← Home

@shopify/react-native-skia

18
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jaimie.wayshopify-adminshopify-depmishsmellebuitammychris.craig

Keywords

react-native

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): execSync copies prebuilt Skia binaries locally; standard native-module install pattern. ai
source-diff large-new-source-files AI (source-diff): Legitimate feature growth in established, high-trust package; no injected code evidence. ai
maintainer-change maintainer-added AI (maintainer-change): Shopify org rotation; CI/CD publish with SLSA provenance attestation confirms legitimate org-controlled release. ai
maintainer-change maintainer-removed AI (maintainer-change): Same org rotation context; no hostile takeover indicators. ai
dependencies unvetted-dep:react-native-skia-android AI (dependencies): Platform-specific prebuilt binary dep; stable pattern for this package. ai
dependencies unvetted-dep:react-native-skia-apple-ios AI (dependencies): Platform-specific prebuilt binary dep; stable pattern for this package. ai
dependencies unvetted-dep:react-native-skia-apple-tvos AI (dependencies): Platform-specific prebuilt binary dep; stable pattern for this package. ai
phantom-deps phantom-dep:react-native-skia-apple-ios AI (phantom-deps): Platform-specific binary package; not directly imported by JS code by design. ai
phantom-deps phantom-dep:react-native-skia-android AI (phantom-deps): Platform-specific binary package; not directly imported by JS code by design. ai
phantom-deps phantom-dep:react-native-skia-apple-macos AI (phantom-deps): Platform-specific binary package; not directly imported by JS code by design. ai
phantom-deps phantom-dep:react-native-skia-apple-tvos AI (phantom-deps): Platform-specific binary package; not directly imported by JS code by design. ai
semgrep semgrep:dynamic-require AI (semgrep): Reads project app.json to detect Expo config; path is user-controlled project file, not arbitrary module loading. ai
install-scripts install-script:postinstall AI (install-scripts): Standard prebuilt-binary install script for a Shopify React Native native module; stable pattern across versions. ai

Versions (showing 18 of 18)

Version Deps Published
2.10.0 6 / 42
2.9.1 6 / 42
2.9.0 6 / 42
2.8.0 6 / 42
2.7.0 6 / 42
2.6.9 6 / 39
2.6.8 6 / 39
2.6.7 6 / 39
2.6.6 6 / 39
2.6.5 6 / 39
2.6.3 6 / 34
2.6.2 6 / 34
2.6.0 6 / 34
2.5.5 6 / 34
2.5.2 6 / 34
2.5.1 6 / 34
2.5.0 6 / 34
2.3.11 2 / 32

v2.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: shopify-dep → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (shopify-dep) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.5.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: shopify-dep → GitHub Actions (on 2026-03-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (shopify-dep) on 2026-03-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.