← Home

@expo/build-tools

`@expo/build-tools` is the core library for the EAS Build service. It implements the build process for React Native projects and for managed Expo applications.

55
Versions
BUSL-1.1
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

idebrentvatneexpoadminexponentbycedrickudochienalanhughestsapetaexpo-botphilplwschurman

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Expo org migrated to GitHub Actions publishing; SLSA attestation confirms CI/CD provenance. Stable pattern for this package. ai
dependencies unvetted-dep:@expo/logger AI (dependencies): First-party Expo monorepo package; stable pattern across versions. ai
dependencies unvetted-dep:@expo/results AI (dependencies): First-party Expo monorepo package; stable pattern across versions. ai
dependencies unvetted-dep:@expo/downloader AI (dependencies): First-party Expo monorepo package; stable pattern across versions. ai
dependencies unvetted-dep:@expo/steps AI (dependencies): First-party Expo monorepo package; stable pattern across versions. ai
dependencies unvetted-dep:@expo/eas-build-job AI (dependencies): First-party Expo monorepo package; stable pattern across versions. ai
dependencies unvetted-dep:@expo/template-file AI (dependencies): First-party Expo monorepo package; stable pattern across versions. ai
bogus-package bogus-package AI (bogus-package): Internal monorepo package; sparse README and no keywords are expected for this type of package. ai
dependencies unvetted-dep:@expo/turtle-spawn AI (dependencies): First-party Expo monorepo package; stable pattern across versions. ai

Versions (showing 55 of 55)

Version Deps Published
21.1.0 39 / 22
21.0.3 39 / 22
21.0.2 39 / 22
21.0.1 40 / 22
21.0.0 40 / 22
20.5.1 40 / 22
20.4.0 40 / 22
20.3.0 40 / 22
20.2.0 40 / 22
20.1.0 40 / 22
20.0.0 40 / 22
19.1.0 39 / 22
19.0.6 39 / 22
19.0.3 39 / 22
19.0.2 39 / 22
19.0.0 39 / 22
18.13.1 39 / 22
18.12.3 39 / 22
18.12.1 38 / 22
18.12.0 38 / 22
18.11.0 38 / 22
18.10.0 38 / 22
18.9.0 38 / 22
18.8.1 38 / 22
18.8.0 38 / 22
18.7.0 38 / 22
18.6.0 38 / 22
18.5.0 38 / 22
18.4.0 38 / 21
18.2.0 38 / 21
18.1.0 38 / 21
18.0.6 38 / 21
18.0.2 37 / 21
18.0.1 35 / 21
1.0.272 31 / 19
1.0.271 31 / 19
1.0.270 31 / 19
1.0.269 31 / 19
1.0.268 31 / 19
1.0.267 31 / 19
1.0.266 31 / 19
1.0.265 31 / 19
1.0.264 31 / 19
1.0.263 31 / 19
1.0.262 31 / 19
1.0.261 31 / 19
1.0.260 31 / 19
1.0.252 31 / 19
1.0.251 31 / 19
1.0.250 31 / 19
1.0.249 31 / 19
1.0.248 31 / 19
1.0.247 31 / 19
1.0.246 31 / 19
1.0.245 31 / 19

v21.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v21.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v20.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v20.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.