← Home

metro-runtime

🚇 Module required for evaluating Metro bundles.

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

fbmetro-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Metadata variance for trusted metro-bot publisher; not a malicious signal. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped runtime loaded by convention; stable FP. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Long-standing metro package uses 0.0.0 versioning convention; high trust signals. ai
npm-metadata no-description AI (npm-metadata): Metadata quirk on an established, widely-used package. ai
semgrep semgrep:eval-usage AI (semgrep): eval() in HMRClient.js is intentional — Metro's HMR client must evaluate JS code at runtime. This is the documented purpose of the package and stable across versions. ai
dependencies unvetted-dep:flow-enums-runtime AI (dependencies): flow-enums-runtime is a Meta/Facebook package for Flow enum support, consistent with Metro's toolchain. Stable dependency for this package. ai

Versions (showing 51 of 99)

View all versions
Version Deps Published
0.87.0 2 / 4
0.86.0 2 / 4
0.85.0 2 / 4
0.84.4 2 / 4
0.84.3 2 / 4
0.84.2 2 / 4
0.84.1 2 / 4
0.84.0 2 / 4
0.83.7 2 / 4
0.83.6 2 / 4
0.83.5 2 / 4
0.83.4 2 / 4
0.83.3 2 / 4
0.83.2 2 / 4
0.83.1 2 / 4
0.83.0 2 / 4
0.82.5 2 / 4
0.82.4 2 / 4
0.82.3 2 / 4
0.82.2 2 / 4
0.82.1 2 / 4
0.82.0 2 / 4
0.81.5 2 / 4
0.81.4 2 / 4
0.81.3 2 / 4
0.81.2 2 / 4
0.81.1 2 / 4
0.81.0 2 / 4
0.80.12 2 / 4
0.80.11 2 / 4
0.80.10 2 / 4
0.80.9 1 / 4
0.80.8 1 / 4
0.80.7 1 / 4
0.80.6 1 / 4
0.80.5 1 / 4
0.80.4 1 / 4
0.80.3 1 / 4
0.80.2 1 / 4
0.80.1 1 / 4
0.80.0 1 / 4
0.79.1 2 / 3
0.79.0 2 / 3
0.78.1 2 / 3
0.78.0 2 / 3
0.77.0 2 / 3
0.76.9 2 / 3
0.76.8 2 / 3
0.76.7 2 / 3
0.76.6 2 / 3
0.76.5 2 / 3

v0.87.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.86.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.82.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.82.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.81.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.81.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.81.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.81.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.81.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.80.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.80.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.78.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.78.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.77.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.