← Home

@aztec/sequencer-client

The sequencer is a module responsible for creating and publishing new rollup blocks. This involves fetching txs from the P2P pool, ordering them, executing any public functions, running them through the rollup circuits, assembling the L2 block, and postin

8
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

zac-williamsonleilawangcharlielyejaosefjoss-aztecprotocolludamad

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@aztec/blob-sink AI (dependencies): Same-org @aztec/* dependency pinned to matching version in a monorepo release pattern; not a supply chain risk. ai
dependencies unvetted-dep:@aztec/noir-protocol-circuits-types AI (dependencies): Same-org @aztec/* dependency pinned to matching version in a monorepo release pattern; not a supply chain risk. ai
bogus-package bogus-package AI (bogus-package): Monorepo package using exports map; missing repo/keywords/main are common patterns for @aztec/* packages and not indicative of spam or malice. ai
phantom-deps phantom-dep:@aztec/noir-types AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/merkle-tree AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/noir-acvm_js AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/prover-client AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/world-state AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/protocol-contracts AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/noir-protocol-circuits-types AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a well-known TypeScript runtime helper; implicit dependency pattern is standard. ai
phantom-deps phantom-dep:lodash.chunk AI (phantom-deps): Referenced in config files; well-known utility package, not a risk. ai
phantom-deps phantom-dep:@aztec/noir-contracts.js AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/bb-prover AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai
phantom-deps phantom-dep:@aztec/simulator AI (phantom-deps): Same-org monorepo sibling; phantom dep pattern is expected in Aztec monorepo releases. ai

Versions (showing 8 of 8)

Version Deps Published
4.2.1 28 / 17
4.2.0 28 / 17
4.1.3 28 / 17
4.1.2 28 / 17
4.1.0 28 / 17
3.0.1 27 / 16
2.1.3 27 / 15
2.1.2 27 / 15

v4.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.