Skip to content

chore: bump toolchain pins to 6.0.0-nightly.20261001 - #373

Merged
fcarreiro merged 1 commit into
mainfrom
fc/bump-toolchain-6.0.0-nightly.20261001
Oct 1, 2026
Merged

fcarreiro merged 1 commit into
mainfrom
fc/bump-toolchain-6.0.0-nightly.20261001

Conversation

@fcarreiro

Copy link
Copy Markdown
Collaborator

Bumps the labs toolchain from 6.0.0-rc.2 to 6.0.0-nightly.20261001, the AztecProtocol/aztec-packages v6 nightly cut at cf7ea33e26 (after AztecProtocol/aztec-packages#25565).

  • BB_VERSION: 6.0.0-rc.2 → 6.0.0-nightly.20261001
  • NOIR_VERSION: unchanged at 1.0.0-rc.3; the nightly's noir/noir-repo submodule is 5a7ee9bf5e, tagged v1.0.0-rc.3

Since 6.0.0-rc.2, v6 gains the labs bump to this repo's main (AztecProtocol/aztec-packages#25560) and AztecProtocol/aztec-packages#25548 (bb.js reports a dead bb process as retryable and replaces it on request).

The rewrite is ./labs-aztec-toolchain/bootstrap.sh set-pins 6.0.0-nightly.20261001 1.0.0-rc.3 (bootstrap.sh, aztec-nr's Nargo.toml, the docs examples, docs/package.json and the 23 @aztec-foundation/* resolutions in yarn-project/package.json), plus yarn in yarn-project and docs. The lockfile diffs are the 24 @aztec-foundation/* entries moving to the nightly and nothing else.

Verification

  • every @aztec-foundation/* resolution and the bb/bb-avm per-platform tarballs exist on npm at 6.0.0-nightly.20261001
  • node labs-aztec-toolchain/pins.mjs check: no drift
  • ./labs-aztec-toolchain/bootstrap.sh: provisions bb and bb-avm 6.0.0-nightly.20261001
  • ./bootstrap.sh in noir-projects/, then in yarn-project/: pass; the standard contracts build from the existing pinned tarball, and no tracked file changes

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​aztec-foundation/​noir-types@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100180 +11006698 +1100
Updatednpm/​@​aztec-foundation/​noir-noir_js@​6.0.0-rc.2 ⏵ 6.0.0-nightly.20261001771006898 +1100
Updatednpm/​@​aztec-foundation/​l1-artifacts@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100187 +11008098 +170
Updatednpm/​@​aztec-foundation/​noir-noir_codegen@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100179 +11007198 +1100
Updatednpm/​@​aztec-foundation/​noir-noirc_abi@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100182 +11007198 +1100
Updatednpm/​@​aztec-foundation/​ipc-runtime@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100182 +11007298 +1100
Updatednpm/​@​aztec-foundation/​mock-protocol-circuits-artifacts@​6.0.0-rc.2 ⏵ 6.0.0-nightly.202610018110076 +198 +1100
Updatednpm/​@​aztec-foundation/​protocol-contracts-artifacts@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100177 -510079 +198 +1100
Updatednpm/​@​aztec-foundation/​noir-acvm_js@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100181 +11007798 +1100
Updatednpm/​@​aztec-foundation/​cdb@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100180 +11007798 +1100
Updatednpm/​@​aztec-foundation/​bb-avm-sim@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100178 +11007798 +1100
Updatednpm/​@​aztec-foundation/​protocol-circuits-artifacts@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100178 -210083 +198 +1100
Updatednpm/​@​aztec-foundation/​constants-codegen@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100178 +11008498 +1100
Updatednpm/​@​aztec-foundation/​wsdb@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100182 +11008198 +1100
Updatednpm/​@​aztec-foundation/​bb.js@​6.0.0-rc.2 ⏵ 6.0.0-nightly.2026100186 +110098 +198 +1100

View full report

@socket-security

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Obfuscated code: npm @aztec-foundation/protocol-circuits-artifacts is 78.0% likely obfuscated

Confidence: 0.78

Location: Package overview

From: yarn-project/noir-protocol-circuits-types/package.json → npm/@aztec-foundation/protocol-circuits-artifacts@6.0.0-nightly.20261001

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@aztec-foundation/protocol-circuits-artifacts@6.0.0-nightly.20261001. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Obfuscated code: npm @aztec-foundation/protocol-circuits-artifacts is 95.0% likely obfuscated

Confidence: 0.95

Location: Package overview

From: yarn-project/noir-protocol-circuits-types/package.json → npm/@aztec-foundation/protocol-circuits-artifacts@6.0.0-nightly.20261001

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@aztec-foundation/protocol-circuits-artifacts@6.0.0-nightly.20261001. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Obfuscated code: npm @aztec-foundation/protocol-circuits-artifacts is 98.0% likely obfuscated

Confidence: 0.98

Location: Package overview

From: yarn-project/noir-protocol-circuits-types/package.json → npm/@aztec-foundation/protocol-circuits-artifacts@6.0.0-nightly.20261001

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@aztec-foundation/protocol-circuits-artifacts@6.0.0-nightly.20261001. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Obfuscated code: npm @aztec-foundation/protocol-contracts-artifacts is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: yarn-project/aztec.js/package.json → npm/@aztec-foundation/protocol-contracts-artifacts@6.0.0-nightly.20261001

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@aztec-foundation/protocol-contracts-artifacts@6.0.0-nightly.20261001. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block

View full report

@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Bumps toolchain and build dependencies to nightly version.

The PR appears safe to merge based on the reviewed changes.

Summary

The PR moves the Barretenberg toolchain and associated Aztec package pins from 6.0.0-rc.2 to 6.0.0-nightly.20261001 while retaining Noir 1.0.0-rc.3.

  • Updates Noir Git dependencies, documentation examples, npm resolutions, and both Yarn lockfiles to the corresponding nightly pins.
  • No actionable issue was established from the changed files.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
    BB["BB_VERSION: 6.0.0-nightly.20261001"]
    BB --> Nargo["Aztec package Git dependencies"]
    BB --> Yarn["yarn-project resolutions and lockfile"]
    BB --> Docs["Docs package, examples, and lockfile"]
    BB --> Binaries["Provisioned bb and bb-avm"]
    Noir["NOIR_VERSION: 1.0.0-rc.3"] --> NargoCompiler["Provisioned nargo"]
Loading

Reviews (1) · Last reviewed commit: "chore: bump toolchain pins to 6.0.0-nigh..."

@fcarreiro

Copy link
Copy Markdown
Collaborator Author

(Written by Claude on behalf of Facundo)

@SocketSecurity ignore npm/@aztec-foundation/protocol-circuits-artifacts@6.0.0-nightly.20261001

@fcarreiro
fcarreiro merged commit 31f1408 into main Oct 1, 2026
6 of 7 checks passed
@fcarreiro
fcarreiro deleted the fc/bump-toolchain-6.0.0-nightly.20261001 branch October 1, 2026 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant