@aztec/node-lib
Shared code for Aztec Nodes and Prover Nodes.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dest/factories/l1_tx_utils.d.ts | AI (source-diff): TypeScript .d.ts files with complex generic type signatures routinely exceed 3000 chars; not obfuscation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 used for blob serialization in storage layer — standard data encoding, not payload hiding. | ai | |
| phantom-deps | phantom-dep:@aztec/blob-sink | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:@aztec/simulator | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:@aztec/epoch-cache | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:@aztec/merkle-tree | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:@aztec/prover-client | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a well-known implicit TypeScript runtime dependency; not directly imported but used transitively. Stable false positive for TypeScript monorepo packages. | ai | |
| phantom-deps | phantom-dep:@aztec/telemetry-client | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:@aztec/validator-client | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:@aztec/protocol-contracts | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal monorepo sub-package of the Aztec Protocol project; missing README/repo/keywords is typical for published monorepo sub-packages, not spam. | ai | |
| phantom-deps | phantom-dep:@aztec/sequencer-client | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai | |
| phantom-deps | phantom-dep:@aztec/bb-prover | AI (phantom-deps): Same-org monorepo sibling dependency; phantom detection is a false positive for Aztec's monorepo publish pattern. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 4.3.1 | 19 / 11 | |
| 4.3.0 | 19 / 11 | |
| 4.2.1 | 19 / 11 | |
| 4.2.0 | 19 / 11 | |
| 4.1.3 | 19 / 11 | |
| 4.1.2 | 19 / 11 | |
| 4.1.1 | 19 / 11 | |
| 4.1.0 | 19 / 11 | |
| 4.0.4 | 19 / 11 | |
| 4.0.3 | 19 / 11 | |
| 4.0.2 | 19 / 11 | |
| 4.0.1 | 19 / 11 | |
| 3.0.3 | 19 / 11 | |
| 3.0.2 | 19 / 11 | |
| 3.0.1 | 19 / 11 | |
| 2.1.11 | 19 / 10 | |
| 2.1.9 | 19 / 10 | |
| 2.1.8 | 19 / 8 | |
| 2.1.7 | 19 / 8 | |
| 2.1.6 | 19 / 8 | |
| 2.1.5 | 19 / 8 | |
| 2.1.4 | 19 / 8 | |
| 2.1.3 | 19 / 8 | |
| 2.1.2 | 19 / 8 | |
| 2.0.4 | 19 / 7 |
v4.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.