@cloudflare/realtimekit-react-native-ui
Cloudflare RealtimeKit's UI library for meeting components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/commonjs/lib/icons/default-icon-pack.js | AI (source-diff): Long lines are inline SVG path data, not obfuscated code; stable pattern for this icon-pack file. | ai | |
| source-diff | obfuscated-file:lib/module/lib/icons/default-icon-pack.js | AI (source-diff): Same SVG-data pattern as commonjs counterpart; false positive for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): cf-npm-publish is a Cloudflare CI service account; consistent with org-level publishing consolidation. | ai | |
| dependencies | unvetted-dep:react-native-gifted-chat | AI (dependencies): Well-known React Native chat UI library; no malware indicators. | ai | |
| dependencies | unvetted-dep:react-native-switch | AI (dependencies): Standard React Native UI toggle component; no malware indicators. | ai | |
| dependencies | unvetted-dep:radio-buttons-react-native | AI (dependencies): Standard React Native radio button UI component; no malware indicators. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Stub/placeholder release under @cloudflare scope; empty payload and missing metadata are expected for namespace reservation. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Cloudflare-scoped package with 43 versions; 0.0.0 is a namespace reservation, not a malicious throwaway. | ai | |
| provenance | no-provenance | AI (provenance): Cloudflare package; provenance absence is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:react-native-svg-transformer | AI (phantom-deps): Platform-specific build tool; not directly imported in JS but legitimately declared as a dep for RN bundler config. | ai | |
| phantom-deps | phantom-dep:abortcontroller-polyfill | AI (phantom-deps): Polyfill referenced in config/setup files rather than direct imports; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-native-url-polyfill | AI (phantom-deps): Platform-specific polyfill; stable false positive for this RN package. | ai | |
| phantom-deps | phantom-dep:radio-buttons-react-native | AI (phantom-deps): Platform-specific RN component; heuristic false positive for native packages. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 1.0.0 | 8 / 0 | |
| 0.2.1 | 8 / 0 | |
| 0.2.0 | 8 / 0 | |
| 0.1.3 | 9 / 0 | |
| 0.1.2 | 9 / 0 | |
| 0.1.1 | 8 / 0 | |
| 0.1.0 | 8 / 0 | |
| 0.0.0 | 0 / 0 |
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.