Findings the reviewer chose to accept rather than block on.
Source
Rule
Reason
Accepted by
When
provenance
publisher-changed
AI (provenance): Publisher change from acdlite to lunaruan reflects a legitimate React core team transition at Facebook in 2019; lunaruan is a well-established trusted publisher.
ai
maintainer-change
maintainer-added
AI (maintainer-change): lunaruan is a known React core team member; this maintainer addition is a legitimate internal Facebook team transition, not a compromise.
ai
provenance
no-provenance
AI (provenance): This version was published in 2019, predating Sigstore provenance attestation tooling. Absence of provenance is expected for this era of releases.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
INFOPublisher changed: react-bot → GitHub Actions (on 2026-06-01)provenance
[Accepted risk] This version was published by a different npm account than previous versions on 2026-06-01. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
INFOPublisher changed: react-bot → GitHub Actions (on 2026-06-01)provenance
[Accepted risk] This version was published by a different npm account than previous versions on 2026-06-01. This could indicate a legitimate maintainer transition or an account compromise.