react-native-windows
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from rnbot to microsoft1es reflects Microsoft's internal CI/CD pipeline transition (1ES publishing); both accounts are Microsoft-controlled. Stable for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): vmoroz (Vladimir Morozov) is a known Microsoft React Native Windows contributor; addition is a legitimate team change. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead is consistent with the 1ES publishing pipeline change; not a malware indicator for this well-established Microsoft package. | ai | |
| phantom-deps | phantom-dep:jsc-android | AI (phantom-deps): jsc-android is a platform-specific binary dependency for Android JS engine; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): semver referenced in config files; expected for version management in platform packages. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander referenced in CLI config; standard for command-line tools. | ai | |
| phantom-deps | phantom-dep:babel-jest | AI (phantom-deps): babel-jest referenced in config files; expected for Jest test configuration. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped package loaded by convention; standard for Babel-based projects. | ai | |
| phantom-deps | phantom-dep:hermes-compiler | AI (phantom-deps): Referenced in config files; expected for Hermes JavaScript engine support. | ai | |
| phantom-deps | phantom-dep:metro-source-map | AI (phantom-deps): Referenced in config files; expected for Metro bundler source map support. | ai | |
| phantom-deps | phantom-dep:event-target-shim | AI (phantom-deps): Referenced in config files; standard polyfill for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/assets | AI (phantom-deps): Platform-specific binary package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/codegen | AI (phantom-deps): Platform-specific binary package for code generation; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli | AI (phantom-deps): Platform-specific CLI package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/gradle-plugin | AI (phantom-deps): Platform-specific binary package for Gradle; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/new-app-screen | AI (phantom-deps): Platform-specific package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:babel-plugin-syntax-hermes-parser | AI (phantom-deps): Referenced in config files; expected for Hermes parser support. | ai | |
| phantom-deps | phantom-dep:@react-native/community-cli-plugin | AI (phantom-deps): Platform-specific CLI plugin loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-ios | AI (phantom-deps): Platform-specific binary package for iOS; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-android | AI (phantom-deps): Platform-specific binary package for Android; expected for React Native. | ai | |
| phantom-deps | phantom-dep:flow-enums-runtime | AI (phantom-deps): Referenced in config files; expected for Flow type checking support. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is referenced in config files for WebSocket support; standard for React Native platform packages. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs referenced in CLI config; expected for build/CLI tools in platform packages. | ai | |
