@react-native-community/template
The template used by `npx @react-native-community/cli init` to bootstrap a React Native application.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transfer to official react-native-community-bot maintainer account. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-affiliated maintainers added; legitimate community transition. | ai |
Versions (showing 69 of 69)
| Version | Deps | Published |
|---|---|---|
| 0.86.0 | 0 / 3 | |
| 0.85.3 | 0 / 3 | |
| 0.85.2 | 0 / 3 | |
| 0.85.1 | 0 / 3 | |
| 0.85.0 | 0 / 3 | |
| 0.84.1 | 0 / 3 | |
| 0.84.0 | 0 / 3 | |
| 0.83.10 | 0 / 2 | |
| 0.83.9 | 0 / 2 | |
| 0.83.8 | 0 / 2 | |
| 0.83.7 | 0 / 2 | |
| 0.83.6 | 0 / 2 | |
| 0.83.5 | 0 / 2 | |
| 0.83.4 | 0 / 2 | |
| 0.83.3 | 0 / 2 | |
| 0.83.2 | 0 / 2 | |
| 0.83.1 | 0 / 2 | |
| 0.83.0 | 0 / 2 | |
| 0.82.1 | 0 / 2 | |
| 0.82.0 | 0 / 2 | |
| 0.81.6 | 0 / 2 | |
| 0.81.5 | 0 / 2 | |
| 0.81.4 | 0 / 2 | |
| 0.81.3 | 0 / 2 | |
| 0.81.2 | 0 / 2 | |
| 0.81.1 | 0 / 2 | |
| 0.81.0 | 0 / 2 | |
| 0.80.3 | 0 / 2 | |
| 0.80.2 | 0 / 2 | |
| 0.80.1 | 0 / 2 | |
| 0.80.0 | 0 / 2 | |
| 0.79.7 | 0 / 2 | |
| 0.79.6 | 0 / 2 | |
| 0.79.5 | 0 / 2 | |
| 0.79.4 | 0 / 2 | |
| 0.79.3 | 0 / 2 | |
| 0.79.2 | 0 / 2 | |
| 0.79.1 | 0 / 2 | |
| 0.79.0 | 0 / 2 | |
| 0.78.3 | 0 / 2 | |
| 0.78.2 | 0 / 2 | |
| 0.78.1 | 0 / 2 | |
| 0.78.0 | 0 / 2 | |
| 0.77.3 | 0 / 2 | |
| 0.77.2 | 0 / 2 | |
| 0.77.1 | 0 / 2 | |
| 0.77.0 | 0 / 2 | |
| 0.76.9 | 0 / 2 | |
| 0.76.8 | 0 / 2 | |
| 0.76.7 | 0 / 2 | |
| 0.76.6 | 0 / 2 | |
| 0.76.5 | 0 / 2 | |
| 0.76.4 | 0 / 2 | |
| 0.76.3 | 0 / 2 | |
| 0.76.2 | 0 / 2 | |
| 0.76.1 | 0 / 2 | |
| 0.76.0 | 0 / 2 | |
| 0.75.7 | 0 / 2 | |
| 0.75.6 | 0 / 2 | |
| 0.75.5 | 0 / 2 | |
| 0.75.4 | 0 / 2 | |
| 0.75.3 | 0 / 2 | |
| 0.75.2 | 0 / 0 | |
| 0.75.1 | 0 / 0 | |
| 0.0.5 | 0 / 0 | |
| 0.0.4 | 0 / 0 | |
| 0.0.3 | 0 / 0 | |
| 0.0.2 | 0 / 0 | |
| 0.0.1 | 0 / 0 |
v0.83.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (react-native-bot) than the most recent previously approved version (cortinico) on 2024-09-08, but react-native-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.75.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (react-native-bot) than the most recent previously approved version (cortinico) on 2024-08-20, but react-native-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.75.1
2 findingsThis version was published by a different npm account than previous versions on 2024-08-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (cortinico) than the most recent previously approved version (wootwootwoot) on 2024-06-20, but cortinico is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.