react-native-windows
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from rnbot to microsoft1es reflects Microsoft's internal CI/CD pipeline transition (1ES publishing); both accounts are Microsoft-controlled. Stable for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): vmoroz (Vladimir Morozov) is a known Microsoft React Native Windows contributor; addition is a legitimate team change. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead is consistent with the 1ES publishing pipeline change; not a malware indicator for this well-established Microsoft package. | ai | |
| phantom-deps | phantom-dep:jsc-android | AI (phantom-deps): jsc-android is a platform-specific binary dependency for Android JS engine; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): semver referenced in config files; expected for version management in platform packages. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander referenced in CLI config; standard for command-line tools. | ai | |
| phantom-deps | phantom-dep:babel-jest | AI (phantom-deps): babel-jest referenced in config files; expected for Jest test configuration. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped package loaded by convention; standard for Babel-based projects. | ai | |
| phantom-deps | phantom-dep:hermes-compiler | AI (phantom-deps): Referenced in config files; expected for Hermes JavaScript engine support. | ai | |
| phantom-deps | phantom-dep:metro-source-map | AI (phantom-deps): Referenced in config files; expected for Metro bundler source map support. | ai | |
| phantom-deps | phantom-dep:event-target-shim | AI (phantom-deps): Referenced in config files; standard polyfill for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/assets | AI (phantom-deps): Platform-specific binary package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/codegen | AI (phantom-deps): Platform-specific binary package for code generation; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli | AI (phantom-deps): Platform-specific CLI package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/gradle-plugin | AI (phantom-deps): Platform-specific binary package for Gradle; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native/new-app-screen | AI (phantom-deps): Platform-specific package loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:babel-plugin-syntax-hermes-parser | AI (phantom-deps): Referenced in config files; expected for Hermes parser support. | ai | |
| phantom-deps | phantom-dep:@react-native/community-cli-plugin | AI (phantom-deps): Platform-specific CLI plugin loaded by convention; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-ios | AI (phantom-deps): Platform-specific binary package for iOS; expected for React Native. | ai | |
| phantom-deps | phantom-dep:@react-native-community/cli-platform-android | AI (phantom-deps): Platform-specific binary package for Android; expected for React Native. | ai | |
| phantom-deps | phantom-dep:flow-enums-runtime | AI (phantom-deps): Referenced in config files; expected for Flow type checking support. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is referenced in config files for WebSocket support; standard for React Native platform packages. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs referenced in CLI config; expected for build/CLI tools in platform packages. | ai | |
