@aztec/pxe
20
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
zac-williamsonleilawangcharlielyejaosefjoss-aztecprotocolludamad
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is same-org @aztec/standard-contracts sibling package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Monorepo release adds many same-org source files; not injected code. | ai | |
| dependencies | unvetted-dep:@aztec/noir-protocol-circuits-types | AI (dependencies): Same-org @aztec scope dependency, part of the monorepo's coordinated versioning. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Aztec monorepo package with 1025 versions; dormancy reflects org publishing cadence, not account takeover risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Part of the @aztec monorepo with 1025 versions and 6 approved dependents; missing metadata is a monorepo artifact, not spam. | ai | |
| phantom-deps | phantom-dep:koa-router | AI (phantom-deps): koa-router is a declared runtime dependency in package.json; used in server entrypoint. Phantom-dep heuristic is a false positive here. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decoding in this package is standard ZK/blockchain serialization (Buffer.from(hex, 'hex') for NoteDao deserialization). No malicious payload risk. | ai | |
| phantom-deps | phantom-dep:koa | AI (phantom-deps): koa is a declared runtime dependency in package.json; used in server entrypoint. Phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:sha3 | AI (phantom-deps): sha3 is a declared runtime dependency in package.json. Phantom-dep heuristic is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:viem | AI (phantom-deps): viem (as custom fork) is a declared runtime dependency in package.json. Phantom-dep heuristic is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit TypeScript runtime dependency; phantom-dep correctly notes it as such. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash.omit | AI (phantom-deps): lodash.omit is a declared runtime dependency in package.json. Phantom-dep heuristic is a false positive for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() is used in a proxy pattern for dynamic dispatch in proxied_contract_data_source.js — standard JavaScript proxy implementation, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@aztec/noir-types | AI (phantom-deps): Same-org @aztec/ scoped package in a monorepo; phantom dep detection is a false positive for monorepo indirect dependencies. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding is used for ZK verification key handling — standard cryptographic practice in a ZK proof system, not a malicious payload. | ai | |
| phantom-deps | phantom-dep:@aztec/ethereum | AI (phantom-deps): Same-org @aztec/ scoped package in a monorepo; phantom dep detection is a false positive for monorepo indirect dependencies. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @aztec/pxe is the Private eXecution Environment component of Aztec Protocol — not a typosquat of 'pg'. The @aztec/ scope and 1025-version history make this a clear false positive. | ai | |
| phantom-deps | phantom-dep:@aztec/builder | AI (phantom-deps): Same-org @aztec/ scoped package in a monorepo; phantom dep detection is a false positive for monorepo indirect dependencies. | ai | |
| phantom-deps | phantom-dep:@aztec/bb.js | AI (phantom-deps): Same-org @aztec/ scoped package in a monorepo; phantom dep detection is a false positive for monorepo indirect dependencies. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 5.0.0 | 20 / 14 | |
| 4.4.0 | 19 / 14 | |
| 4.3.0 | 19 / 14 | |
| 4.2.1 | 19 / 13 | |
| 4.2.0 | 19 / 13 | |
| 4.1.3 | 19 / 13 | |
| 4.1.2 | 19 / 13 | |
| 4.1.1 | 19 / 13 | |
| 4.1.0 | 19 / 13 | |
| 4.0.2 | 19 / 13 | |
| 4.0.1 | 19 / 13 | |
| 3.0.3 | 19 / 13 | |
| 3.0.1 | 19 / 13 | |
| 2.1.11 | 20 / 12 | |
| 2.1.9 | 20 / 12 | |
| 2.1.8 | 20 / 12 | |
| 2.1.4 | 20 / 12 | |
| 2.1.3 | 20 / 12 | |
| 2.1.2 | 20 / 12 | |
| 2.0.4 | 20 / 12 |
v5.0.0
2 findings
HIGH
Missing gitHead — previous versions had it
provenance
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: charlielye.
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.