@react-native/eslint-config
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:eslint-plugin-prettier | AI (phantom-deps): ESLint config package; deps referenced via config, not imports. | ai | |
| source-diff | net-exec-file:shared.js | AI (source-diff): shared.js is a static ESLint config; the net-exec detection is a false positive for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Backport patch releases for older minor series naturally have long gaps; trusted publisher with 1561 approved packages. | ai | |
| provenance | no-provenance | AI (provenance): Official React Native monorepo package; lack of Sigstore provenance is consistent across all versions and not a meaningful risk signal here. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-ft-flow | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-config-prettier | AI (phantom-deps): ESLint config packages reference configs by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): ESLint config packages reference parsers by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react-hooks | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react-native | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@react-native/eslint-plugin | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-eslint-comments | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/eslint-parser | AI (phantom-deps): ESLint config packages reference parsers by name in config, not via import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jest | AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:eslint-plugin-ft-flow | AI (dependencies): eslint-plugin-ft-flow is a legitimate Flow linting plugin; appropriate dependency for React Native ESLint config. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): @babel/core is a declared runtime dep used by @babel/eslint-parser; phantom-dep false positive for this package. | ai |
Versions (showing 51 of 87)
| Version | Deps | Published |
|---|---|---|
| 0.86.2 | 12 / 2 | |
| 0.86.1 | 12 / 2 | |
| 0.86.0 | 12 / 2 | |
| 0.85.3 | 12 / 2 | |
| 0.85.2 | 12 / 2 | |
| 0.85.1 | 12 / 2 | |
| 0.85.0 | 12 / 2 | |
| 0.84.1 | 12 / 2 | |
| 0.84.0 | 12 / 2 | |
| 0.83.10 | 12 / 2 | |
| 0.83.9 | 12 / 2 | |
| 0.83.8 | 12 / 2 | |
| 0.83.7 | 12 / 2 | |
| 0.83.6 | 12 / 2 | |
| 0.83.5 | 12 / 2 | |
| 0.83.4 | 12 / 2 | |
| 0.83.3 | 12 / 2 | |
| 0.83.2 | 12 / 2 | |
| 0.83.1 | 12 / 2 | |
| 0.83.0 | 12 / 2 | |
| 0.82.1 | 12 / 2 | |
| 0.82.0 | 12 / 2 | |
| 0.81.6 | 12 / 2 | |
| 0.81.5 | 12 / 2 | |
| 0.81.4 | 12 / 2 | |
| 0.81.3 | 12 / 2 | |
| 0.81.2 | 12 / 2 | |
| 0.81.1 | 12 / 2 | |
| 0.81.0 | 12 / 2 | |
| 0.80.3 | 12 / 2 | |
| 0.80.2 | 12 / 2 | |
| 0.80.1 | 12 / 2 | |
| 0.80.0 | 12 / 2 | |
| 0.79.7 | 12 / 2 | |
| 0.79.6 | 12 / 2 | |
| 0.79.5 | 12 / 2 | |
| 0.79.4 | 12 / 2 | |
| 0.79.3 | 12 / 2 | |
| 0.79.2 | 12 / 2 | |
| 0.79.1 | 12 / 2 | |
| 0.79.0 | 12 / 2 | |
| 0.78.3 | 12 / 2 | |
| 0.78.2 | 12 / 2 | |
| 0.78.1 | 12 / 2 | |
| 0.78.0 | 12 / 2 | |
| 0.77.3 | 12 / 2 | |
| 0.77.2 | 12 / 2 | |
| 0.77.1 | 12 / 2 | |
| 0.77.0 | 12 / 2 | |
| 0.76.9 | 12 / 2 | |
| 0.76.8 | 12 / 2 |
v0.86.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (react-native-bot) on 2026-07-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.86.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.79.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.78.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.77.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.76.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.