← Home

@growflow/react-scripts

Configuration and scripts for Create React App.

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

zachgrowflow.comsnoltonchristian20gfpeter20gfconsidinetomgrowflowsperryejaygrowflowchadlyryanmorrowjpboodhoo_growflowroberto.hernandezjreyesericjohannsengreglarrenaga

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-bulk-read AI (semgrep): Standard CRA config/env.js pattern; filters to REACT_APP_ prefix only. ai
semgrep semgrep:dynamic-require AI (semgrep): CRA build tooling loads optional compilers (typescript, sass, etc.) dynamically by design. ai
semgrep semgrep:child-process-import AI (semgrep): execSync in scripts/eject.js is the standard CRA eject flow; not a runtime risk. ai
phantom-deps phantom-dep:less AI (phantom-deps): Build-tool peer dep loaded by webpack config convention, not direct import. ai
phantom-deps phantom-dep:fsevents AI (phantom-deps): Optional native dep for macOS file watching; loaded by webpack-dev-server indirectly. ai
phantom-deps phantom-dep:camelcase AI (phantom-deps): Utility used indirectly in build config; stable false positive for this package. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped peer dep loaded by babel-loader convention. ai
phantom-deps phantom-dep:less-loader AI (phantom-deps): Webpack loader referenced in config, not directly imported. ai
phantom-deps phantom-dep:sass-loader AI (phantom-deps): Webpack loader referenced in config, not directly imported. ai
phantom-deps phantom-dep:@svgr/webpack AI (phantom-deps): Webpack loader referenced in config, not directly imported. ai
phantom-deps phantom-dep:identity-obj-proxy AI (phantom-deps): Jest transform referenced in config, not directly imported. ai
phantom-deps phantom-dep:react-app-polyfill AI (phantom-deps): Referenced in CRA template entry points by convention. ai
phantom-deps phantom-dep:@growflow/browserslist-config AI (phantom-deps): Same-org browserslist config; referenced in package.json browserslist field, not a JS import. ai

Versions (showing 1 of 1)

Version Deps Published
0.5.0 43 / 2