react-native-windows
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from rnbot to microsoft1es reflects Microsoft's internal CI/CD pipeline transition (1ES publishing); both accounts are Microsoft-controlled. Stable for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): vmoroz (Vladimir Morozov) is a known Microsoft React Native Windows contributor; addition is a legitimate team change. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead is consistent with the 1ES publishing pipeline change; not a malware indicator for this well-established Microsoft package. | ai | |
| phantom-deps | phantom-dep:jsc-android | AI (phantom-deps): jsc-android is a platform-specific binary dependency for Android JS engine; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): semver referenced in config files; expected for version management in platform packages. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander referenced in CLI config; standard for command-line tools. | ai | |
| phantom-deps | phantom-dep:babel-jest | AI (phantom-deps): babel-jest referenced in config files; expected for Jest test configuration. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped package loaded by convention; standard for Babel-based projects. | ai | |
| phantom-deps | phantom-dep:hermes-compiler | AI (phantom-deps): Referenced in config files; expected for Hermes JavaScript engine support. | ai | |
| phantom-deps | phantom-dep:metro-source-map | AI (phantom-deps): Referenced in config files; expected for Metro bundler source map support. | ai | |
| phantom-deps | phantom-dep:event-target-shim | AI (phantom-deps): Referenced in config files; standard polyfill for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/assets | AI (phantom-deps): Platform-specific binary package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/codegen | AI (phantom-deps): Platform-specific binary package for code generation; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli | AI (phantom-deps): Platform-specific CLI package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/gradle-plugin | AI (phantom-deps): Platform-specific binary package for Gradle; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/new-app-screen | AI (phantom-deps): Platform-specific package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:babel-plugin-syntax-hermes-parser | AI (phantom-deps): Referenced in config files; expected for Hermes parser support. | ai | |
| phantom-deps | phantom-dep:@react-native/community-cli-plugin | AI (phantom-deps): Platform-specific CLI plugin loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-ios | AI (phantom-deps): Platform-specific binary package for iOS; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-android | AI (phantom-deps): Platform-specific binary package for Android; expected for React Native. | ai | |
| phantom-deps | phantom-dep:flow-enums-runtime | AI (phantom-deps): Referenced in config files; expected for Flow type checking support. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is referenced in config files for WebSocket support; standard for React Native platform packages. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs referenced in CLI config; expected for build/CLI tools in platform packages. | ai | |
