react-native-windows
51
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
rozele
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from rnbot to microsoft1es reflects Microsoft's internal CI/CD pipeline transition (1ES publishing); both accounts are Microsoft-controlled. Stable for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): vmoroz (Vladimir Morozov) is a known Microsoft React Native Windows contributor; addition is a legitimate team change. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead is consistent with the 1ES publishing pipeline change; not a malware indicator for this well-established Microsoft package. | ai | |
| phantom-deps | phantom-dep:jsc-android | AI (phantom-deps): jsc-android is a platform-specific binary dependency for Android JS engine; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): semver referenced in config files; expected for version management in platform packages. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander referenced in CLI config; standard for command-line tools. | ai | |
| phantom-deps | phantom-dep:babel-jest | AI (phantom-deps): babel-jest referenced in config files; expected for Jest test configuration. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped package loaded by convention; standard for Babel-based projects. | ai | |
| phantom-deps | phantom-dep:hermes-compiler | AI (phantom-deps): Referenced in config files; expected for Hermes JavaScript engine support. | ai | |
| phantom-deps | phantom-dep:metro-source-map | AI (phantom-deps): Referenced in config files; expected for Metro bundler source map support. | ai | |
| phantom-deps | phantom-dep:event-target-shim | AI (phantom-deps): Referenced in config files; standard polyfill for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/assets | AI (phantom-deps): Platform-specific binary package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/codegen | AI (phantom-deps): Platform-specific binary package for code generation; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli | AI (phantom-deps): Platform-specific CLI package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/gradle-plugin | AI (phantom-deps): Platform-specific binary package for Gradle; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/new-app-screen | AI (phantom-deps): Platform-specific package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:babel-plugin-syntax-hermes-parser | AI (phantom-deps): Referenced in config files; expected for Hermes parser support. | ai | |
| phantom-deps | phantom-dep:@react-native/community-cli-plugin | AI (phantom-deps): Platform-specific CLI plugin loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-ios | AI (phantom-deps): Platform-specific binary package for iOS; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-android | AI (phantom-deps): Platform-specific binary package for Android; expected for React Native. | ai | |
| phantom-deps | phantom-dep:flow-enums-runtime | AI (phantom-deps): Referenced in config files; expected for Flow type checking support. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is referenced in config files for WebSocket support; standard for React Native platform packages. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs referenced in CLI config; expected for build/CLI tools in platform packages. | ai | |
| phantom-deps | phantom-dep:mkdirp | AI (phantom-deps): mkdirp referenced in config files; standard utility for build scripts. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() in loadBundleFromServer.js is the standard React Native Metro dev-server bundle loading pattern; intentional and stable across versions. | ai | |
| provenance | no-provenance | AI (provenance): microsoft1es has 3550 approved packages; lack of Sigstore provenance is not a meaningful risk signal for this well-established publisher. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in template.config.js reads app.json for app name — standard React Native template pattern, not arbitrary module loading. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process in Scripts/cli.js is build/CLI tooling, not runtime library code. Expected for a framework package with build scripts. | ai |
Versions (showing 51 of 402)
| Version | Deps | Published |
|---|---|---|
| 0.84.0 | 47 / 20 | |
| 0.83.2 | 46 / 20 | |
| 0.83.0 | 46 / 20 | |
| 0.82.8 | 46 / 20 | |
| 0.82.5 | 46 / 20 | |
| 0.82.3 | 46 / 20 | |
| 0.82.1 | 46 / 20 | |
| 0.82.0 | 46 / 20 | |
| 0.81.32 | 45 / 20 | |
| 0.81.31 | 45 / 20 | |
| 0.81.30 | 45 / 20 | |
| 0.81.29 | 45 / 20 | |
| 0.81.28 | 45 / 20 | |
| 0.81.27 | 45 / 20 | |
| 0.81.26 | 45 / 20 | |
| 0.81.25 | 45 / 20 | |
| 0.81.24 | 45 / 20 | |
| 0.81.22 | 45 / 20 | |
| 0.81.21 | 45 / 20 | |
| 0.81.20 | 45 / 20 | |
| 0.81.19 | 45 / 20 | |
| 0.81.18 | 45 / 20 | |
| 0.81.15 | 45 / 20 | |
| 0.81.13 | 45 / 20 | |
| 0.81.12 | 45 / 20 | |
| 0.81.11 | 45 / 20 | |
| 0.81.10 | 45 / 20 | |
| 0.81.9 | 45 / 20 | |
| 0.81.7 | 45 / 20 | |
| 0.81.6 | 45 / 20 | |
| 0.81.5 | 45 / 20 | |
| 0.81.4 | 45 / 20 | |
| 0.81.3 | 45 / 20 | |
| 0.81.2 | 45 / 20 | |
| 0.81.1 | 45 / 20 | |
| 0.81.0 | 45 / 20 | |
| 0.80.6 | 45 / 20 | |
| 0.80.5 | 45 / 20 | |
| 0.80.1 | 45 / 20 | |
| 0.80.0 | 45 / 20 | |
| 0.79.5 | 44 / 20 | |
| 0.79.4 | 44 / 20 | |
| 0.79.3 | 44 / 20 | |
| 0.79.2 | 44 / 20 | |
| 0.79.1 | 44 / 20 | |
| 0.79.0 | 44 / 20 | |
| 0.78.15 | 44 / 20 | |
| 0.78.14 | 44 / 20 | |
| 0.78.13 | 44 / 20 | |
| 0.78.12 | 44 / 20 | |
| 0.78.10 | 44 / 20 |
v0.81.32
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.81.31
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.81.30
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.