@planningcenter/chat-react-native
The code hosted here is meant to encapsulate behavior for our mobile targets. Currently we support behavior in Services and ChurchCenterApp.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Active component library regularly adds source files across versions; not indicative of injected code. | ai | |
| phantom-deps | phantom-dep:fast-text-encoding | AI (phantom-deps): Polyfill dependency; used indirectly via platform-specific imports. | ai | |
| phantom-deps | phantom-dep:jest-fetch-mock | AI (phantom-deps): Test dependency; legitimately used in test config without direct import. | ai | |
| phantom-deps | phantom-dep:react-native-url-polyfill | AI (phantom-deps): Platform-specific polyfill; standard pattern for React Native packages. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs 'yarn build' via expo-module; standard build step for this React Native library, stable across versions. | ai | |
| dependencies | unvetted-dep:@fortawesome/react-native-fontawesome | AI (dependencies): Official Font Awesome React Native package; no malicious indicators; stable dependency. | ai | |
| dependencies | unvetted-dep:lodash-inflection | AI (dependencies): Well-known utility library; no malicious indicators; stable dependency across versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across 467 versions of this internal org package; not a malice indicator. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal org package (@planningcenter); sparse metadata is expected, not a spam/malware signal. | ai | |
| provenance | no-provenance | AI (provenance): Large org package with 461 versions; no provenance is consistent with their publishing history. | ai | |
| phantom-deps | phantom-dep:react-compiler-runtime | AI (phantom-deps): react-compiler-runtime is a declared runtime dep used by the React compiler toolchain; phantom-dep false positive for this package. | ai |
Versions (showing 57 of 57)
| Version | Deps | Published |
|---|---|---|
| 3.37.0 | 5 / 19 | |
| 3.36.1 | 5 / 19 | |
| 3.36.0 | 5 / 19 | |
| 3.35.0 | 5 / 19 | |
| 3.34.0 | 5 / 13 | |
| 3.33.1 | 5 / 13 | |
| 3.33.0 | 5 / 13 | |
| 3.32.0 | 4 / 13 | |
| 3.31.0 | 4 / 13 | |
| 3.30.0 | 4 / 13 | |
| 3.29.0 | 2 / 13 | |
| 3.28.0 | 2 / 13 | |
| 3.27.0 | 2 / 13 | |
| 3.26.0 | 2 / 13 | |
| 3.25.0 | 2 / 13 | |
| 3.24.4 | 2 / 13 | |
| 3.24.3 | 2 / 13 | |
| 3.24.2 | 2 / 13 | |
| 3.24.1 | 2 / 13 | |
| 3.24.0 | 2 / 13 | |
| 3.23.0 | 2 / 13 | |
| 3.22.0 | 2 / 13 | |
| 3.21.1 | 2 / 13 | |
| 3.21.0 | 2 / 13 | |
| 3.20.2 | 2 / 13 | |
| 3.20.1 | 2 / 13 | |
| 3.20.0 | 2 / 13 | |
| 3.19.0 | 2 / 13 | |
| 3.18.0 | 2 / 13 | |
| 3.17.2 | 2 / 13 | |
| 3.17.1 | 2 / 13 | |
| 3.17.0 | 1 / 12 | |
| 3.16.1 | 1 / 12 | |
| 3.16.0 | 1 / 12 | |
| 3.15.0 | 1 / 12 | |
| 3.14.0 | 1 / 12 | |
| 3.13.1 | 1 / 12 | |
| 3.13.0 | 1 / 12 | |
| 3.12.2 | 1 / 12 | |
| 3.12.1 | 5 / 8 | |
| 3.12.0 | 5 / 8 | |
| 3.11.2 | 5 / 8 | |
| 3.11.1 | 5 / 8 | |
| 3.11.0 | 5 / 8 | |
| 3.10.0 | 5 / 8 | |
| 3.9.2 | 5 / 8 | |
| 3.9.1 | 5 / 8 | |
| 3.9.0 | 5 / 8 | |
| 3.8.0 | 5 / 8 | |
| 3.7.0 | 5 / 8 | |
| 3.6.0 | 5 / 8 | |
| 3.5.0 | 5 / 7 | |
| 3.4.1 | 5 / 7 | |
| 3.4.0 | 5 / 7 | |
| 3.3.0 | 5 / 7 | |
| 3.2.0 | 5 / 7 | |
| 3.1.0 | 5 / 7 |
v3.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.33.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.32.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.31.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.30.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.24.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.24.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.20.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.20.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.12.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.0
2 findingsScript: yarn build
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.