Essential Libraries Best Practices
Solana repos accumulate dozens of crates and npm packages. These rules keep dependencies aligned with Agave 4.1.1, Anchor 0.32.1, and @solana/kit 7.0.0 while reducing supply-chain and audit risk.
Search across all documentation pages
Solana repos accumulate dozens of crates and npm packages. These rules keep dependencies aligned with Agave 4.1.1, Anchor 0.32.1, and @solana/kit 7.0.0 while reducing supply-chain and audit risk.
Cargo.toml, off-chain Rust, and TS client packages.cargo audit, npm audit, and verifiable build checks.solana-program, solana-sdk, and CLI 3.0.10 share one generation.anchor-lang and Anchor CLI at 0.32.1. Prevents IDL and macro drift.@solana/kit to 7.0.0 across monorepo packages. Avoid duplicate majors in one app.cargo tree for std-only deps in programs. Breaks or bloats sBPF builds.anchor-lang. Each feature can expand ELF size.@solana/web3.js v1. Use kit + Codama/gill.@solana-program/* ix crates with kit. Fewer hand-packed layouts.cargo deny or equivalent for unknown registries. Block typosquat crates.solana-verify workflow.If cargo tree depth hides program logic - consolidate internal helpers.
Yes across different program binaries; document per-program framework choice.
Committed Cargo.lock for binaries; programs follow workspace policy.
Either - enforce single package manager in CI for kit monorepos.
Yes - treat IDL as API contract alongside crate versions.
Avoid on mainnet programs unless risk accepted in writing.
Test CPI paths on devnet; MPL releases can change account metas.
Match rust-toolchain.toml across program and client workspaces.
Track licenses for MPL/MIT/Apache deps in distribution notices.
Maintain hotfix branch with minimal version bumps and fast audit review.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 19, 2026