@jobber/components-native
React Native implementation of Atlantis
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Same rationale; org-managed package with rotating maintainers. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer churn consistent with active Jobber org team, not a takeover pattern. | ai | |
| provenance | publisher-changed | AI (provenance): CI-shaped publisher account, provenance direction unchanged; consistent with automated releases. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Active component library; large file additions are routine for new component releases across 622 versions. | ai | |
| dependencies | unvetted-dep:react-native-modalize | AI (dependencies): react-native-modalize is a well-known RN modal library; appropriate for a RN component package. | ai | |
| dependencies | unvetted-dep:react-native-portalize | AI (dependencies): react-native-portalize is a companion to react-native-modalize; appropriate for a RN component package. | ai | |
| dependencies | unvetted-peer-dep:react-native-keyboard-controller | AI (dependencies): Stable peer dependency for this package; pre-existing and accepted. | ai | |
| dependencies | unvetted-dep:ts-xor | AI (dependencies): Legitimate TypeScript utility; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:@react-native-clipboard/clipboard | AI (dependencies): Official React Native community clipboard package; well-known ecosystem dep. | ai | |
| dependencies | unvetted-dep:react-native-keyboard-controller | AI (dependencies): Popular React Native keyboard management library; no risk indicators. | ai | |
| dependencies | unvetted-dep:@react-native-picker/picker | AI (dependencies): Official React Native community picker package; well-known ecosystem dep. | ai | |
| provenance | no-provenance | AI (provenance): Established org package; lack of provenance is common and not a risk signal here. | ai |
Versions (showing 100 of 127)
| Version | Deps | Published |
|---|---|---|
| 0.111.0 | 13 / 33 | |
| 0.110.0 | 13 / 33 | |
| 0.109.1 | 13 / 33 | |
| 0.109.0 | 13 / 33 | |
| 0.108.2 | 13 / 33 | |
| 0.108.1 | 13 / 33 | |
| 0.108.0 | 13 / 33 | |
| 0.107.3 | 13 / 33 | |
| 0.107.2 | 13 / 33 | |
| 0.107.1 | 13 / 33 | |
| 0.107.0 | 13 / 33 | |
| 0.106.0 | 13 / 33 | |
| 0.105.4 | 11 / 33 | |
| 0.105.3 | 11 / 33 | |
| 0.105.2 | 11 / 33 | |
| 0.105.1 | 11 / 33 | |
| 0.105.0 | 11 / 33 | |
| 0.104.2 | 11 / 33 | |
| 0.104.1 | 11 / 33 | |
| 0.104.0 | 11 / 33 | |
| 0.103.1 | 11 / 33 | |
| 0.103.0 | 11 / 33 | |
| 0.102.2 | 11 / 33 | |
| 0.102.1 | 11 / 33 | |
| 0.102.0 | 11 / 33 | |
| 0.101.11 | 11 / 33 | |
| 0.101.10 | 11 / 33 | |
| 0.101.9 | 11 / 33 | |
| 0.101.8 | 11 / 33 | |
| 0.101.7 | 11 / 33 | |
| 0.101.6 | 11 / 33 | |
| 0.101.5 | 11 / 33 | |
| 0.101.4 | 11 / 32 | |
| 0.101.3 | 11 / 25 | |
| 0.101.2 | 11 / 25 | |
| 0.101.1 | 11 / 25 | |
| 0.101.0 | 11 / 24 | |
| 0.100.2 | 11 / 24 | |
| 0.100.1 | 11 / 24 | |
| 0.100.0 | 11 / 24 | |
| 0.99.0 | 13 / 23 | |
| 0.98.5 | 13 / 23 | |
| 0.98.4 | 13 / 23 | |
| 0.98.3 | 13 / 23 | |
| 0.98.2 | 13 / 23 | |
| 0.98.1 | 13 / 23 | |
| 0.98.0 | 13 / 23 | |
| 0.97.1 | 13 / 23 | |
| 0.97.0 | 13 / 23 | |
| 0.96.0 | 13 / 23 | |
| 0.95.4 | 13 / 23 | |
| 0.95.3 | 13 / 23 | |
| 0.95.2 | 13 / 23 | |
| 0.95.1 | 13 / 23 | |
| 0.95.0 | 13 / 23 | |
| 0.94.0 | 13 / 23 | |
| 0.93.0 | 13 / 22 | |
| 0.92.0 | 13 / 22 | |
| 0.91.4 | 13 / 22 | |
| 0.91.3 | 13 / 22 | |
| 0.91.2 | 13 / 22 | |
| 0.91.1 | 13 / 22 | |
| 0.91.0 | 13 / 22 | |
| 0.90.0 | 13 / 22 | |
| 0.89.4 | 13 / 22 | |
| 0.89.3 | 13 / 22 | |
| 0.89.2 | 13 / 22 | |
| 0.89.1 | 13 / 22 | |
| 0.89.0 | 13 / 22 | |
| 0.88.1 | 13 / 22 | |
| 0.88.0 | 13 / 22 | |
| 0.87.1 | 13 / 23 | |
| 0.87.0 | 13 / 23 | |
| 0.86.1 | 13 / 23 | |
| 0.86.0 | 13 / 23 | |
| 0.85.0 | 13 / 15 | |
| 0.84.3 | 13 / 13 | |
| 0.84.2 | 13 / 9 | |
| 0.84.1 | 13 / 9 | |
| 0.84.0 | 13 / 9 | |
| 0.83.0 | 13 / 9 | |
| 0.82.0 | 13 / 9 | |
| 0.81.2 | 14 / 9 | |
| 0.81.1 | 14 / 9 | |
| 0.81.0 | 14 / 9 | |
| 0.80.2 | 14 / 9 | |
| 0.80.1 | 14 / 9 | |
| 0.80.0 | 14 / 9 | |
| 0.79.0 | 14 / 9 | |
| 0.78.0 | 14 / 9 | |
| 0.77.1 | 14 / 9 | |
| 0.77.0 | 14 / 9 | |
| 0.76.0 | 14 / 9 | |
| 0.75.5 | 14 / 9 | |
| 0.75.3 | 14 / 9 | |
| 0.75.2 | 14 / 9 | |
| 0.75.1 | 14 / 9 | |
| 0.75.0 | 14 / 9 | |
| 0.74.0 | 14 / 9 | |
| 0.73.3 | 14 / 9 |
v0.111.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.109.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.109.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.108.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.108.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.108.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.107.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.107.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.107.1
2 findingsThis version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.78.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.77.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.77.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.76.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.