| ------------ | ------- | ------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `graphology` | ^0.25.0 | Tier 3 | In-memory graph library for HippoRAG knowledge graph with Personalized PageRank. Required for associative cross-episode retrieval. Pure JavaScript, zero native dependencies. See [memory-architecture.md](/docs/prd-shared/memory-architecture.md) Part 2 §2 (HippoRAG research). |

All current and planned dependencies are TypeScript/JavaScript npm packages. No Python sidecars, external language runtimes, or non-Node.js processes are required at any tier.

### Runtime Requirements

* **Node.js**: >= 20.0.0
* **Foundry**: For Solidity compilation, testing, and local testnet deployment
* **Anvil**: For local testnet (included with Foundry)
* **DeFi Brain memory system** (when `learning` profile active): +150-250MB RAM for current embedding model (`all-MiniLM-L6-v2`, \~23MB q8). After Tier 1 upgrade to `nomic-embed-text-v1.5`: \~75MB q8 model, \~300-400MB RAM at runtime. LanceDB and SQLite files grow with usage (\~1KB per episode, \~500B per insight).

***

## v1 Standards Scope

The full PRD references 20 ERC/EIP standards. For v1, only 10 are required. The remaining 10 can be added as expansion modules without blocking launch.

### Core v1 Standards (required for launch)

| Standard | Role                      | Why Required                              |
| -------- | ------------------------- | ----------------------------------------- |
| ERC-20   | Token interface           | Base asset + share token                  |
| ERC-721  | NFT interface             | ERC-8004 identity NFTs                    |
| ERC-4337 | Account abstraction       | Smart wallet + UserOps + paymaster        |
| ERC-4626 | Tokenized vault           | Core vault standard                       |
| ERC-8004 | Agent identity            | Protocol spine -- gates all participation |
| EIP-712  | Typed structured data     | Permit2 signatures                        |
| EIP-1559 | Gas pricing               | Transaction fee estimation                |
| EIP-7702 | EOA smart account upgrade | Migration path for existing EOAs          |
| ERC-7265 | Circuit breaker           | NAV circuit breaker interface             |
| ERC-7579 | Modular smart account     | Session keys + module system              |

### Deferred Standards (not required for v1)

| Standard | Role                            | Removal Tradeoff                                           | When to Add                         |
| -------- | ------------------------------- | ---------------------------------------------------------- | ----------------------------------- |
| ERC-6909 | Multi-token internal accounting | Lose gas efficiency on internal transfers; ERC-20 suffices | Track D (cross-vault ecosystem)     |
| ERC-7540 | Async deposits/withdrawals      | Already marked "Planned" -- no loss                        | Track A (CCA lifecycle)             |
| ERC-7677 | Paymaster capability            | Gasless txns work without this standard                    | When paymaster expands beyond Base  |
| ERC-7683 | Cross-chain intents             | Already deferred to Track E                                | Track E                             |
| ERC-7710 | Delegation registry             | Internal role system suffices                              | If cross-protocol delegation needed |
| ERC-7715 | Permission requests             | Minimal loss                                               | If wallet UX standardization needed |
| ERC-7802 | Superchain portability          | Base-only for v1                                           | When expanding to Superchain L2s    |

***

## Base L2 Risk Acknowledgments

Base is the primary deployment target with $4.63B TVL (46% of all L2 DeFi TVL), ultra-low gas (\~$0.001-$0.01/tx), and 9.3M monthly active traders. However, the following risks must be acknowledged and mitigated:

| Risk                          | Details                                                                                                                                                                                            | Mitigation                                                                                                                                                                                                       |
| ----------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Centralized sequencer**     | The Base sequencer is the sole block producer (Nakamoto coefficient = 1). This creates censorship and downtime risk. At least one block production stall has been observed in production.          | Time-delayed proxy ensures critical operations (cancel, pause) can be submitted via alternate sequencers or L1 escape hatch. Monitor sequencer health as critical alert.                                         |
| **7-day withdrawal delay**    | Optimistic fraud proofs require a week-long challenge window for L2→L1 bridging. Users moving vault assets to mainnet face this delay.                                                             | Document clearly in UX. ERC-7683 cross-chain intents (Track E) provide alternative faster exit paths via fillers.                                                                                                |
| **Flashblocks compatibility** | Flashblocks (200ms sub-blocks within 2-second blocks, live since July 2025) change event timing behavior. Some developers report app breakage when switching to Flashblocks-enabled RPC endpoints. | Require Flashblocks compatibility testing for all hook-based event handling before mainnet. Add to Phase 5 acceptance gate: "hook events process correctly with Flashblocks-enabled and standard RPC endpoints." |
| **MEV concentration**         | Over 50% of on-chain gas was consumed by MEV activity in Q1 2025. Vault rebalancing transactions are high-value MEV targets.                                                                       | Mitigated by TWAMM time-splitting (reduces MEV surface), am-AMM management auctions (competitive execution), and intent-based rebalance auctions (D-064).                                                        |
| **No governance token**       | Base has explored but not committed to token issuance. This limits on-chain governance options for the protocol on Base itself.                                                                    | Protocol governance is independent of Base governance. veVAULT module (D-050, Track G) provides protocol-level governance if needed.                                                                             |
