react-native-macos
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:jsc-android | AI (phantom-deps): jsc-android is a platform-specific peer dep referenced in config; stable false positive for this package. | ai | |
| semgrep | semgrep:child-process-exec | AI (semgrep): exec() in runMacOS.js opens macOS apps by bundle ID — standard CLI toolchain behavior for a React Native macOS build tool. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): spawn() in runMacOS.js invokes xcpretty for Xcode build output — expected behavior for a macOS build CLI tool. | ai | |
| phantom-deps | phantom-dep:@react-native/virtualized-lists | AI (phantom-deps): react-native-macos uses its own fork (@react-native-macos/virtualized-lists); declaring the upstream as a dep is a known compatibility pattern for this package. | ai | |
| provenance | no-provenance | AI (provenance): Microsoft's react-native-macos is a well-established package with 54 approved-dep edges and automated publishing; lack of Sigstore provenance is not a disqualifier here. | ai | |
| phantom-deps | phantom-dep:babel-jest | AI (phantom-deps): babel-jest is referenced in jest config files; phantom-dep detection is a false positive for config-file-only references in large frameworks. | ai | |
| phantom-deps | phantom-dep:flow-enums-runtime | AI (phantom-deps): flow-enums-runtime is a Flow type system runtime dependency referenced in config; expected for this package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env in runMacOS.js CLI tool is standard practice for passing developer environment to child processes. Not credential exfiltration. | ai | |
| phantom-deps | phantom-dep:babel-plugin-syntax-hermes-parser | AI (phantom-deps): Referenced in Babel config files; phantom-dep detection is a false positive for config-file-only references. | ai | |
| phantom-deps | phantom-dep:@react-native/gradle-plugin | AI (phantom-deps): Platform-specific binary package for Android/Gradle builds; not directly imported in JS but legitimately declared. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() in loadBundleFromServer.js is React Native's intentional dev-mode hot reload mechanism, explicitly marked with eslint-disable and well-documented. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process usage in a CLI tool (cli.js) is expected for spawning build tools, packagers, and simulators. Standard for React Native CLI. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in cli.js delegates to @react-native-community/cli after resolving its path — standard CLI delegation pattern for React Native. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a legitimate declared dependency used in config/platform-specific contexts in this large framework package. | ai |
Versions (showing 100 of 216)
| Version | Deps | Published |
|---|---|---|
| 0.74.12 | 37 / 0 | |
| 0.74.11 | 37 / 0 | |
| 0.74.10 | 37 / 0 | |
| 0.74.9 | 37 / 0 | |
| 0.74.8 | 37 / 0 | |
| 0.74.7 | 37 / 0 | |
| 0.74.6 | 37 / 0 | |
| 0.74.5 | 37 / 0 | |
| 0.74.4 | 37 / 0 | |
| 0.74.3 | 37 / 0 | |
| 0.74.2 | 37 / 0 | |
| 0.74.1 | 37 / 0 | |
| 0.73.36 | 38 / 0 | |
| 0.73.35 | 38 / 0 | |
| 0.73.34 | 38 / 0 | |
| 0.73.33 | 38 / 0 | |
| 0.73.32 | 38 / 0 | |
| 0.73.31 | 38 / 0 | |
| 0.73.30 | 38 / 0 | |
| 0.73.29 | 38 / 0 | |
| 0.73.28 | 38 / 0 | |
| 0.73.27 | 38 / 0 | |
| 0.73.26 | 38 / 0 | |
| 0.73.25 | 38 / 0 | |
| 0.73.24 | 38 / 0 | |
| 0.73.23 | 38 / 0 | |
| 0.73.22 | 38 / 0 | |
| 0.73.21 | 38 / 0 | |
| 0.73.20 | 38 / 0 | |
| 0.73.19 | 38 / 0 | |
| 0.73.18 | 38 / 0 | |
| 0.73.17 | 38 / 0 | |
| 0.73.16 | 38 / 0 | |
| 0.73.15 | 38 / 0 | |
| 0.73.14 | 37 / 0 | |
| 0.73.13 | 37 / 0 | |
| 0.73.12 | 37 / 0 | |
| 0.73.11 | 37 / 0 | |
| 0.73.10 | 37 / 0 | |
| 0.73.9 | 37 / 0 | |
| 0.73.8 | 37 / 0 | |
| 0.73.7 | 37 / 0 | |
| 0.73.6 | 37 / 0 | |
| 0.73.5 | 37 / 0 | |
| 0.73.4 | 37 / 0 | |
| 0.73.3 | 37 / 0 | |
| 0.73.2 | 37 / 0 | |
| 0.73.1 | 37 / 0 | |
| 0.72.21 | 36 / 0 | |
| 0.72.20 | 36 / 0 | |
| 0.72.19 | 36 / 0 | |
| 0.72.18 | 36 / 0 | |
| 0.72.17 | 36 / 0 | |
| 0.72.16 | 36 / 0 | |
| 0.72.15 | 36 / 0 | |
| 0.72.14 | 36 / 0 | |
| 0.72.13 | 36 / 0 | |
| 0.72.12 | 36 / 0 | |
| 0.72.11 | 36 / 0 | |
| 0.72.10 | 36 / 0 | |
| 0.72.9 | 36 / 0 | |
| 0.72.8 | 36 / 0 | |
| 0.72.7 | 36 / 0 | |
| 0.72.6 | 36 / 0 | |
| 0.72.5 | 36 / 0 | |
| 0.72.4 | 36 / 0 | |
| 0.72.3 | 36 / 0 | |
| 0.72.2 | 36 / 0 | |
| 0.72.1 | 36 / 0 | |
| 0.72.0 | 36 / 0 | |
| 0.71.36 | 35 / 47 | |
| 0.71.35 | 35 / 47 | |
| 0.71.34 | 35 / 47 | |
| 0.71.33 | 36 / 47 | |
| 0.71.32 | 36 / 47 | |
| 0.71.31 | 36 / 47 | |
| 0.71.30 | 36 / 47 | |
| 0.71.29 | 36 / 47 | |
| 0.71.28 | 36 / 47 | |
| 0.71.27 | 36 / 47 | |
| 0.71.26 | 36 / 47 | |
| 0.71.25 | 36 / 47 | |
| 0.71.24 | 36 / 47 | |
| 0.71.23 | 36 / 47 | |
| 0.71.22 | 36 / 47 | |
| 0.71.21 | 36 / 47 | |
| 0.71.20 | 36 / 47 | |
| 0.71.19 | 36 / 47 | |
| 0.71.18 | 36 / 47 | |
| 0.71.17 | 36 / 47 | |
| 0.71.16 | 35 / 47 | |
| 0.71.15 | 35 / 47 | |
| 0.71.14 | 35 / 47 | |
| 0.71.13 | 35 / 47 | |
| 0.71.12 | 35 / 47 | |
| 0.71.11 | 35 / 47 | |
| 0.71.10 | 35 / 47 | |
| 0.71.9 | 35 / 47 | |
| 0.71.8 | 35 / 47 | |
| 0.71.7 | 35 / 47 |
v0.74.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.74.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.73.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.