@react-native/community-cli-plugin
Core CLI commands for React Native
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:metro | AI (dependencies): metro is the official React Native bundler maintained by Meta; it is a core, expected dependency for this CLI plugin package across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Official React Native monorepo package published by Meta's react-native-bot; repository URL anchors legitimacy. Provenance absence is common and not a risk here. | ai |
Versions (showing 100 of 103)
| Version | Deps | Published |
|---|---|---|
| 0.86.2 | 7 / 1 | |
| 0.86.1 | 7 / 1 | |
| 0.86.0 | 7 / 1 | |
| 0.85.3 | 7 / 1 | |
| 0.85.2 | 7 / 1 | |
| 0.85.1 | 7 / 1 | |
| 0.85.0 | 7 / 1 | |
| 0.84.1 | 7 / 1 | |
| 0.84.0 | 7 / 1 | |
| 0.83.10 | 7 / 1 | |
| 0.83.9 | 7 / 1 | |
| 0.83.8 | 7 / 1 | |
| 0.83.7 | 7 / 1 | |
| 0.83.6 | 7 / 1 | |
| 0.83.5 | 7 / 1 | |
| 0.83.4 | 7 / 1 | |
| 0.83.3 | 7 / 1 | |
| 0.83.2 | 7 / 1 | |
| 0.83.1 | 7 / 1 | |
| 0.83.0 | 7 / 1 | |
| 0.82.1 | 7 / 1 | |
| 0.82.0 | 7 / 1 | |
| 0.81.6 | 7 / 1 | |
| 0.81.5 | 7 / 1 | |
| 0.81.4 | 7 / 1 | |
| 0.81.3 | 7 / 1 | |
| 0.81.2 | 7 / 1 | |
| 0.81.1 | 7 / 1 | |
| 0.81.0 | 7 / 1 | |
| 0.80.3 | 8 / 1 | |
| 0.80.2 | 8 / 1 | |
| 0.80.1 | 8 / 1 | |
| 0.80.0 | 8 / 1 | |
| 0.79.7 | 8 / 1 | |
| 0.79.6 | 8 / 1 | |
| 0.79.5 | 8 / 1 | |
| 0.79.4 | 8 / 1 | |
| 0.79.3 | 8 / 1 | |
| 0.79.2 | 8 / 1 | |
| 0.79.1 | 8 / 1 | |
| 0.79.0 | 8 / 1 | |
| 0.78.3 | 10 / 1 | |
| 0.78.2 | 10 / 1 | |
| 0.78.1 | 10 / 1 | |
| 0.78.0 | 10 / 1 | |
| 0.77.3 | 10 / 1 | |
| 0.77.2 | 10 / 1 | |
| 0.77.1 | 10 / 1 | |
| 0.77.0 | 10 / 1 | |
| 0.76.9 | 11 / 1 | |
| 0.76.8 | 11 / 1 | |
| 0.76.7 | 11 / 1 | |
| 0.76.6 | 11 / 1 | |
| 0.76.5 | 11 / 1 | |
| 0.76.4 | 11 / 1 | |
| 0.76.3 | 11 / 1 | |
| 0.76.2 | 11 / 1 | |
| 0.76.1 | 10 / 1 | |
| 0.76.0 | 10 / 1 | |
| 0.75.5 | 11 / 1 | |
| 0.75.4 | 11 / 1 | |
| 0.75.3 | 11 / 1 | |
| 0.75.2 | 12 / 1 | |
| 0.75.1 | 12 / 1 | |
| 0.75.0 | 12 / 1 | |
| 0.74.89 | 12 / 1 | |
| 0.74.88 | 12 / 1 | |
| 0.74.87 | 12 / 1 | |
| 0.74.86 | 12 / 1 | |
| 0.74.85 | 12 / 1 | |
| 0.74.84 | 12 / 1 | |
| 0.74.83 | 12 / 1 | |
| 0.74.82 | 12 / 1 | |
| 0.74.81 | 12 / 1 | |
| 0.74.80 | 12 / 1 | |
| 0.74.79 | 12 / 1 | |
| 0.74.78 | 12 / 1 | |
| 0.74.77 | 12 / 1 | |
| 0.74.76 | 12 / 1 | |
| 0.74.75 | 12 / 1 | |
| 0.74.5 | 12 / 1 | |
| 0.74.4 | 12 / 1 | |
| 0.74.2 | 12 / 1 | |
| 0.74.1 | 12 / 1 | |
| 0.74.0 | 11 / 1 | |
| 0.73.18 | 11 / 1 | |
| 0.73.17 | 11 / 1 | |
| 0.73.16 | 11 / 1 | |
| 0.73.15 | 11 / 1 | |
| 0.73.14 | 11 / 1 | |
| 0.73.13 | 11 / 1 | |
| 0.73.12 | 11 / 1 | |
| 0.73.11 | 11 / 1 | |
| 0.73.10 | 11 / 1 | |
| 0.73.9 | 11 / 1 | |
| 0.73.8 | 11 / 1 | |
| 0.73.7 | 11 / 1 | |
| 0.73.6 | 11 / 1 | |
| 0.73.5 | 11 / 1 | |
| 0.73.4 | 11 / 1 |
v0.86.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (react-native-bot) on 2026-07-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.86.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.75.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.89
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.88
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.87
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.86
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.85
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.84
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.83
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.82
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.81
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.80
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.79
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.78
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.