All react-native-reanimated versions

react-native-reanimated @4.1.7

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
80
Risk Score
MIT
License
No
Install Scripts
2
Dependencies
54
Dev Dependencies
773.6 KB
Package Size
Published

More powerful alternative to Animated library for React Native.

Maintainers

swm-botkmagpiaskowyktomekzawtjzelmatipl01bartlomiejbloniarzpatrycjakalinska

Keywords

react-nativereactnativereanimated

Dependencies (2)

PackageConstraintRegistry Status
semver ^7.7.2 auto_approved
react-native-is-edge-to-edge ^1.2.1 auto_approved

Dev Dependencies (54)

PackageConstraintRegistry Status
jest ^29.0.0 auto_approved
knip ^5.61.3 auto_approved
axios ^1.8.2 auto_approved
madge ^5.0.1 pending
react 19.1.0 auto_approved
cspell ^8.8.0 auto_approved
eslint ^9.29.0 auto_approved
shelljs ^0.8.5 auto_approved
code-tag ^1.1.0 Not imported
prettier ^3.3.3 auto_approved
@babel/cli ^7.20.0 auto_approved
typescript 5.8.3 auto_approved
@babel/core ^7.25.2 auto_approved
@types/jest ^29.5.13 auto_approved
@types/node ^18.0.0 auto_approved
@babel/types ^7.20.0 auto_approved
@types/react ^19.1.0 auto_approved
babel-eslint ^10.1.0 auto_approved
react-native patch:react-native@npm%3A0.81.0#~/.yarn/patches/react-native-npm-0.81.0-96e336150b.patch auto_approved
@types/semver ^7 auto_approved
eslint-plugin-n ^17.19.0 auto_approved
react-native-svg 15.12.1 auto_approved
@babel/preset-env ^7.25.3 auto_approved
clang-format-node ^1.3.1 Not imported
@types/babel__core ^7.20.0 auto_approved
eslint-plugin-jest ^28.13.0 auto_approved
@shopify/flash-list 2.0.2 pending
eslint-plugin-tsdoc ^0.4.0 pending
react-test-renderer 19.1.0 auto_approved
eslint-plugin-import ^2.31.0 auto_approved
eslint-plugin-promise ^7.2.1 auto_approved
react-native-worklets 0.8.0 auto_approved
@types/babel__traverse ^7.14.2 auto_approved
eslint-config-standard ^17.1.0 auto_approved
eslint-plugin-standard ^5.0.0 auto_approved
@types/babel__generator ^7.6.4 auto_approved
eslint-plugin-reanimated workspace:* Not imported
react-native-builder-bob 0.40.13 auto_approved
@types/convert-source-map ^2.0.0 pending
@typescript-eslint/parser ^6.19.0 auto_approved
eslint-plugin-react-hooks ^5.2.0 auto_approved
@react-native/babel-preset 0.81.0 auto_approved
@react-native/metro-config 0.81.0 pending
@types/react-test-renderer ^19.1.0 auto_approved
@react-native/eslint-config 0.81.0 pending
@testing-library/jest-native ^4.0.4 Not imported
@testing-library/react-hooks ^8.0.1 auto_approved
babel-plugin-module-resolver ^5.0.0 auto_approved
react-native-gesture-handler 2.28.0 auto_approved
@testing-library/react-native ^13.0.1 auto_approved
@typescript-eslint/rule-tester ^6.21.0 pending
eslint-plugin-no-inline-styles ^1.0.5 Not imported
@react-native/typescript-config 0.81.0 pending
eslint-import-resolver-babel-module ^5.3.2 pending

Transitive Dependency Tree

2 transitive deps max depth 1
  ├─ react-native-is-edge-to-edge ^1.2.1 → 1.3.1
  ├─ semver ^7.7.2 → 7.8.0

Changes from v4.3.0-nightly-20260319-405a07d0a

Dependency Changes

ChangePackageVersion
changed semver 7.7.3 → ^7.7.2
changed react-native-is-edge-to-edge 1.2.1 → ^1.2.1

Script Changes

+ prepack+ postpack+ type:check:src+ use-strict-check - type:check:strict- type:check:src:web- tree-shake:check:web- type:check:src:native- type:check:strict:app- type:check:strict:src

File Changes

215 added 388 removed 744 modified size delta: -410.2 KB

Risk Dispositions (2 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
regressed-provenance provenance reject AI AI (provenance): react-native-reanimated established CI/CD provenance attestation; any version published without it should be rejected as it matches supply-chain attack patterns.
publisher-changed provenance reject AI AI (provenance): Package historically published via GitHub Actions CI; switch to personal account publishing without provenance is a strong compromise indicator for this package.

SAST Findings (2)

HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

HIGH Publisher changed: GitHub Actions → bartlomiejbloniarz (on 2026-03-20) provenance

This version was published by a different npm account than previous versions on 2026-03-20. This could indicate a legitimate maintainer transition or an account compromise.

Review Summary

Risk score: 80. Findings: 2 high (+50), 3 medium (+30).

Published to npm: