OpenZeppelinを使う理由
実績のあるコード
「OpenZeppelinを使う理由」はCoddyKit上の無料Web3 & DApp Development Fundamentalsレッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはWeb3 & DApp Development Fundamentals学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Web3 & DApp Development Fundamentalsコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
What Is OpenZeppelin
OpenZeppelin Contracts is a library of secure, reusable smart contract building blocks for Solidity.
- Implements common standards (ERC-20, ERC-721, ERC-1155).
- Provides access control, security, and utility modules.
- Is audited and widely used across production protocols.
Why Not Write It Yourself
Reimplementing token standards by hand is risky:
- Subtle bugs in arithmetic or approvals can drain funds.
- Standards have edge cases easy to miss.
- Custom code is unaudited and untested by the community.
Reusing battle-tested code lets you focus on your unique logic.
Installing the Library
Add OpenZeppelin Contracts as a dependency:
npm install @openzeppelin/contractsIt installs into node_modules, and Hardhat resolves imports from there automatically.
npm install @openzeppelin/contractsImporting Contracts
Import the modules you need by their package path:
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
import "@openzeppelin/contracts/token/ERC20/ERC20.sol";The path mirrors the library's folder structure (token, access, security, utils).
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
import "@openzeppelin/contracts/token/ERC20/ERC20.sol";Inheriting a Standard
You build your contract by inheriting from a base. An ERC-20 token in just a few lines:
contract MyToken is ERC20 {
constructor() ERC20("MyToken", "MTK") {
_mint(msg.sender, 1000000 * 10 ** decimals());
}
}All transfer, approval, and balance logic is inherited.
contract MyToken is ERC20 {
constructor() ERC20("MyToken", "MTK") {
_mint(msg.sender, 1000000 * 10 ** decimals());
}
}Overriding Behavior
You can customize inherited functions by overriding them, while still calling the parent with super:
function transfer(address to, uint256 amount)
public override returns (bool) {
require(to != address(0), "No zero address");
return super.transfer(to, amount);
}function transfer(address to, uint256 amount)
public override returns (bool) {
require(to != address(0), "No zero address");
return super.transfer(to, amount);
}The Module Categories
OpenZeppelin is organized into areas:
- token/ — ERC-20, ERC-721, ERC-1155 implementations.
- access/ — Ownable, AccessControl.
- security/ — ReentrancyGuard, Pausable.
- utils/ — math, strings, cryptography helpers.
The Wizard
OpenZeppelin offers a web-based Contracts Wizard that generates a starter contract from checkboxes — pick the standard, toggle mintable, pausable, or access control, and copy the code.
It is a great way to scaffold a correct base before customizing.
Audited and Versioned
OpenZeppelin releases are audited and follow semantic versioning. Pin a version in package.json so a major upgrade does not silently change behavior:
"@openzeppelin/contracts": "^5.0.0"Read the migration guide before bumping major versions.
"@openzeppelin/contracts": "^5.0.0"Not a Silver Bullet
OpenZeppelin secures the building blocks, but your logic still needs review:
- Inheriting securely written code does not make custom functions safe.
- Misconfiguration (wrong roles, missing checks) can still create holes.
Always test and, for high-value contracts, get an audit.
Contracts vs Contracts-Upgradeable
OpenZeppelin ships two packages:
- @openzeppelin/contracts — standard contracts with normal constructors.
- @openzeppelin/contracts-upgradeable — the same modules adapted for proxies, using initializers.
Pick the upgradeable variant only if you actually deploy behind a proxy.
Quick Check
Test your understanding of why teams use OpenZeppelin.
Recap
You learned why OpenZeppelin is the standard library for Solidity.
- It offers audited, reusable implementations of token standards and security modules.
- Install with npm and inherit base contracts like
ERC20. - Override functions with
superto customize behavior. - Modules cover token, access, security, and utils; the Wizard scaffolds code.
- Pin versions and still test your own logic — it is not a silver bullet.
よくある質問
「OpenZeppelinを使う理由」レッスンは無料ですか?
はい。「OpenZeppelinを使う理由」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Web3 & DApp Development Fundamentalsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Web3 & DApp Development Fundamentalsコースには全4レッスンが含まれています。
「OpenZeppelinを使う理由」で何を学びますか?
実績のあるコード ブラウザで直接実行するハンズオンコードでWeb3 & DApp Development Fundamentalsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Web3 & DApp Development Fundamentalsを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのWeb3 & DApp Development Fundamentalsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。
「OpenZeppelinを使う理由」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このWeb3 & DApp Development Fundamentalsレッスンでコードを書いて実行できますか?
はい。すべてのWeb3 & DApp Development Fundamentalsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- OpenZeppelinを使う理由
- アクセス制御
- トークン拡張
- アップグレード可能なコントラクト