@office-iss/react-native-win32
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@react-native/community-cli-plugin | AI (phantom-deps): Platform-specific binary package; stable pattern for React Native monorepos. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-ios | AI (phantom-deps): Platform-specific binary package; stable pattern for React Native monorepos. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-android | AI (phantom-deps): Platform-specific binary package; stable pattern for React Native monorepos. | ai | |
| phantom-deps | phantom-dep:jsc-android | AI (phantom-deps): Platform-specific native dep referenced via config, not direct import. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:mkdirp | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:babel-jest | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped package loaded by convention in RN ecosystem. Stable false positive. | ai | |
| phantom-deps | phantom-dep:hermes-compiler | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:metro-source-map | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() in loadBundleFromServer.js is the canonical RN dev-server bundle eval pattern; stable across versions. | ai | |
| phantom-deps | phantom-dep:flow-enums-runtime | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:@react-native/assets | AI (phantom-deps): Platform-specific RN package; stable false positive for this framework package. | ai | |
| phantom-deps | phantom-dep:@react-native/codegen | AI (phantom-deps): Platform-specific RN package; stable false positive for this framework package. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli | AI (phantom-deps): Platform-specific RN package; stable false positive for this framework package. | ai | |
| phantom-deps | phantom-dep:@react-native/gradle-plugin | AI (phantom-deps): Platform-specific RN package; stable false positive for this framework package. | ai | |
| phantom-deps | phantom-dep:react-clone-referenced-element | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:babel-plugin-syntax-hermes-parser | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:event-target-shim | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:art | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): RN framework package; deps used via config/tooling, not direct imports. Stable false positive. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 0.84.0 | 46 / 22 | |
| 0.83.1 | 45 / 22 | |
| 0.83.0 | 45 / 22 | |
| 0.82.1 | 45 / 21 | |
| 0.82.0 | 45 / 21 | |
| 0.81.8 | 44 / 21 | |
| 0.81.7 | 44 / 21 | |
| 0.81.6 | 44 / 21 | |
| 0.81.5 | 44 / 21 | |
| 0.81.4 | 44 / 21 | |
| 0.81.3 | 44 / 21 | |
| 0.81.2 | 44 / 21 | |
| 0.81.1 | 44 / 21 | |
| 0.81.0 | 44 / 21 | |
| 0.80.2 | 44 / 21 | |
| 0.80.1 | 44 / 21 | |
| 0.74.13 | 42 / 21 | |
| 0.74.12 | 42 / 21 | |
| 0.74.11 | 42 / 21 |
v0.84.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.81.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.81.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.81.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.81.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.81.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.81.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.81.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.81.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.80.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.80.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.