@react-native-windows/telemetry
Telemetry library for the react-native-windows CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Well-known utility deps supporting telemetry/CI detection, not suspicious additions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Matches added dependencies/features; no malicious content found. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Legitimate feature growth in official Microsoft package, not injected payload. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): microsoft-oss-releases is a known Microsoft automation account. | ai | |
| provenance | missing-githead | AI (provenance): Microsoft monorepo publish tooling change; publisher is trusted microsoft1es. | ai | |
| phantom-deps | phantom-dep:minimatch | AI (phantom-deps): minimatch used indirectly via config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@azure/core-auth | AI (phantom-deps): @azure/core-auth is a Microsoft Azure SDK package used as a peer/transitive dep by applicationinsights; not being directly imported is expected for this type of auth abstraction. | ai | |
| dependencies | unvetted-dep:applicationinsights | AI (dependencies): applicationinsights is Microsoft's official Azure Application Insights Node.js SDK — a legitimate and expected dependency for a telemetry package in the react-native-windows ecosystem. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in projectUtils.js loads package.json from a project root to read the project name — a common, legitimate pattern in React Native build tooling. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process is used in basePropUtils.js for CI environment detection alongside os and ci-info — standard telemetry/environment-probing behavior for this package. | ai |
Versions (showing 81 of 81)
| Version | Deps | Published |
|---|---|---|
| 0.84.0 | 10 / 17 | |
| 0.83.1 | 10 / 17 | |
| 0.83.0 | 10 / 17 | |
| 0.82.1 | 10 / 17 | |
| 0.82.0 | 10 / 17 | |
| 0.81.2 | 9 / 17 | |
| 0.81.1 | 9 / 17 | |
| 0.81.0 | 9 / 17 | |
| 0.80.1 | 9 / 17 | |
| 0.80.0 | 9 / 17 | |
| 0.79.2 | 9 / 17 | |
| 0.79.1 | 9 / 17 | |
| 0.79.0 | 10 / 17 | |
| 0.78.2 | 9 / 17 | |
| 0.78.1 | 10 / 17 | |
| 0.78.0 | 10 / 17 | |
| 0.77.2 | 9 / 17 | |
| 0.77.1 | 10 / 17 | |
| 0.77.0 | 10 / 17 | |
| 0.76.4 | 9 / 17 | |
| 0.76.3 | 10 / 17 | |
| 0.76.2 | 10 / 17 | |
| 0.76.1 | 10 / 17 | |
| 0.76.0 | 10 / 17 | |
| 0.75.5 | 9 / 17 | |
| 0.75.4 | 10 / 17 | |
| 0.75.3 | 9 / 17 | |
| 0.75.2 | 9 / 17 | |
| 0.75.1 | 9 / 17 | |
| 0.75.0 | 9 / 17 | |
| 0.74.3 | 9 / 17 | |
| 0.74.2 | 9 / 17 | |
| 0.74.1 | 9 / 17 | |
| 0.74.0 | 9 / 17 | |
| 0.73.2 | 8 / 17 | |
| 0.73.1 | 8 / 17 | |
| 0.73.0 | 8 / 17 | |
| 0.72.3 | 8 / 17 | |
| 0.72.2 | 8 / 17 | |
| 0.72.1 | 8 / 17 | |
| 0.72.0 | 8 / 17 | |
| 0.71.10 | 8 / 17 | |
| 0.71.9 | 8 / 17 | |
| 0.71.8 | 8 / 17 | |
| 0.71.7 | 8 / 17 | |
| 0.71.6 | 8 / 17 | |
| 0.71.5 | 8 / 17 | |
| 0.71.4 | 8 / 17 | |
| 0.71.3 | 8 / 17 | |
| 0.71.2 | 8 / 17 | |
| 0.71.1 | 10 / 15 | |
| 0.71.0 | 10 / 15 | |
| 0.70.3 | 8 / 17 | |
| 0.70.2 | 10 / 15 | |
| 0.70.1 | 10 / 15 | |
| 0.70.0 | 10 / 15 | |
| 0.69.5 | 8 / 18 | |
| 0.69.4 | 10 / 16 | |
| 0.69.3 | 10 / 16 | |
| 0.69.2 | 10 / 16 | |
| 0.69.1 | 10 / 16 | |
| 0.69.0 | 11 / 16 | |
| 0.68.5 | 8 / 16 | |
| 0.68.4 | 8 / 16 | |
| 0.68.3 | 9 / 16 | |
| 0.68.2 | 9 / 16 | |
| 0.68.1 | 9 / 16 | |
| 0.68.0 | 9 / 16 | |
| 0.67.1 | 1 / 13 | |
| 0.67.0 | 1 / 13 | |
| 0.66.1 | 1 / 13 | |
| 0.66.0 | 1 / 13 | |
| 0.65.1 | 1 / 13 | |
| 0.65.0 | 1 / 13 | |
| 0.64.1 | 1 / 12 | |
| 0.64.0 | 1 / 12 | |
| 0.63.5 | 1 / 13 | |
| 0.63.4 | 1 / 13 | |
| 0.63.3 | 1 / 13 | |
| 0.63.2 | 1 / 13 | |
| 0.63.0 | 1 / 12 |
v0.78.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.72.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.72.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.72.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.72.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.69.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.69.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.69.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.69.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.69.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.69.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.68.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.66.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.66.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.65.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.65.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.64.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.63.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.63.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.63.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.63.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.63.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.