@instantdb/react-native
Instant DB for React Native
100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
stopachkanezajdwwdrew-h
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed from human (dww) to GitHub Actions as part of a legitimate CI/CD migration; SLSA provenance attestation confirms controlled pipeline publishing. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removal (tonsky) is consistent with the org-wide shift to automated CI/CD publishing under GitHub Actions; not indicative of takeover. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy reflects package namespace restructuring within the active InstantDB ecosystem; SLSA attestation and legitimate repo confirm no takeover. | ai | |
| dependencies | unvetted-dep:@instantdb/core | AI (dependencies): First-party sibling package from the same InstantDB monorepo, always published at the same version. Not an independent third-party risk. | ai | |
| dependencies | unvetted-dep:@instantdb/react-common | AI (dependencies): First-party sibling package from the same InstantDB monorepo, always published at the same version. Not an independent third-party risk. | ai |
Versions (showing 100 of 201)
Showing 100 of 201
Next page →