| phantom-deps | phantom-dep:mkdirp | AI (phantom-deps): mkdirp referenced in config files; standard utility for build scripts. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() in loadBundleFromServer.js is the standard React Native Metro dev-server bundle loading pattern; intentional and stable across versions. | ai | |
| provenance | no-provenance | AI (provenance): microsoft1es has 3550 approved packages; lack of Sigstore provenance is not a meaningful risk signal for this well-established publisher. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in template.config.js reads app.json for app name — standard React Native template pattern, not arbitrary module loading. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process in Scripts/cli.js is build/CLI tooling, not runtime library code. Expected for a framework package with build scripts. | ai |
Versions (showing 100 of 402)
| Version | Deps | Published |
|---|---|---|
| 0.70.1 | 36 / 22 | |
| 0.70.0 | 36 / 22 | |
| 0.68.35 | 36 / 20 | |
| 0.68.34 | 36 / 20 | |
| 0.68.33 | 36 / 20 | |
| 0.68.32 | 36 / 20 | |
| 0.68.31 | 36 / 20 | |
| 0.68.30 | 36 / 20 | |
| 0.68.29 | 36 / 20 | |
| 0.68.28 | 36 / 20 | |
| 0.68.27 | 36 / 20 | |
| 0.68.26 | 36 / 20 | |
| 0.68.25 | 36 / 20 | |
| 0.68.24 | 36 / 20 | |
| 0.68.23 | 36 / 20 | |
| 0.68.22 | 36 / 20 | |
| 0.68.21 | 36 / 20 | |
| 0.68.20 | 36 / 20 | |
| 0.68.19 | 36 / 20 | |
| 0.68.18 | 36 / 20 | |
| 0.68.17 | 36 / 20 | |
| 0.68.16 | 36 / 20 | |
| 0.68.15 | 36 / 20 | |
| 0.68.14 | 36 / 20 | |
| 0.68.13 | 36 / 20 | |
| 0.68.12 | 36 / 20 | |
| 0.68.11 | 36 / 20 | |
| 0.68.10 | 36 / 20 | |
| 0.68.9 | 36 / 20 | |
| 0.68.8 | 36 / 20 | |
| 0.68.7 | 36 / 20 | |
| 0.68.6 | 36 / 20 | |
| 0.68.5 | 36 / 20 | |
| 0.68.4 | 36 / 20 | |
| 0.68.3 | 36 / 20 | |
| 0.68.2 | 36 / 20 | |
| 0.68.1 | 36 / 20 | |
| 0.68.0 | 36 / 20 | |
| 0.67.19 | 34 / 20 | |
| 0.67.18 | 34 / 20 | |
| 0.67.17 | 34 / 20 | |
| 0.67.16 | 34 / 20 | |
| 0.67.15 | 34 / 20 | |
| 0.67.14 | 34 / 20 | |
| 0.67.13 | 34 / 20 | |
| 0.67.12 | 34 / 20 | |
| 0.67.11 | 34 / 20 | |
| 0.67.10 | 34 / 20 | |
| 0.67.9 | 34 / 20 | |
| 0.67.8 | 34 / 20 | |
| 0.67.7 | 34 / 20 | |
| 0.67.6 | 34 / 20 | |
| 0.67.5 | 34 / 20 | |
| 0.67.4 | 34 / 20 | |
| 0.67.3 | 34 / 20 | |
| 0.67.2 | 34 / 20 | |
| 0.67.1 | 34 / 20 | |
| 0.67.0 | 34 / 20 | |
| 0.66.25 | 35 / 20 | |
| 0.66.24 | 35 / 20 | |
| 0.66.23 | 35 / 20 | |
| 0.66.22 | 35 / 20 | |
| 0.66.21 | 35 / 20 | |
| 0.66.20 | 35 / 20 | |
| 0.66.19 | 35 / 20 | |
| 0.66.18 | 35 / 20 | |
| 0.66.17 | 35 / 20 | |
| 0.66.16 | 35 / 20 | |
| 0.66.15 | 35 / 20 | |
| 0.66.14 | 35 / 20 | |
| 0.66.13 | 35 / 20 | |
| 0.66.12 | 35 / 20 | |
| 0.66.11 | 35 / 20 | |
| 0.66.10 | 35 / 20 | |
| 0.66.9 | 35 / 20 | |
| 0.66.8 | 35 / 20 | |
| 0.66.7 | 35 / 20 | |
| 0.66.6 | 35 / 20 | |
| 0.66.5 | 35 / 20 | |
| 0.66.4 | 35 / 20 | |
| 0.66.3 | 35 / 20 | |
| 0.66.2 | 35 / 20 | |
| 0.66.1 | 35 / 20 | |
| 0.66.0 | 35 / 20 | |
| 0.65.14 | 33 / 17 | |
| 0.65.13 | 33 / 17 | |
| 0.65.12 | 33 / 17 | |
| 0.65.11 | 33 / 17 | |
| 0.65.10 | 33 / 17 | |
| 0.65.9 | 33 / 17 | |
| 0.65.8 | 33 / 17 | |
| 0.65.7 | 33 / 17 | |
| 0.65.6 | 33 / 17 | |
| 0.65.5 | 33 / 17 | |
| 0.65.4 | 33 / 17 | |
| 0.65.3 | 33 / 17 | |
| 0.65.2 | 33 / 17 | |
| 0.65.1 | 33 / 17 | |
| 0.65.0 | 33 / 17 | |
| 0.2.3 | 0 / 0 |
v0.70.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.68.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.67.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.66.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.65.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.