← Home

@react-native/eslint-config

87
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

react-native-botfb

Keywords

eslintconfigreact-native

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:eslint-plugin-prettier AI (phantom-deps): ESLint config package; deps referenced via config, not imports. ai
source-diff net-exec-file:shared.js AI (source-diff): shared.js is a static ESLint config; the net-exec detection is a false positive for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Backport patch releases for older minor series naturally have long gaps; trusted publisher with 1561 approved packages. ai
provenance no-provenance AI (provenance): Official React Native monorepo package; lack of Sigstore provenance is consistent across all versions and not a meaningful risk signal here. ai
phantom-deps phantom-dep:eslint-plugin-ft-flow AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): ESLint config packages reference configs by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): ESLint config packages reference parsers by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-plugin-react AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-plugin-react-native AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:@react-native/eslint-plugin AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-plugin-eslint-comments AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:@babel/eslint-parser AI (phantom-deps): ESLint config packages reference parsers by name in config, not via import; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-plugin-jest AI (phantom-deps): ESLint config packages reference plugins by name in config, not via import; stable false positive for this package. ai
dependencies unvetted-dep:eslint-plugin-ft-flow AI (dependencies): eslint-plugin-ft-flow is a legitimate Flow linting plugin; appropriate dependency for React Native ESLint config. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): @babel/core is a declared runtime dep used by @babel/eslint-parser; phantom-dep false positive for this package. ai

Versions (showing 87 of 87)

Version Deps Published
0.86.2 12 / 2
0.86.1 12 / 2
0.86.0 12 / 2
0.85.3 12 / 2
0.85.2 12 / 2
0.85.1 12 / 2
0.85.0 12 / 2
0.84.1 12 / 2
0.84.0 12 / 2
0.83.10 12 / 2
0.83.9 12 / 2
0.83.8 12 / 2
0.83.7 12 / 2
0.83.6 12 / 2
0.83.5 12 / 2
0.83.4 12 / 2
0.83.3 12 / 2
0.83.2 12 / 2
0.83.1 12 / 2
0.83.0 12 / 2
0.82.1 12 / 2
0.82.0 12 / 2
0.81.6 12 / 2
0.81.5 12 / 2
0.81.4 12 / 2
0.81.3 12 / 2
0.81.2 12 / 2
0.81.1 12 / 2
0.81.0 12 / 2
0.80.3 12 / 2
0.80.2 12 / 2
0.80.1 12 / 2
0.80.0 12 / 2
0.79.7 12 / 2
0.79.6 12 / 2
0.79.5 12 / 2
0.79.4 12 / 2
0.79.3 12 / 2
0.79.2 12 / 2
0.79.1 12 / 2
0.79.0 12 / 2
0.78.3 12 / 2
0.78.2 12 / 2
0.78.1 12 / 2
0.78.0 12 / 2
0.77.3 12 / 2
0.77.2 12 / 2
0.77.1 12 / 2
0.77.0 12 / 2
0.76.9 12 / 2
0.76.8 12 / 2
0.76.7 12 / 2
0.76.6 12 / 2
0.76.5 12 / 2
0.76.4 12 / 2
0.76.3 13 / 2
0.76.2 13 / 2
0.76.1 13 / 2
0.76.0 13 / 2
0.75.5 12 / 2
0.75.4 12 / 2
0.75.3 12 / 2
0.75.2 12 / 2
0.75.1 12 / 2
0.75.0 12 / 2
0.74.89 13 / 2
0.74.88 13 / 2
0.74.87 13 / 2
0.74.86 13 / 2
0.74.85 13 / 2
0.74.84 13 / 2
0.74.83 13 / 2
0.74.82 13 / 2
0.74.81 13 / 2
0.74.80 13 / 2
0.74.79 13 / 2
0.74.78 13 / 2
0.74.77 13 / 2
0.74.76 13 / 2
0.74.75 13 / 2
0.74.1 13 / 2
0.74.0 13 / 2
0.73.2 13 / 2
0.73.1 13 / 2
0.73.0 13 / 2
0.72.2 13 / 2
0.72.1 13 / 2

v0.86.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: react-native-bot → GitHub Actions (on 2026-07-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (react-native-bot) on 2026-07-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.86.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.78.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.78.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.78.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.77.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.77.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.77.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.75.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.75.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.75.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.75.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.75.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.75.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.88

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.87

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.86

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.85

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.84

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.83

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.82

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.81

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.80

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.79

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.78

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.77

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.76

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.75

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.74.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.73.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.73.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.73.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.72.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.72.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.