Getting started
Quickstart
One command against a real contract on testnet. It needs Node 24, and nothing else — no key, no account, and no install step.
Run it
The contract id below is guinea-pig A, one of three contracts this project runs against on
testnet. It is a real deployment, so the numbers you get back will differ from the ones here —
they move every five seconds.
npx @evergreen-stellar/cli@0.1.1 scan CANZNTAW7DYMCZ6EAY5BP672H4AL2O2HVRBP4O4HRUEZRATHQRRLXL6L
npx fetches the package and runs it; there is no global install to
undo afterwards. Node 24 is required — the package declares it, and npm will refuse on older
runtimes rather than fail strangely later.
What comes back
A scan of the same contract, captured on 2026-09-12 and committed under
docs/evidence/. Read the last two lines first: they are the ones
that say what the scan could not establish.
Coverage: known keys only — contract storage has NOT been fully enumerated.
CANZNTAW7DYMCZ6EAY5BP672H4AL2O2HVRBP4O4HRUEZRATHQRRLXL6L: 0 explicit data key(s)
No data keys were supplied, so any further entries are unread. A clean result covers only what was asked for, never the whole contract.
HEALTHY instance AAAABgAAAA…
contracts: CANZNTAW7DYMCZ6EAY5BP672H4AL2O2HVRBP4O4HRUEZRATHQRRLXL6L
remaining: 1,400,453 ledgers — live
ends at: ledger 6,025,589
approx: 2026-12-01T18:58:52.518Z (estimate — ledgers are the truth)
observed: ledger 4,625,136
health: HEALTHY — Above threshold.
HEALTHY code AAAAB8flXw…
contracts: CANZNTAW7DYMCZ6EAY5BP672H4AL2O2HVRBP4O4HRUEZRATHQRRLXL6L
⚠ sharing: code entries are shared by every contract built from the same Wasm.
This scan saw 1. Whether others depend on this entry cannot be
determined from a single-contract scan — pass them together.
remaining: 665,693 ledgers — live
ends at: ledger 5,290,829
approx: 2026-10-20T06:28:52.518Z (estimate — ledgers are the truth)
observed: ledger 4,625,136
health: HEALTHY — Above threshold.
! sharing-undetermined: Code entries are shared by every contract built from the same Wasm. This scan saw 1. Whether others depend on this entry cannot be determined from a single-contract scan — pass them together to see the real blast radius.
contracts: CANZNTAW7DYMCZ6EAY5BP672H4AL2O2HVRBP4O4HRUEZRATHQRRLXL6L
! coverage-limited: No data keys were supplied, so any further entries are unread. A clean result covers only what was asked for, never the whole contract.
contracts: CANZNTAW7DYMCZ6EAY5BP672H4AL2O2HVRBP4O4HRUEZRATHQRRLXL6L
Worst entry health: HEALTHY (threshold 17,280 ledgers)
Scan is PARTIAL — 2 issue(s). Absence is not health.
Captured on 2026-09-12 and committed at docs/evidence/2026-09-12-w2-review/scan-a-human.txt. Its ledger numbers are from that day; the dashboard reads the chain now.
Reading it
| Line | What it is telling you |
| Coverage | Which entries were read, and that storage was not enumerated. A clean result covers only what was asked for. |
| remaining | Ledgers left on that entry. Ledgers are the truth; the date beside them is an estimate at five seconds each. |
| ⚠ sharing | The code entry is shared by every contract built from the same Wasm. One scan saw one consumer and says so, rather than concluding it is unshared. |
| Scan is PARTIAL | The scan finished and is telling you its own limits. Absence is not health. |
Then what
Pass several contracts to one scan and the sharing question resolves as far as it can —
scan A B C reports the code entry’s consumers as a lower bound.
To see what keeping an entry alive would cost, add --cost. To
change anything, extend is a separate command with its own guards.
Next
How state archival works
Four kinds of ledger entry, two ways of ending, and the one that cannot be undone.