| phantom-deps | phantom-dep:mkdirp | AI (phantom-deps): mkdirp referenced in config files; standard utility for build scripts. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() in loadBundleFromServer.js is the standard React Native Metro dev-server bundle loading pattern; intentional and stable across versions. | ai | |
| provenance | no-provenance | AI (provenance): microsoft1es has 3550 approved packages; lack of Sigstore provenance is not a meaningful risk signal for this well-established publisher. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in template.config.js reads app.json for app name — standard React Native template pattern, not arbitrary module loading. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process in Scripts/cli.js is build/CLI tooling, not runtime library code. Expected for a framework package with build scripts. | ai |
Versions (showing 100 of 402)
| Version | Deps | Published |
|---|---|---|
| 0.72.30 | 40 / 21 | |
| 0.72.29 | 40 / 21 | |
| 0.72.28 | 40 / 21 | |
| 0.72.27 | 40 / 21 | |
| 0.72.26 | 40 / 21 | |
| 0.72.25 | 40 / 21 | |
| 0.72.24 | 40 / 21 | |
| 0.72.23 | 40 / 21 | |
| 0.72.22 | 40 / 21 | |
| 0.72.21 | 40 / 21 | |
| 0.72.20 | 40 / 21 | |
| 0.72.19 | 40 / 21 | |
| 0.72.18 | 40 / 21 | |
| 0.72.17 | 40 / 21 | |
| 0.72.16 | 40 / 21 | |
| 0.72.15 | 40 / 21 | |
| 0.72.14 | 40 / 21 | |
| 0.72.13 | 40 / 21 | |
| 0.72.12 | 40 / 21 | |
| 0.72.11 | 40 / 21 | |
| 0.72.10 | 40 / 21 | |
| 0.72.9 | 40 / 21 | |
| 0.72.8 | 40 / 21 | |
| 0.72.7 | 40 / 21 | |
| 0.72.6 | 40 / 21 | |
| 0.72.5 | 40 / 21 | |
| 0.72.4 | 40 / 21 | |
| 0.72.3 | 40 / 21 | |
| 0.72.2 | 40 / 21 | |
| 0.72.1 | 40 / 21 | |
| 0.72.0 | 40 / 21 | |
| 0.71.47 | 38 / 21 | |
| 0.71.46 | 35 / 21 | |
| 0.71.45 | 35 / 21 | |
| 0.71.44 | 35 / 21 | |
| 0.71.43 | 35 / 21 | |
| 0.71.42 | 35 / 21 | |
| 0.71.41 | 35 / 21 | |
| 0.71.40 | 35 / 21 | |
| 0.71.39 | 35 / 21 | |
| 0.71.38 | 35 / 21 | |
| 0.71.37 | 35 / 21 | |
| 0.71.36 | 35 / 21 | |
| 0.71.35 | 35 / 21 | |
| 0.71.34 | 35 / 21 | |
| 0.71.33 | 35 / 21 | |
| 0.71.32 | 35 / 21 | |
| 0.71.31 | 35 / 21 | |
| 0.71.30 | 35 / 21 | |
| 0.71.29 | 35 / 21 | |
| 0.71.28 | 35 / 21 | |
| 0.71.27 | 35 / 21 | |
| 0.71.26 | 35 / 21 | |
| 0.71.25 | 35 / 21 | |
| 0.71.24 | 35 / 21 | |
| 0.71.23 | 35 / 21 | |
| 0.71.22 | 35 / 21 | |
| 0.71.21 | 35 / 21 | |
| 0.71.20 | 35 / 21 | |
| 0.71.19 | 35 / 21 | |
| 0.71.18 | 35 / 21 | |
| 0.71.17 | 35 / 21 | |
| 0.71.16 | 35 / 21 | |
| 0.71.15 | 35 / 21 | |
| 0.71.14 | 35 / 21 | |
| 0.71.13 | 35 / 21 | |
| 0.71.12 | 35 / 21 | |
| 0.71.11 | 35 / 21 | |
| 0.71.10 | 35 / 21 | |
| 0.71.9 | 35 / 21 | |
| 0.71.8 | 35 / 21 | |
| 0.71.7 | 35 / 21 | |
| 0.71.6 | 35 / 21 | |
| 0.71.5 | 35 / 21 | |
| 0.71.4 | 35 / 21 | |
| 0.71.3 | 37 / 21 | |
| 0.71.2 | 37 / 21 | |
| 0.71.1 | 37 / 21 | |
| 0.71.0 | 37 / 21 | |
| 0.70.22 | 36 / 22 | |
| 0.70.21 | 36 / 22 | |
| 0.70.20 | 36 / 22 | |
| 0.70.19 | 36 / 22 | |
| 0.70.18 | 36 / 22 | |
| 0.70.17 | 36 / 22 | |
| 0.70.16 | 36 / 22 | |
| 0.70.15 | 36 / 22 | |
| 0.70.14 | 36 / 22 | |
| 0.70.13 | 36 / 22 | |
| 0.70.12 | 36 / 22 | |
| 0.70.11 | 36 / 22 | |
| 0.70.10 | 36 / 22 | |
| 0.70.9 | 36 / 22 | |
| 0.70.8 | 36 / 22 | |
| 0.70.7 | 36 / 22 | |
| 0.70.6 | 36 / 22 | |
| 0.70.5 | 36 / 22 | |
| 0.70.4 | 36 / 22 | |
| 0.70.3 | 36 / 22 | |
| 0.70.2 | 36 / 22 |
v0.72.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.71.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.70.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.