| phantom-deps | phantom-dep:mkdirp | AI (phantom-deps): mkdirp referenced in config files; standard utility for build scripts. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() in loadBundleFromServer.js is the standard React Native Metro dev-server bundle loading pattern; intentional and stable across versions. | ai | |
| provenance | no-provenance | AI (provenance): microsoft1es has 3550 approved packages; lack of Sigstore provenance is not a meaningful risk signal for this well-established publisher. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in template.config.js reads app.json for app name — standard React Native template pattern, not arbitrary module loading. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process in Scripts/cli.js is build/CLI tooling, not runtime library code. Expected for a framework package with build scripts. | ai |
Versions (showing 100 of 402)
| Version | Deps | Published |
|---|---|---|
| 0.75.12 | 44 / 20 | |
| 0.75.11 | 44 / 20 | |
| 0.75.10 | 44 / 20 | |
| 0.75.9 | 44 / 20 | |
| 0.75.8 | 44 / 20 | |
| 0.75.7 | 44 / 20 | |
| 0.75.6 | 44 / 21 | |
| 0.75.5 | 44 / 21 | |
| 0.75.4 | 44 / 21 | |
| 0.75.3 | 43 / 21 | |
| 0.75.2 | 43 / 21 | |
| 0.75.1 | 43 / 21 | |
| 0.75.0 | 43 / 21 | |
| 0.74.59 | 42 / 21 | |
| 0.74.58 | 42 / 21 | |
| 0.74.56 | 42 / 21 | |
| 0.74.55 | 42 / 21 | |
| 0.74.54 | 42 / 21 | |
| 0.74.53 | 42 / 21 | |
| 0.74.52 | 42 / 21 | |
| 0.74.48 | 42 / 21 | |
| 0.74.47 | 42 / 21 | |
| 0.74.46 | 42 / 21 | |
| 0.74.45 | 42 / 21 | |
| 0.74.44 | 42 / 21 | |
| 0.74.43 | 41 / 21 | |
| 0.74.42 | 41 / 21 | |
| 0.74.41 | 41 / 21 | |
| 0.74.40 | 41 / 21 | |
| 0.74.39 | 41 / 21 | |
| 0.74.38 | 41 / 21 | |
| 0.74.37 | 41 / 21 | |
| 0.74.36 | 41 / 21 | |
| 0.74.35 | 41 / 21 | |
| 0.74.34 | 41 / 21 | |
| 0.74.33 | 41 / 21 | |
| 0.74.32 | 41 / 21 | |
| 0.74.31 | 41 / 21 | |
| 0.74.30 | 41 / 21 | |
| 0.74.29 | 41 / 21 | |
| 0.74.28 | 41 / 21 | |
| 0.74.27 | 41 / 21 | |
| 0.74.26 | 41 / 21 | |
| 0.74.25 | 41 / 21 | |
| 0.74.24 | 41 / 21 | |
| 0.74.23 | 41 / 21 | |
| 0.74.22 | 41 / 21 | |
| 0.74.21 | 41 / 21 | |
| 0.74.20 | 41 / 21 | |
| 0.74.19 | 41 / 21 | |
| 0.74.18 | 41 / 21 | |
| 0.74.17 | 41 / 21 | |
| 0.74.16 | 41 / 21 | |
| 0.74.15 | 41 / 21 | |
| 0.74.14 | 41 / 21 | |
| 0.74.13 | 41 / 21 | |
| 0.74.12 | 41 / 21 | |
| 0.74.11 | 41 / 21 | |
| 0.74.10 | 41 / 21 | |
| 0.74.9 | 41 / 21 | |
| 0.74.8 | 41 / 21 | |
| 0.74.7 | 41 / 21 | |
| 0.74.6 | 41 / 21 | |
| 0.74.5 | 41 / 21 | |
| 0.74.4 | 41 / 21 | |
| 0.74.3 | 41 / 21 | |
| 0.74.2 | 41 / 21 | |
| 0.74.1 | 41 / 21 | |
| 0.74.0 | 41 / 21 | |
| 0.73.22 | 41 / 21 | |
| 0.73.21 | 41 / 21 | |
| 0.73.20 | 41 / 21 | |
| 0.73.19 | 41 / 21 | |
| 0.73.18 | 41 / 21 | |
| 0.73.17 | 41 / 21 | |
| 0.73.16 | 41 / 21 | |
| 0.73.15 | 41 / 21 | |
| 0.73.14 | 41 / 21 | |
| 0.73.13 | 41 / 21 | |
| 0.73.12 | 41 / 21 | |
| 0.73.11 | 41 / 21 | |
| 0.73.10 | 41 / 21 | |
| 0.73.9 | 41 / 21 | |
| 0.73.8 | 41 / 21 | |
| 0.73.7 | 41 / 21 | |
| 0.73.6 | 41 / 21 | |
| 0.73.5 | 41 / 21 | |
| 0.73.4 | 41 / 21 | |
| 0.73.3 | 41 / 21 | |
| 0.73.2 | 41 / 21 | |
| 0.73.1 | 41 / 21 | |
| 0.73.0 | 41 / 21 | |
| 0.72.38 | 41 / 21 | |
| 0.72.37 | 41 / 21 | |
| 0.72.36 | 41 / 21 | |
| 0.72.35 | 41 / 21 | |
| 0.72.34 | 41 / 21 | |
| 0.72.33 | 41 / 21 | |
| 0.72.32 | 40 / 21 | |
| 0.72.31 | 40 / 21 |
v0.75.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.75.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.74.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.73.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.72.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.