@planningcenter/chat-react-native
The code hosted here is meant to encapsulate behavior for our mobile targets. Currently we support behavior in Services and ChurchCenterApp.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@planningcenter/emoji-keyboard | AI (dependencies): Same-org internal package replacing rn-emoji-keyboard; version-locked to match this package's own version. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Active component library regularly adds source files across versions; not indicative of injected code. | ai | |
| phantom-deps | phantom-dep:jest-fetch-mock | AI (phantom-deps): Test dependency; legitimately used in test config without direct import. | ai | |
| phantom-deps | phantom-dep:fast-text-encoding | AI (phantom-deps): Polyfill dependency; used indirectly via platform-specific imports. | ai | |
| phantom-deps | phantom-dep:react-native-url-polyfill | AI (phantom-deps): Platform-specific polyfill; standard pattern for React Native packages. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs 'yarn build' via expo-module; standard build step for this React Native library, stable across versions. | ai | |
| dependencies | unvetted-dep:lodash-inflection | AI (dependencies): Well-known utility library; no malicious indicators; stable dependency across versions. | ai | |
| dependencies | unvetted-dep:@fortawesome/react-native-fontawesome | AI (dependencies): Official Font Awesome React Native package; no malicious indicators; stable dependency. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across 467 versions of this internal org package; not a malice indicator. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal org package (@planningcenter); sparse metadata is expected, not a spam/malware signal. | ai | |
| provenance | no-provenance | AI (provenance): Large org package with 461 versions; no provenance is consistent with their publishing history. | ai | |
| phantom-deps | phantom-dep:react-compiler-runtime | AI (phantom-deps): react-compiler-runtime is a declared runtime dep used by the React compiler toolchain; phantom-dep false positive for this package. | ai |
Versions (showing 59 of 59)
| Version | Deps | Published |
|---|---|---|
| 3.38.0 | 5 / 19 | |
| 3.37.2 | 5 / 19 | |
| 3.37.0 | 5 / 19 | |
| 3.36.1 | 5 / 19 | |
| 3.36.0 | 5 / 19 | |
| 3.35.0 | 5 / 19 | |
| 3.34.0 | 5 / 13 | |
| 3.33.1 | 5 / 13 | |
| 3.33.0 | 5 / 13 | |
| 3.32.0 | 4 / 13 | |
| 3.31.0 | 4 / 13 | |
| 3.30.0 | 4 / 13 | |
| 3.29.0 | 2 / 13 | |
| 3.28.0 | 2 / 13 | |
| 3.27.0 | 2 / 13 | |
| 3.26.0 | 2 / 13 | |
| 3.25.0 | 2 / 13 | |
| 3.24.4 | 2 / 13 | |
| 3.24.3 | 2 / 13 | |
| 3.24.2 | 2 / 13 | |
| 3.24.1 | 2 / 13 | |
| 3.24.0 | 2 / 13 | |
| 3.23.0 | 2 / 13 | |
| 3.22.0 | 2 / 13 | |
| 3.21.1 | 2 / 13 | |
| 3.21.0 | 2 / 13 | |
| 3.20.2 | 2 / 13 | |
| 3.20.1 | 2 / 13 | |
| 3.20.0 | 2 / 13 | |
| 3.19.0 | 2 / 13 | |
| 3.18.0 | 2 / 13 | |
| 3.17.2 | 2 / 13 | |
| 3.17.1 | 2 / 13 | |
| 3.17.0 | 1 / 12 | |
| 3.16.1 | 1 / 12 | |
| 3.16.0 | 1 / 12 | |
| 3.15.0 | 1 / 12 | |
| 3.14.0 | 1 / 12 | |
| 3.13.1 | 1 / 12 | |
| 3.13.0 | 1 / 12 | |
| 3.12.2 | 1 / 12 | |
| 3.12.1 | 5 / 8 | |
| 3.12.0 | 5 / 8 | |
| 3.11.2 | 5 / 8 | |
| 3.11.1 | 5 / 8 | |
| 3.11.0 | 5 / 8 | |
| 3.10.0 | 5 / 8 | |
| 3.9.2 | 5 / 8 | |
| 3.9.1 | 5 / 8 | |
| 3.9.0 | 5 / 8 | |
| 3.8.0 | 5 / 8 | |
| 3.7.0 | 5 / 8 | |
| 3.6.0 | 5 / 8 | |
| 3.5.0 | 5 / 7 | |
| 3.4.1 | 5 / 7 | |
| 3.4.0 | 5 / 7 | |
| 3.3.0 | 5 / 7 | |
| 3.2.0 | 5 / 7 | |
| 3.1.0 | 5 / 7 |
v3.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.37.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.33.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.32.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.31.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.30.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.24.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.24.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.20.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.20.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.12.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.0
2 findingsScript: yarn build
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.